E-commerce
September 3, 2026
Are you wondering how to manage concerns related to connected devices and customer account security? This is a crucial issue: a customer who does not understand why an unknown device appears can quickly lose trust in your store, directly threatening loyalty and conversion. This topic is complex because it requires distinguishing a simple technical anomaly from a genuine security breach without unnecessarily alarming the visitor or violating their privacy. So, Customer Account: how to manage access and security of connected devices? On the agenda: How to identify legitimate sources of suspicious connections to reassure without downplaying? What criteria should be used to differentiate familiar device sharing from an intrusive attempt? What precise steps should you guide the customer through to secure their account immediately? Why is it imperative to escalate certain sensitive cases to human support without delay? Let's get started.
Summary
Why do connected devices worry customers so much?
When a customer checks their account and discovers a device they do not recognize, the immediate reaction is often a suspicion of hacking. This visual alert can also reveal the presence of an old phone forgotten by the visitor themselves, or even access by a family member connected with their consent.
The response provided by your tool must therefore be balanced: it must be reassuring while remaining extremely precise about the nature of the device. The chatbot must help distinguish a normal connection, perhaps due to a recent browser change, from a real risk signal requiring intervention.
It is crucial that the assistant never downplays a potential security alert, as this could expose your brand and your customers to financial losses. Conversely, it must under no circumstances ask the customer to share their password or a sensitive verification code directly in the conversation, which would be a serious violation of current cybersecurity standards.
An unknown device does not automatically mean fraud, but it always deserves a quick and structured check to restore the user's peace of mind. The goal is to transform a panic fear into a controlled action.

Convert over 2,000 customers on average per month with Qstomy.
The world’s 1st Shopify AI dedicated to customer conversion



