By default, your staff can sign in to Pigeonhole from anywhere — the nursery iPad, their own phone, a home laptop. Authorised devices lets you change that. Once it is switched on, staff can only reach your setting from devices you have approved, and everywhere else they simply won’t see it.
This is designed for settings that want children’s records to stay on the premises. It is a practical control rather than a lock-and-key one — it stops casual out-of-hours access from personal devices, and it is not a substitute for good password and passkey habits.
Who is affected
Not everyone is restricted. The rules are:
- Staff are restricted. They can only sign in on an authorised device.
- Managers, owners, and organisation owners are never restricted. You can always sign in from any device — this is what stops you locking yourself out, because only you can approve a new device.
- Parents and carers are never restricted. The parent portal is meant to be used at home.
- A staff member who is also a parent at your setting keeps their parent access on any device. On an unapproved device they see their own child’s journal, but not their staff areas.
Each setting has its own device list. If you run more than one nursery, approving a device for one does not approve it for the others — you choose which settings a device covers when you approve it.
Step 1: Turn the feature on
- Go to Settings → Site Profile.
- Scroll to the Features section.
- Turn on Authorised devices.
- Click Save.
Approve at least one device before you turn this on, or as soon as you have. The moment it is enabled, staff signing in on an unapproved device are blocked from your setting.
Step 2: Approve a device
You approve a device by signing in on it yourself. There is no code to type in and nothing to install.
- On the device you want your staff to use, go to the Pigeonhole sign-in page and sign in with your own manager or owner account.
- After you enter your code or use your passkey, Pigeonhole asks “Authorise this device?”
- Give the device a name your team will recognise — for example “Toddler room iPad” or “Office PC”. Pigeonhole suggests a name based on the device, which you can change.
- If you manage more than one setting, tick the settings this device should cover.
- Click Authorise this device.
If you are signing in on a device you don’t want to approve — your own phone, say — click Not now. You still get signed in, and you’ll be offered the choice again next time.
Only approve devices that belong to the setting. Don’t approve your personal phone or a shared family computer: once a device is on the list, any staff member can sign in on it.
Step 3: Manage your approved devices
Go to Settings → Authorised Devices to see every device your staff can sign in from.
Each device in the list shows:
- An icon for the kind of device — a laptop for web browsers, a tablet for iPhones and iPads, a phone for Android.
- The device name, with a This device badge if it’s the one you’re using right now.
- Who approved it and when, so there’s a record of how it got on the list.
- Last used — the last time anyone successfully signed in on it.
Rename a device
Click the pencil icon next to the device name, type the new name, and press Enter or click the tick. Press Escape or click the cross to cancel.
Remove a device
Click the delete icon at the end of the row and confirm.
Removing a device signs out everyone currently using it, straight away — including on the mobile app. Staff will not be able to sign in on it again until a manager approves it afresh.
Devices never expire on their own, so the list only shrinks when you prune it. Use the Last used date to spot devices nobody has signed in on for months — an old staff tablet, a replaced office PC — and remove them.
What staff see on an unapproved device
A staff member signing in on a device you haven’t approved gets a Device not authorised page naming your setting, with a short explanation and a description of the device they’re on. They are told to ask a manager to sign in on it once.
If they belong to another setting that doesn’t use authorised devices, they are signed in to that one as normal — only the restricted setting is withheld.
Getting staff onto the mobile app
On a shared device, staff switch to their account with a PIN. Normally they set their own PIN from My Account on the web — but at a setting using authorised devices, a new starter may never be able to sign in on the web to do that.
Instead, send them a PIN yourself: on the Staff page, open the row actions for the staff member and choose Send PIN. The PIN is generated for them, emailed to them, and shown to you once. If they didn’t have a login yet, one is created automatically — the PIN works on the approved device straight away, with no sign-in needed first. See Staff Management for the details.
Frequently Asked Questions
How does Pigeonhole recognise a device?
When someone first visits the sign-in page, Pigeonhole stores a small identifier on that device — in the browser for the web app, and in the phone’s secure storage for the mobile app. That identifier is what your device list is matched against.
What if someone clears their browser data?
The identifier is cleared with it, so the device looks brand new and a manager needs to approve it again. The same applies to signing in through a private or incognito window, or to a different browser on the same computer — each browser counts as its own device. Reinstalling the mobile app can have the same effect.
Does each browser on the same computer need approving separately?
Yes. Approving Chrome on the office PC does not approve Edge or Safari on it. Approve whichever browser your staff actually use.
Can a staff member approve their own device?
No. Only managers, owners, and organisation owners are offered the option, and the choice is re-checked when it’s submitted.
I’ve removed the wrong device — what now?
Sign in on that device again with your manager account and approve it as new. Nothing is lost; anyone who was using it just has to sign in again.
What happens if I turn the feature off?
Everything goes back to normal immediately — staff can sign in from anywhere again. Your device list is kept, so turning it back on later restores the same approvals.
Should staff set up passkeys on an authorised device?
Not if the device is shared. A passkey on a shared iPad is unlocked with the iPad’s own passcode, so anyone who knows it could sign in as that staff member. On shared devices, have a manager sign in to the mobile app once and let staff switch to their own account with their Pigeonhole PIN. See Which sign-in method should I use?
Will I ever be locked out?
No. Managers, owners, and organisation owners bypass the device check entirely, on every device. Even if the list is empty or every device on it is removed, you can still sign in and approve a new one.