Field notes › Choosing software

Why 2FA on workforce systems is non-negotiable

Two-factor authentication is one of those controls everyone agrees with in principle, then quietly skips because it adds a step at login. On a workforce system that is a bad bet, and you are not placing it only for yourself. You are placing it for every worker whose licence photo and home address sit behind that login.

What a rostering login actually protects

Think about what a coordinator account can see in a labour hire system. Full personal details for the whole pool. Copies of licences and certificates, which are precisely the documents someone needs to impersonate a person. Fit-for-work declarations. Which sites people work on, and where they are sleeping while on swing. That is not scheduling data with a bit of personal information attached. It is a personal information system that happens to draw rosters.

An intruder does not have to steal anything to do damage, either. With a working login they can change things: quietly edit shifts, redirect communication, or walk out with your client and worker lists.

Passwords fail in boring ways

The attacks that catch businesses are rarely clever. Someone reuses a password across a dozen services, one of those services gets breached, and automated tools try the leaked combination everywhere else. Or a convincing email harvests a login on a fake page. None of this is targeted, and none of it cares how small your company is or how uninteresting you think your data would be to a stranger.

DashboardON SITE NOW12UNFILLED SHIFTS3EXPIRING SOON5Expiring in the next 60 daysWorking at Heights · 2 workersRemindSite induction · 3 workersRemind12
The office dashboard: who's on site, what's unfilled, what's expiring.

Two-factor authentication turns most of those wins into dead ends, because the stolen password stops being enough on its own. It is not a perfect control, nothing is, but it moves you from a closed door to a locked one, and it costs each user a few seconds a day.

Optional 2FA is a chore you own forever

Plenty of software offers 2FA as a setting, which sounds like the same thing and is not. Optional 2FA means someone in your business now owns an enrolment campaign that never ends: new starters, holdouts, and everyone whose phone changed since last time. The people least likely to turn it on are often the busiest ones with the most access. Enforced 2FA on every login removes the campaign. There is nothing to chase, because there is no way to opt out.

The front door matters too. A system with public signup lets anyone on the internet create an account and start probing. Mustr is invite-only, with no public signup and 2FA on every login, for workers, clients and admins alike.

Other people will ask you about this

Even if you are never attacked, the question is coming from somewhere. Cyber insurance proposal forms ask about multi-factor authentication. Client procurement questionnaires ask about it. If you supply crews to mine sites, your client's security people may hold your systems to standards not far off their own. "Yes, enforced on every login" is a one-line answer that ends the topic. "It is available and we encourage people to turn it on" invites a follow-up meeting you do not want to sit through.

Five minutes of checking

  • Does your current rostering system support 2FA at all?
  • Is it enforced for every account, or optional?
  • Do client portal users and workers get the same protection as admins?
  • Can anyone on the internet create an account, or is access invite-only?

If any of those answers made you wince, it is cheaper to fix now than after someone tests it for you. The workers on your books are trusting you with the documents that prove who they are, and that trust is worth more than the few seconds a second factor costs at login.

If you want a workforce system where the security answers are already yes, book a demo.

Bring one roster to the demo. We'll show you Mustr running it.

Book a 20-minute demo