Scope
Owners only. This page contains the master code procedure, so it must never be moved to the Employee Handbook, which every barista can read. What staff need is already in the Cash Handling SOP: you have your own code, you never lend it, and four wrong entries lock the keypad for five minutes.
The lock
Mesa MFL2014E depository safe with an MSL-500 electronic lock. One master code plus user codes, 3–8 digits each, with a concealed emergency key override. Mesa technical support: 800.490.5624, Mon–Fri 7am–4pm PST.
Capacity is genuinely unclear: the manual’s feature list says Users 1–5, but its own programming steps only accept 1, 2, 3 or 4. Confirm by programming User 5 once. Until that works, treat 4 as the ceiling.
Do this before the safe holds anything
The factory master code is 1-2-3-4-5-6-7-8, and it is printed in a manual anyone can download. Change it before a single dollar goes in.
Change master: * * 8-8-8 # OldMaster # NewCode # NewCode #
How to read the lock
Two beeps means the step was accepted. Five beeps means it failed — start the sequence over. A green light means success. Four wrong codes lock the keypad for five minutes and it will accept nothing during that window.
Always program with the door OPEN, and test the new code several times before closing it. A mis-programmed code on a closed safe means the emergency key or a locksmith.
The rule that makes this work
One person, one code, never shared.
Never set a barista’s code and then tell them what it is. If you know their code, every access under it is deniable — “you knew my code” — and that destroys the attribution the per-user codes exist to create.
Adding a holder — two steps, with them standing there
You activate a throwaway code: * * 3-3-3 # Master # User# # 1111 # 1111 #
They immediately change it to their own, with you not watching the keypad: * * 4-4-4 # 1111 # User# # TheirCode # TheirCode #
Changing a user code needs only that user’s own current code, not the master — which is exactly what makes step 2 possible. You keep the master, so you can always open the safe and always delete their slot. You lose nothing by not knowing their digits.
Then record who holds the slot in the Pepper dashboard, Cash tab. The code itself is never written down, anywhere, by anyone.
Removing a holder
Delete: * * 6-6-6 # Master # User# # User# #
Do this on their last day, as part of offboarding — /offboard Phase 5b covers it. Look the slot up in the Cash tab first, because guessing revokes the wrong person, then clear the slot there afterwards.
If they left on bad terms, change the master too. They may have watched you enter it.
Time delay — leave it off
The lock can delay opening by 1 to 59 minutes. Leave it at 00.
Set: * * 1-5-9 # Master # 00 #
It exists to deter robbery in high-cash retail, and here it fights our own process: baristas pull change mid-shift, and a delay during a rush recreates the exact “we ran out, so I forgave the change” failure this whole system was built to stop. The master code overrides the delay anyway, so switching it on would only ever penalise the staff.
Choosing digits
No 1234. No birthdays, phone fragments, or the café street number. Three to eight digits are allowed; use at least four.
Where the record lives
Pepper dashboard → Cash → Safe keypad codes. That table records which person holds which User slot and nothing else. Codes are never stored there, including by you.