A customer record can exist in three states, shown as a badge on their page: Verified (has a login and can sign in), Unverified (signed up but has not confirmed their email yet), and Guest (a record with no login, typically from a guest checkout). The Account card on the Customer Details tab manages all of it.
Granting login access
On a guest record, click Grant login access. Give them a username, and either set a password yourself or (better) leave Send a setup email checked: the customer receives a welcome email with a link to choose their own password.
Verifying an unverified account
A customer who never clicked their verification email can be helped along: Resend verification sends the email again, or Mark as verified activates the account on your say-so (useful on the phone). Unverified accounts that never verify eventually become guest records automatically; nothing is deleted.
Password resets and username changes
On a verified account, the card offers a password reset (emailed link) and lets you change the username.
Revoking access
Revoke login access turns a verified account back into a guest without losing anything: their orders, wants, and history stay, and Restore login access undoes it later.
About duplicate emails
Only login accounts require a unique email; guest records can share one (each guest checkout makes its own record by design). If you edit a customer's email to one that belongs to a login account, the page warns you before the save is rejected, with a link to review and merge the duplicates instead.
Every account action leaves a trace: grants, revocations, and verifications are stamped into the customer's Notes automatically, so you can always see who did what and when.