Standard Practices when Creating New GRUBBRR Portal Users
Last updated: August 25, 2026
On April 21, 2025, GRUBBRR's Engineering Team released a critical security update that will change the way that we handle user accounts and passwords in the GRUBBRR Portal platform. Here's what you need to know about this update.
For all Company/Location Users Created On or After 4.21.25:
All User Logins must be tied to an active email address
The "Show Password" tool will no longer be available for these users in the SuperAdmin Portal
Instead, we will offer a "Reset Password" option, which will send an automated email to the associated account with a password reset link
Users will be sent an email asking them to create a new password when the Company/User is first created
For all Company/Location Users Created Before 4.21.25:
Existing users will continue to function as they have previously:
We will still have the ability to use the "Show Password" tool
We do not need to change any existing emails or passwords
The "Reset Password" tool will not be available
Standard Procedures for Creating New Companies
As part of this update, we adjusted the process we use for creating new Companies/Locations through the SuperAdmin Portal. Going forward, when we create a new Company:
When creating new companies or internal admin accounts that we would use to manage a company/location, enter newacct+[[clientname]]@grubbrr.com; this is a unique email group that will send a password change request to support@grubbrr.com, allowing us to create and manage the new organization's password internally
The Menu Team & the Support Team will receive a notification, and a ticket will be created in salesforce so that we can track these new accounts going forward
These Credentials should never be shared with clients; instead, we should create Company-level users for the client following the rules outlined above
This will ensure that we are tracking changes made by GRUBBRR vs. changes made by the client's team
If a client needs help resetting their password, we can use the Reset Password tool to send them the automated email
We will not have visibility into the client's credentials at any level
Standard Procedures for Creating New Users
When creating new user accounts that for a company or location, we need to enter the active email (without any prefix or other changes) of the primary point of contact for that location, or the email of any additional users that the client has asked us to create
The system will then create an account and send that person an email asking them to set/change their password; we will not be able to access this password in the backend
If a client needs help resetting their password, we can use the Reset Password tool to send them the automated email