📖 NACH security: delegate access without sharing passwords


Everyone should use their own account

NA Chess Hub (NACH) lets organizers give staff the access they need without sharing the organizer's username and password. A tournament director, arbiter or assistant signs in to their own account and works through a delegation. You do not need to give them your password, verification codes, recovery codes or passkeys.

Sharing a login gives another person the same access as you, makes it harder to identify who performed an action, and makes it difficult to remove just that person's access. Use the narrowest delegation that covers the job instead.

Organizer-level delegation: ongoing help across events

Use Account Delegations in the Organizer Portal when a trusted player needs to create or manage events on behalf of your organization.

  • Event Creator: can create events for the organizer and manage only the events they created under that delegation.
  • Event Manager: can create events and manage all of that organizer's events, including events created by other people. Grant this broader access only when necessary.
  1. Ask the staff member to create and use their own NACH player account. Confirm that you have selected the correct person.
  2. Sign in to the organizer account, open the Organizer Portal, and find Account Delegations.
  3. Select Delegate a player, select the player and the appropriate level, and save.
  4. The player signs in using their own credentials and accesses the delegated work from their own portal. The organizer retains control of the events.

Organizer-level event delegation is not a transfer of the organizer login or permission to share its credentials. It is also different from the separately assigned site-wide Account Manager role.

Event-level delegation: help with one particular event

If someone is helping only with one tournament, delegate that event rather than granting access to every event of the organizer.

  1. Open the event's Details page using an account authorized to delegate it.
  2. Select Delegate, then Create New Delegation.
  3. Select the correct player and the minimum delegation level needed, then save.

The available event levels are:

  • TD - Rating, Email, Event Files: focused tournament-director tasks.
  • Event Admin: event administration, excluding cloning, deletion and delegation.
  • Owner - Full Control: full event control, including sensitive actions. Use sparingly.

The delegate uses their own account; an event delegation does not give them the organizer's password or general access to unrelated events.

Review and revoke access when the job ends
  • Review both account-level and event-level delegations regularly and remove access that is no longer needed.
  • Use Change Level or Remove for an account delegation, or Edit/Delete on the event's delegation list.
  • Revoking an account delegation removes the access granted by it, including an Event Creator's access to events they created. It does not delete those events.
  • Check both levels: removing an event delegation does not cancel broader account-level access, and removing an account delegation does not cancel a separate event delegation. Other valid permissions may still grant access.
  • If a password was previously shared, change it, review registered passkeys and delegations, and stop sharing verification/recovery codes. Delegation alone does not make an already-shared password private again.
Protect each person's own sign-in
  • Use a unique password stored in a trusted password manager.
  • Enable an authenticator app through Two-factor authentication for password sign-ins. Keep recovery codes private and somewhere you can reach if your phone is lost.
  • Consider adding a passkey on a trusted personal device. Passkeys are tied to the website and help protect against phishing; your device's private key is not sent to NACH.
  • Check that the address is https://www.nachesshub.com. HTTPS protects data in transit, but does not make an unfamiliar link or a request to share credentials trustworthy.
  • Do not register your personal passkey on a shared/public computer. Sign out when you finish and use keep-signed-in options only on private devices.

No security feature eliminates every risk. If you suspect unauthorized access or cannot recover your account, contact NACH support. Describe the issue, but never send passwords, device PINs, authenticator setup keys or recovery codes.

General
Everyone should use their own account

NA Chess Hub (NACH) lets organizers give staff the access they need without sharing the organizer's username and password. A tournament director, arbiter or assistant signs in to their own account and works through a delegation. You do not need to give them your password, verification codes, recovery codes or passkeys.

Sharing a login gives another person the same access as you, makes it harder to identify who performed an action, and makes it difficult to remove just that person's access. Use the narrowest delegation that covers the job instead.

Organizer-level delegation: ongoing help across events

Use Account Delegations in the Organizer Portal when a trusted player needs to create or manage events on behalf of your organization.

  • Event Creator: can create events for the organizer and manage only the events they created under that delegation.
  • Event Manager: can create events and manage all of that organizer's events, including events created by other people. Grant this broader access only when necessary.
  1. Ask the staff member to create and use their own NACH player account. Confirm that you have selected the correct person.
  2. Sign in to the organizer account, open the Organizer Portal, and find Account Delegations.
  3. Select Delegate a player, select the player and the appropriate level, and save.
  4. The player signs in using their own credentials and accesses the delegated work from their own portal. The organizer retains control of the events.

Organizer-level event delegation is not a transfer of the organizer login or permission to share its credentials. It is also different from the separately assigned site-wide Account Manager role.

Event-level delegation: help with one particular event

If someone is helping only with one tournament, delegate that event rather than granting access to every event of the organizer.

  1. Open the event's Details page using an account authorized to delegate it.
  2. Select Delegate, then Create New Delegation.
  3. Select the correct player and the minimum delegation level needed, then save.

The available event levels are:

  • TD - Rating, Email, Event Files: focused tournament-director tasks.
  • Event Admin: event administration, excluding cloning, deletion and delegation.
  • Owner - Full Control: full event control, including sensitive actions. Use sparingly.

The delegate uses their own account; an event delegation does not give them the organizer's password or general access to unrelated events.

Review and revoke access when the job ends
  • Review both account-level and event-level delegations regularly and remove access that is no longer needed.
  • Use Change Level or Remove for an account delegation, or Edit/Delete on the event's delegation list.
  • Revoking an account delegation removes the access granted by it, including an Event Creator's access to events they created. It does not delete those events.
  • Check both levels: removing an event delegation does not cancel broader account-level access, and removing an account delegation does not cancel a separate event delegation. Other valid permissions may still grant access.
  • If a password was previously shared, change it, review registered passkeys and delegations, and stop sharing verification/recovery codes. Delegation alone does not make an already-shared password private again.
Protect each person's own sign-in
  • Use a unique password stored in a trusted password manager.
  • Enable an authenticator app through Two-factor authentication for password sign-ins. Keep recovery codes private and somewhere you can reach if your phone is lost.
  • Consider adding a passkey on a trusted personal device. Passkeys are tied to the website and help protect against phishing; your device's private key is not sent to NACH.
  • Check that the address is https://www.nachesshub.com. HTTPS protects data in transit, but does not make an unfamiliar link or a request to share credentials trustworthy.
  • Do not register your personal passkey on a shared/public computer. Sign out when you finish and use keep-signed-in options only on private devices.

No security feature eliminates every risk. If you suspect unauthorized access or cannot recover your account, contact NACH support. Describe the issue, but never send passwords, device PINs, authenticator setup keys or recovery codes.