Some things should not happen because somebody picked up an unlocked phone. The Action PIN is the check on those.
What it protects
Commands that commit a decision on the organisation's behalf. Approving an expense. Marking an invoice paid.
The reasoning is simple: a WhatsApp message carries no proof of who is holding the phone. For reading a briefing that is fine. For releasing money it is not.
It also gates sensitive admin surfaces inside the platform itself, not only commands.
How it behaves
Enter it once and you have an eight hour session, so you are not retyping it through an afternoon of approvals.
The session is per device. Unlocking on your laptop does not unlock your phone.
Setting it up
An administrator sets the PIN for the organisation the first time somebody reaches a protected surface.
If you are not an admin and no PIN exists yet, you will be told to ask one rather than being allowed to set it yourself. That is deliberate: the person who sets the PIN controls the approvals.
If you get locked out
Repeated wrong entries lock the surface. Waiting clears it; there is no self-service reset, and an administrator can set a new one.
Do not share it to work around a lockout. A shared PIN makes the audit trail meaningless, and the audit trail is most of why the PIN exists. If several people genuinely need approval rights, give them approval rights.
Choosing one
Not a birthday, and not the same as your device unlock. It protects a different thing and should fail differently.
Did this answer your question?
No, ask a person