Field Access & PINs
A technician standing in front of a broken machine is rarely signed in to the portal. Neither is the client contact you emailed a link to. Field access lets both of them reach a single location or asset — and lets you know exactly who did.
What an Access PIN Is
An access PIN is a six-digit code that identifies a person in front of one form. That is the whole of it.
It is worth being precise about what a PIN is not, because the word invites the wrong assumption:
- It is not a second password. It does not sign anyone in, and it opens no part of the portal.
- It is not a key to your account. Entering a PIN to view one asset grants access to that asset and nothing else. The same PIN entered against a different asset is a separate decision, checked separately.
- It is not a way around permissions. A PIN identifies someone; it never promotes them. Whatever their account was already allowed to see is exactly what they see.
What a PIN buys you is attribution. Without one, a public link is anonymous — you know the page was opened, not by whom. With one, every view and every report carries a name.
Creating a PIN
Each person manages their own under Account → Security → Access PIN.
- Create PIN generates a six-digit code. It is generated, not chosen, so nobody sets theirs to their birth year.
- Show reveals it, with a copy button beside it. A PIN is meant to be read off the screen and remembered or saved, so it can be shown again later rather than only once.
- New PIN replaces the existing one. Doing so immediately invalidates anything the old PIN had open.
- Remove deletes it. That person can no longer use any PIN-gated form until a new one is issued.
The panel also shows when the PIN was created and when it was last used — or "never used", which is often the more interesting of the two when you are working out whether a rollout landed.
Administrators can create, replace, or remove a PIN on someone else's behalf from that person's user record — useful when you are setting up a crew who will only ever meet the portal through a sticker on a wall.
QR Stickers for Equipment
Any location or asset can be reached by a scan link, which is what you print on a sticker and put on the equipment itself.
Generate one from Tickets → Embed form → Tie it to one asset or location. Search for the record, and the Sticker link (QR) field fills in. Feed that URL to whatever QR generator or label printer you already use.
The link looks like ?cove_access=asset&id=123 — it names a record and nothing else.
The code on the sticker is not a secret, and is not treated as one. A sticker on a wall can be read by anyone in the room, photographed from across it, and turns up in listing photos and insurance surveys. So the code carries no key, no token, and no PIN. It says only which record this is. A scanned code on its own is worth nothing to whoever scanned it — identity comes entirely from the PIN typed afterwards.
That is what makes the stickers safe to put somewhere genuinely public.
What the Scanner Sees
Scanning opens a small page built for a phone held one-handed in a plant room. No portal chrome, no login screen, no app to install.
- Enter your PIN. Email and the six digits.
- Confirm the record. The title, the client, and a few identifying fields — serial, model, address, depending on the record. Enough to be sure you are looking at the right machine before you write anything about it.
- Report a problem, if you need to. Covered in Reporting Problems.
This is a confirmation view, not a data export. It deliberately does not carry the vault, the file library, the full service history, or anything else the workspace holds.
Every successful scan is recorded against the record. See Who Has Been Looking below.
Sharing a Record by Link
Locations and assets can also be shared by link, the same way resources can. Open the record and use the Share button, then Activate Public Link.
The share dialog covers:
- Activate Public Link — on or off
- Require a PIN to view — see below
- Link Expiration — Never, 1 Day, 3 Days, 1 Week, 1 Month, or 1 Year
- A QR code for the share link once it is active, downloadable as PNG or SVG
A share link is for sending to a specific person — a landlord, an insurer, a contractor quoting a job. The QR sticker is for the equipment. They are different tools and it is worth not mixing them up: a sticker is seen by whoever walks past, a link is seen by whoever you sent it to and anyone they forward it to.
Requiring a PIN to View
Require a PIN to view closes the gap in that last sentence. With it on, holding the URL is not enough — whoever opens it identifies themselves with their access PIN first, and you know who looked.
It is still a public view of that one record. The PIN does not sign them in and opens nothing else.
Two behaviours worth knowing:
- New shares have it on by default. When you activate a link on a record that has never been shared, the dialog tells you that saving will switch it on.
- Links you have already sent are not touched. Applying this retroactively would have broken every live link from the recipient's side, with no warning and no way for them to tell you what happened. So a share created before this existed keeps working exactly as before until someone opens its settings.
Turn it off when the recipient has no portal account and never will — an insurer's assessor, say. Leave it on whenever the recipient is someone you already have on the system, which is most of the time.
Who Can See What
A PIN identifies; it never elevates. Everything behind field access runs as the person whose PIN was entered, so the portal's normal client scoping decides what comes back.
In practice:
- A PIN belonging to one client cannot open another client's asset, whatever record ID is in the URL. The record simply reports as unavailable.
- If someone's account could not see a record while signed in, their PIN will not show it to them in the field either.
- A PIN that has been removed or replaced stops working immediately, everywhere, including on links and stickers already in circulation.
This is why stickers can be printed and forgotten about. Revoking access is a matter of changing one person's PIN, not of collecting stickers.
Who Has Been Looking
Every PIN-verified view is recorded on the record itself — both QR scans and views through a PIN-gated share link.
Open the location or asset and look for Viewed From Outside, above the activity log. Each row shows who opened it, when, and the address they came from. The record keeps its most recent fifty.
It sits apart from the activity log on purpose. That log answers "what changed?"; this one answers "who has been here?" — and a run of scans would otherwise be buried under a week of field edits.
The panel is visible to anyone who can edit the record, which means a client administrator sees it for their own equipment and nobody else's. It does not widen when a record is shared: sending someone a link does not show them who else has opened it.
This is the payoff for gating access at all. An ungated public link tells you a page was opened; it cannot tell you by whom.
Limits and Session Length
- PIN entry is rate limited to five attempts per fifteen minutes from any one address. Six digits is a small space; the limiter is what makes it a reasonable one.
- A verified session lasts twenty minutes, and covers only the record it was opened for.
- Changing or removing a PIN invalidates every session it had opened, immediately.
- A session that expires mid-task returns the person to the PIN step rather than failing silently on submit.
Choosing an Approach
| You want to… | Use |
|---|---|
| Let field crew reach equipment they are standing next to | A QR sticker |
| Send one record to one person outside the portal | A share link, PIN required |
| Send one record to someone with no portal account at all | A share link, PIN not required, with an expiry set |
| Let people report faults from your own website | The embeddable support form |
All four are off until you set them up. Nobody holds a PIN until one is created for them, no share link exists until you activate it, and no sticker works until you generate its URL.