Boutique Operators let a thrift store or shop counter track who is running a checkout without giving that person a full CoolFocus login. Each operator signs in on a paired device with a short numeric PIN instead of a username and password.
Use this when the people working the shop counter (volunteers, part-time staff) need real attribution on every checkout and override, but should not have access to client, donor, or staff records.
Go to Settings > Points & Inventory > Boutique Operators. This is an administrator task: you need Material Support module admin rights or tenant admin rights to open it.
Pick a center from the dropdown at the top, then use New Operator to add someone to that center's roster.
When you create an operator you set:
• Display name, shown on the device and in the audit trail.
• PIN, 4 to 8 digits. CoolFocus stores only a hashed version and never displays or logs the plain PIN again.
• Supervisor, a toggle only staff admins can set. Supervisors can approve protected actions for other operators; regular operators cannot.
An operator's name must be unique within a center. You can rename an operator, change their supervisor status, or deactivate them at any time from the same list.
On a paired device, operators pick their name from a roster and enter their PIN. Signing in as a second operator on the same device automatically signs the first one out (quick switch); a device only ever has one operator active at a time.
An operator's session stays open while they are active and ends after 30 minutes of no activity (the device itself locks its screen sooner, after 5 minutes). Signing out, an admin PIN reset, or deactivating the operator all end the session immediately.
If an operator enters the wrong PIN 5 times within 15 minutes, that operator's PIN locks for 15 minutes. CoolFocus deliberately shows the same "PIN not accepted" message whether the PIN was wrong or the operator is locked, so a person testing PINs at the counter cannot tell which operators exist or which are currently locked.
If failed attempts pile up across every operator on one device, the device itself is throttled for 5 minutes after 20 combined failures in 15 minutes.
An administrator can clear a lockout early from the operator list, or reset the operator's PIN. Resetting a PIN signs that operator out of every device immediately.
Some actions at the counter need a supervisor's sign-off: letting a checkout overdraw a client's points balance, or waiving an item's redemption limit (a limit like "one car seat per client per year"). Instead of the supervisor taking over the device, the operator asks a supervisor to enter their PIN and give a reason on the spot. Operators cannot approve their own protected actions; only a supervisor's PIN clears the approval.
Overdraw approval and a redemption-limit waiver are two separate decisions. A checkout that is both short on points and over a cap needs a supervisor sign-off for each one, and CoolFocus records the two approvals independently rather than letting one satisfy the other.
Overdraw and a redemption-limit waiver are separate approvals, even on the same cart. A client who is both out of points and over an item's limit needs a supervisor to clear each one individually: approving the overdraw does not also waive the limit, and waiving the limit does not also clear the overdraw. This keeps the record honest about which decision the supervisor actually made.
That approval is single-use and expires within 120 seconds. It is tied to the exact device, the operator's session, the client, and the specific cart being checked out, so it cannot be reused on a different cart, carried to another device, or replayed later. If the cart changes after approval, the operator needs a fresh approval.
When the approval waives a redemption limit, the claim keeps the rule it waived and the supervisor's reason alongside the approval, so the exception reads correctly in an audit even if the limit's terms change later. See Claiming Items With Points for how this looks from the claim dialog.
An eligibility override is recorded twice: once in this operator's audit history, and again on the claim itself, alongside the supervisor's name, the reason given, and the redemption rule that was in effect. Staff reviewing a claim later can see the exception without having to cross-reference the operator log.
Every checkout completed on a paired Boutique device records three identities independently: the device it came from, the operator who was signed in and rang it up, and, when a supervisor approved an overdraw or limit waiver, the supervisor who signed off and why. An ordinary checkout that trips no limit still records its device and operator; attribution does not depend on something going wrong.
Device and operator are stored separately from any supervisor approval, so an approval is never mistaken for the person who actually ran the transaction, and never merged into either one.
Staff reviewing any checkout later—not just the ones that hit a limit or overdraw—can see exactly which device rang it up and which operator was signed in, straight from the checkout record itself rather than only from the operator's own audit history.
Every operator has an audit history (the clock icon in the operator list) showing sign-ins, failed attempts, lockouts, PIN resets, activation changes, and supervisor approvals with who approved them and why. Checkout receipts carry the same device, operator, and supervisor attribution, so a disputed transaction can be traced back to the exact device and operator without cross-referencing this log. Use this to review counter activity or investigate a disputed checkout.
• Points & Inventory Overview
• Claiming Items With Points
• Boutique Devices: Pairing Phones for Checkout
• Boutique Client Cards: Issuing and Scanning QR Credentials