Empowering 200+ e-commerce merchants
What technical information should the customer check as a priority?
To diagnose the situation, the chatbot must be able to query and display the key metadata of the suspicious connection. This includes the exact type of device, often referred to as the terminal identifier or browser model used for access.
The dialogue must also reveal the date and time of the last active connection, as well as the approximate location if available in the system logs. It is also relevant to examine recent usage associated with this device: a recently placed order or a profile change?
Additionally, the bot must inquire about contextual factors with the customer: did they recently change their phone? Did they use a shared computer at work or in an internet cafe? Did they install a new mobile application that might have created a new link?
Finally, the question of account sharing must be addressed, as some customers share their credentials with relatives. These details help avoid unnecessary escalation and help understand whether the risk signal is real or a false positive.
How to effectively guide the disconnection of a device?
If your platform allows it, the chatbot must clearly explain the logout procedures available to the user. It can indicate how to remove a specific session identified as problematic or how to force the logout of all connected devices simultaneously.
This action must be imperatively accompanied by a strong recommendation: if the client does not recognize the access or if they have a persistent doubt, they must immediately change their password. This is the most effective security measure to isolate the intruder.
It is essential to specify that some sessions may remain active for a few minutes before being actually invalidated, depending on the technical settings of the application or website. Sometimes, a new connection is required to validate the recent security update.
The guidance must be smooth: identify the device concerned, confirm the logout action with the client, and ensure they have the new access credentials before closing the sequence. This transforms a complex technical procedure into a simple action for the user.
What procedure should be followed when dealing with a completely unknown device?
Faced with an alert confirming a completely unknown device, the chatbot must propose a clear four-step method to regain control of the situation. The first step is always to verify the technical details provided by the system to confirm the anomaly.
The second step is to initiate or validate the immediate disconnection of this suspicious device from the customer account. The third step requires forcing a secure password change to invalidate any future unauthorized access attempts.
Finally, if the tool allows, it is necessary to recommend and activate additional security, such as two-factor authentication (2FA) or SMS alerts. However, if this alert is accompanied by an order placed, a payment made, or a modification of sensitive data from this unknown access, the logic changes radically.
In this critical case, the chatbot must not attempt to resolve the issue alone but must immediately transfer the case to the security support team. This is a strict limit to be respected to avoid any financial damage to the customer.
How to approach the delicate question of account sharing?
It is common for some customers to share their e-commerce account with a relative, a team member, or for family reasons, sometimes using the same credentials on multiple devices. The chatbot must explain the risks inherent in this sharing without ever using an accusatory or judging tone.
The real risks include full visibility of past orders, saved delivery addresses, payment methods, and stored personal preferences. The exposure of this data can become problematic in the event of a conflict between partners or the end of a family relationship.
The bot must guide toward safer solutions: creating separate accounts for each user or using appropriate permissions if your service offers it. This helps limit access while maintaining the convenience of the shopping experience.
The goal is to educate the customer on the benefits of separating digital identities for better protection of their personal data and purchase history over time.
What logical flow should be followed to protect the account without causing panic?
The conversational flow must be designed to protect the customer account while avoiding generating unnecessary panic for the user. The first phase precisely identifies the device concerned, the account to which it is linked, the date of the suspicious activity, and the nature of the channel used.
Next, it is necessary to verify whether this access corresponds to a recent legitimate use, or if it is an old forgotten device or a temporary sharing. This contextual analysis is vital to avoid false positives that frustrate the customer.
The process continues by explaining how to disconnect the specific device or all sessions if the feature is available. The chatbot must then recommend changing the password and activating enhanced security if any doubt persists.
Finally, any suspicion of illegitimate access, unknown order, fraudulent payment, or blocking data modification must automatically trigger a transfer to human support. This is the guarantee of a secure and smooth journey for the user.
What specific messages should be used to reassure and secure?
The tone used by the chatbot is crucial for maintaining trust. To reassure, an effective phrasing can be: "An unknown device can come from an old phone or a shared browser, but we will check it carefully with you."
To establish security without ambiguity, firm messages must be used, such as: "Never share your password or a verification code in this conversation. This would allow anyone to access your banking details."
When a sensitive action is detected requiring human intervention, the transfer message must be clear: "As a sensitive action seems linked to this unknown access, I am immediately forwarding your file to support with the elements we have already gathered."
These precise formulations avoid alarmism while showing that the customer's security is your service's absolute priority and that concrete action is underway to protect them.
What criteria trigger human intervention and handoff?
Transferring to a human agent is not a failure but a crucial security step. It is necessary when the customer absolutely does not recognize the reported device, which suggests an unconsented takeover.
Human intervention must also be requested if an order or a payment appears suspicious from this access, as this implies an immediate financial risk. Likewise, any modification of sensitive personal data must trigger an alert.
If the account is blocked by the security system due to a persistent anomaly, or if the attempt to log out of the device fails despite the chatbot's attempts, the transfer is essential. The bot must then transmit a comprehensive summary including the account, the device, the date, the suspicious action, and the steps already attempted.
This level of urgency allows human support to prioritize resolving the issue with the necessary technical tools to permanently lock out unauthorized access and secure the customer's account.
Which performance indicators should you track to improve your security?
To continually optimize the management of connected devices, it is imperative to track specific key performance indicators (KPIs) related to security and user experience. The number of unknown devices reported by clients constitutes a primary key indicator of vigilance.
It is also necessary to monitor the rate of successful disconnections following chatbot instructions, as well as the number of password changes made immediately after a security alert. These metrics show the responsiveness of users to recommendations.
Tracking accounts blocked for security reasons and the number of tickets processed by the "security" department provides a global view of incident frequency. Finally, complaints related to unrecognized actions are a sensitive indicator of the effectiveness of detection processes.
These indicators make it possible to evaluate whether the device management interface is clear and reassuring, and to adjust the chatbot's algorithms to better prevent future incidents.
What fatal errors must absolutely be avoided in access management?
Certain common practices can seriously compromise customer security and trust if implemented carelessly. Minimizing or brushing off an unknown device must be avoided, as this leaves the customer vulnerable to a potential attack.
A critical error is asking the customer for sensitive information, such as a full password or a verification code via chat. This is a major security flaw that any modern system must prevent.
You should never promise the immediate and complete removal of a device without prior technical confirmation, as this can create a false sense of security or inconsistencies in the logs. Similarly, leaving an anxious customer without providing a clear path to securing their account is unacceptable.
The chatbot's sole mission must be to help the customer regain full and secure control of their account, guiding each step with caution and precision to avoid any confusion or accidental escalation of the issue.
How specifically does Qstomy help secure the mobile and desktop experience?
Qstomy acts as a specialized AI agent capable of connecting the chatbot directly to customer accounts to securely access associated device lists. The tool can query privacy policies and product catalogs to provide accurate answers regarding legitimate uses.
It also manages consignment statuses, consumables, and contextual help messages to clearly answer technical questions without inventing information. The Qstomy chatbot helps the customer progress in their security steps without ever disclosing or displaying an uncertain device status.
When a sensitive case is identified, Qstomy transfers the entire context to human support with an actionable summary for quick resolution. This helps maintain context between mobile and desktop, ensuring that the user does not have to repeat their information.
Finally, Qstomy helps manage complex cases such as name errors on an order or problems with in-store testing before purchasing online, while strictly respecting data confidentiality and security protocols defined by the merchant.
What checklist should be applied to secure a flagged customer account?
Key steps to securing the account
Identification: Verify the device type, location, and recent history.
Validation: Confirm whether the access is recognized (family, old phone) or suspicious.
Action: Disconnect the device and force a password change.
Securing: Enable two-factor authentication if it is not already active.
In brief
Managing connected devices relies on a balance between technical support and strict protection. The customer must understand how to identify suspicious access without panicking. Qstomy facilitates this process by centralizing security data and triggering a transfer to a human expert when necessary.
Quick FAQ
Q: Should I ask the customer for their password?
A: No, never. This is a security violation.
Q: Does an unknown device always mean a hack?
A: No, it could be an old, forgotten device or family sharing.
To go further: Out of stock on a single size: helping the customer choose between waiting, an alternative, and a stock alert - Qstomy, Product seen in a short video: helping the customer find the exact item and verify what is shown - Qstomy, Integrating customer service answers into an e-commerce SEO strategy useful to customers - Qstomy, How to handle customer questions about in-store trials before online purchase - Qstomy, Training an e-commerce chatbot with Shopify: using the right data without creating wrong answers - Qstomy, Name error on an order: correcting what can be corrected before the package gets stuck - Qstomy, Click & Collect: helping the customer pick up without surprises - Qstomy.

Enzo
September 3, 2026


