Skip to content

FAQ — Access & Roles

import { Aside } from ‘@astrojs/starlight/components’;

Cause: The employee account is missing the pos or order write module.

Fix (store owner):

  1. Sign in to vendor web with the owner account.
  2. Open Employees → Roles → edit the employee’s role.
  3. Enable the POS write module (or order write for the dashboard POS).
  4. Save — the employee should sign out and sign back in to apply.

See: Roles (Vendor).

Cause: The route requires a module not present in your profile.modules.

Fix:

ScreenModule neededAction
/point-of-sale/salepos writeAsk owner to enable POS write on the role
/point-of-sale/ordersorder readAsk owner to enable Order read
/point-of-sale/customerscustomer readAsk owner to enable Customer read
/point-of-sale/returnsorder writeAsk owner to enable Order write
/point-of-sale/settings/*settings writeAsk owner to enable Settings write

Note: The store owner usually passes every POS route (because they have settings + pos write).

See: Sign in & access.

Cause: The role is missing customer read in profile.modules.

Fix: Ask the owner to enable the Customer (read) module in Employees → Roles. Then sign out / sign in to apply.

Cause: Opening Settings needs settings read (any employee has it), but saving CRUD needs settings write or pos write.

Fix:

  • Ask the owner to check the role has both: settings read + settings/pos write.
  • In practice, only the store owner should configure hardware.

Cause: The employee belongs to only one store in the system (profile.store_id is fixed).

Fix:

  • If the employee genuinely works at multiple branches: the owner must assign more store_id values in Employees → Detail → Stores.
  • If the employee only works at one store: this is the correct configuration; no change needed.

See: Employees & stores.

Send to the store owner — they can adjust the role. If the owner is also blocked, contact support@lionpos.com.

IDScenario
P3Employees without pos / order write cannot open Sale
TC-PS2-003Accessing an out-of-tenancy store → 403 on API