Skip to content

Roles and permissions

A role is a bundle of permissions that an employee gets when assigned to it. Roles live at the store level — one store can have many roles.

Roles list

  • Presets come with every store: Admin, Manager, Employee, Cashier.
  • Custom roles — owners create them when presets don’t fit.

You can tune presets (add / remove modules) but cannot delete them.

Each module controls access to one feature area. Levels are:

LevelWhat it lets you do
NoneNo access — the menu / page is hidden / blocked.
ReadView only. Cannot create, edit, or delete.
WriteCreate and edit. Most day-to-day users want this.
ManagerFull CRUD — also delete and reassign. Required for staff management.
ModuleLets you access
dashboardHome page, KPIs.
orderOrders list, create order, work shifts, deliveries.
posFullscreen POS lane and POS workspace.
productCatalog (products, categories, units, attributes, tags, suppliers, gallery).
inventoryWarehouses, stocks, lots, adjustments, transfers.
customerCustomers and categories.
couponDiscounts / coupons.
financeSales reports, refunds, transactions, expenses, receivables.
storeStore list and configuration.
employeeEmployees / staff management.
settingsNotifications, devices, terminal, shift templates.
roleRoles editor (owners only).
notificationMessages to staff.

If a module is None, the link in the sidebar is hidden — but bookmarked URLs still hit the access gate, so don’t share links an employee can’t open.

PresetHighlights
AdminEvery module write or manager. Can’t edit roles itself.
ManagerOrders / inventory / customers / finance manager; employee manager so they can CRUD staff; product.view_cost capability.
EmployeePOS, orders, basic inventory, customers read.
CashierLane only — pos write, plus order / product / customer read so the cashier can browse and look up.

Tip for owners: start with Manager for supervisors, Employee for part-timers, and Cashier for lane-only staff. Reserve Admin for yourself / a co-owner.

  1. Owner opens Roles → picks a row.

Managers list

  1. Edit to add or remove modules / change level.
  2. Save. Employees pick up the change on next sign-in or token refresh.

Removing a module hides the link the moment the page reloads — they won’t lose data, they just can’t open the screen anymore.

Employee still sees the old role after I change it. They need to reload the page or sign out / sign in. The change applies on the next token refresh.

Removing pos write broke my cashier. Yes — without pos write they can’t open the sale screen. Put pos back to Write for cashiers.

A preset has a level I don’t want. Open the preset, switch to None (or any level you prefer) on the specific module, save. Presets are templates — they can be tuned.

I want one employee to view cost and another not to. Make two custom roles: one with product.view_cost, one without. The view_cost is a capability granted via product’s manager level.