Overview
Sign-In Only Emails are specialized accounts designed for use on Self Sign-In kiosks within Mindbody sites. These accounts are intentionally restricted at both the Exos system level and within Mindbody to ensure a secure, kiosk-only experience for member check-in.
By limiting access to only essential functionality, Sign-In Only Emails help prevent unauthorized access to applications, member data, and system settings.
Why Use Sign-In Only Emails?
Using Sign-In Only Emails ensures:
- A secure, locked-down kiosk environment
- Faster and more efficient member check-in
- Protection of sensitive member and business data
- Elimination of access to non-essential tools and systems
How It Works
Sign-In Only Emails operate with two layers of restriction:
1. Exos-Level Restrictions
These accounts are restricted at the organizational level to prevent access outside of kiosk functionality.
Users cannot access:
- Google Drive
- Workday
- Vivo
- Any other Exos applications or internal systems
Result:
The device is limited strictly to its intended kiosk purpose and cannot be used for general browsing or internal tools.
2. Mindbody Permission Restrictions
Within Mindbody, permissions are configured to allow only check-in functionality.
Allowed:
- Staff Sign-In
- Self Sign-In
Not Available:
- Staff dashboards
- Client profiles or member data
- Scheduling tools
- Reports and analytics
- Payment and transaction screens
- Settings and configuration menus
Result:
The user interface is limited to the check-in experience, with all other screens removed or inaccessible.
Kiosk Workflow
- Log into the kiosk using a Sign-In Only Email
- Launch Self Sign-In mode
- Members check in by searching for their profile
- No additional navigation or system access is available
Security Benefits
Sign-In Only Emails are designed to reduce risk and improve data protection:
- Prevent access to personally identifiable information (PII)
- Eliminate risk of unauthorized staff actions
- Block access to sensitive systems and applications
- Reduce the likelihood of accidental system changes
Even if a user attempts to exit the check-in flow:
- Exos restrictions prevent access to the device or other applications
- Mindbody permissions prevent access to platform features
Best Practices
- Assign one Sign-In Only Email per kiosk device
- Do not use these accounts for staff or administrative tasks
- Ensure kiosk devices are physically secured
- Configure devices to launch directly into Self Sign-In mode when possible
- Periodically review permissions to confirm restrictions remain in place
Summary
Sign-In Only Emails create a secure, single-purpose kiosk experience by combining:
- Exos-level system restrictions
- Mindbody-level permission controls
This ensures that kiosk devices remain focused on member check-in only, improving both security and operational efficiency across all locations.