Team, roles & permissions
Invite staff, pick the right role, and grant only the permissions each job needs — refunds, discounts, purchasing, reconciliation and finance figures.
Invite a member
Organization → Members
Open Organization → Members and click Invite member.
Enter their email address and choose a role: Admin or Member.
Admin holds every permission in the organization. Member holds nothing until you grant it — which is what you want for most staff.
Click Send Invite.
They open the link in their email and land on the Join Organization page.
They click Join Organization and sign in — or sign up if they are new.
They then appear in the Members list with their role.
The invitation carries only Admin or Member. The role that decides what they can do, and the branches they can do it in, are set afterwards on the Members list.
Read this diagram as text
- Send invite → They open the emailed link
- They open the emailed link → Do they have an account?
- Do they have an account? → Sign in (yes)
- Do they have an account? → Sign up, then verify (no)
- Sign in → Join Organization
- Sign up, then verify → Join Organization
- Join Organization → Do they run the business?
- Do they run the business? → Set as Administrator (yes)
- Do they run the business? → Give them a role (no)
- Give them a role → Assign their branches
- Assign their branches → Ready to work
- Set as Administrator → Ready to work
Invite as Member, then give them a role and their branches
Administrator is all-or-nothing and reaches every branch, so keep it for the people who run the business. Everyone else comes in as Member, holds a role you chose, and works only at the branches you assigned.
Changing someone's level later
On the Members list, the menu beside each person offers Set as Administrator, Set as Member, and remove. An owner cannot be demoted or edited from here, and members without admin rights cannot manage anyone.
Roles and what they can do by default
Organization → Members
Access is decided by three things: the level someone holds, the role they carry, and the branches they are assigned to. Owners and administrators reach every branch. Everyone else reaches only their own — and inside those, only what their role permits.
| Level | What it means |
|---|---|
| Owner | The person who created the organization. Holds everything, cannot be demoted or edited from the Members list |
| Administrator | Holds every permission implicitly. Can invite, remove and set other members' access |
| Member | Holds nothing until you tick permissions for them. This is where most staff belong |
Three separate things
Job title is what the person is called — Head Chef, Senior Cashier — and grants nothing. Role is the permission set they hold. Branches are where that role applies. Keeping them apart means fifty job titles do not need fifty permission sets.
The roles every organization starts with
| Role | Holds |
|---|---|
| Manager | The branch, end to end: refunds, purchasing, settings, finance |
| Supervisor | Floor cover: refunds and voids, without the money figures |
| Cashier | Sell and reconcile. No refunds, no price changes |
| Waiter | Sell, work the floor, manage bookings |
| Kitchen | The kitchen board and the menu, nothing else |
| Storekeeper | Stock, suppliers, purchasing, transfers |
| Accountant | Reports, finance, reconciliation. Changes nothing on the floor |
These are a starting point, not a fixed list. Edit any of them, or build your own — a Duty Manager who can refund but not touch settings, a Bar Lead who runs the bar station only.
Creating roles, feature by feature
Organization → Roles
| Permission | Unlocks |
|---|---|
| Create orders | Take orders at the POS and send them to the kitchen |
| Refund orders | Refund a paid order and return its stock |
| Void orders | Void or delete an order |
| Change prices | Override an item's price at the point of sale |
| Manage discounts | Create and edit discount codes |
| Manage inventory | Edit stock items, categories and thresholds |
| Manage menu | Edit menu items, categories and recipes |
| Manage purchasing | Purchase orders, goods receipts, credit and debit notes |
| Reconcile | Run end-of-day cash, card and M-Pesa reconciliation |
| View reports | Sales, product and staff reports |
| View finance | Revenue, cost, profit and VAT figures |
| Manage settings | Branch settings: tax, service charge, eTIMS |
| Manage reservations | Create and manage table reservations |
| Kitchen | Advance tickets on the kitchen display |
Build a role
Open Organization → Roles and click New role.
Name it after the job — Duty Manager, Bar Lead, Receiving Clerk.
Add a line describing who it is for while you remember.
Tick permissions feature by feature.
They are grouped by area — Selling, Catalog, Front of house, Supply, Money & oversight, Administration. Select a whole area, then untick the exceptions.
Save. The role is available to everyone in the organization immediately.
Put someone in a role, at their branches
Open Organization → Members and use the menu beside the person.
Choose Role & branch access.
Set their job title, pick their role, tick the branches they work at.
Job title is for your records. The role decides what they can do; the branches decide where.
Save. It applies on their next action — no re-invite needed.
Rules worth knowing
- Only owners and administrators can create roles or change anyone's access.
- Mark one role as the default and anybody who joins without a role of their own holds it. Leave it unset and they hold nothing until you decide.
- Built-in roles can be renamed and re-permissioned, but not deleted.
- Deleting a custom role leaves its holders with no role until you give them one.
- A member with no branches assigned can sign in and reach nothing.
- An individual grant can still be added on top of a role for a one-off exception.
- Sensitive permissions are flagged in the picker so they are not ticked by accident.
The same check runs on the server for every sensitive action, so hiding a button is never the thing keeping you safe.
Read this diagram as text
- Member attempts an action → Signed in?
- Signed in? → Member of this organization? (yes)
- Signed in? → Refused (no)
- Member of this organization? → Assigned to this branch? (yes)
- Member of this organization? → Refused (no)
- Assigned to this branch? → Owner or administrator? (yes)
- Assigned to this branch? → Refused (no)
- Owner or administrator? → Action runs, and is written to the audit log (yes)
- Owner or administrator? → Does their role or an individual grant hold the permission? (no)
- Does their role or an individual grant hold the permission? → Action runs, and is written to the audit log (yes)
- Does their role or an individual grant hold the permission? → Refused (no)
Permissions are enforced on the server
Hiding a button is not the control — every privileged action is re-checked on the server. A cashier without refund rights cannot refund by any route, and price overrides sent from a till without Change prices are ignored in favour of the catalog price.
How to shape access for a typical shop
Give each person the smallest role that lets them do their job, at only the branches they work. These combinations cover most shops.
| The job | Role to use, or build |
|---|---|
| Cashier | Create orders, Reconcile |
| Supervisor | Create orders, Refund orders, Void orders, Manage discounts, Reconcile — or make them an Administrator |
| Accountant | View reports, View finance, Reconcile |
| Inventory manager | Manage inventory, Manage purchasing |
| Kitchen or bar staff | Kitchen |
| Waiter | Create orders, Manage reservations, Kitchen |
- Keep Refund orders and Void orders away from the till. A second pair of eyes on a reversal is the cheapest fraud control there is.
- Change prices is stronger than it looks — it lets someone sell at any price they type. Grant it sparingly.
- View finance exposes cost and margin. Most floor staff have no reason to hold it.
Audit follows the person
Refunds, voids, reconciliations and other sensitive actions are written to the audit log with the member who performed them. Do not share one login between staff, or the trail is worthless.
Who reaches which branch
Organization → Members → Role & branch access
An administrator reaches every branch, including ones you open later. Everybody else reaches only the branches ticked on their access dialog — a cashier at Westlands cannot read, sell or refund at Kilimani, and a branch id typed into a request returns nothing.
- Somebody covering two outlets simply gets both ticked.
- The branch switcher only lists what they can reach, so there is nothing misleading to click.
- Untick a branch and their access there stops at their next action.
- A new branch reaches nobody but administrators until you assign people to it.
Sessions on a shared terminal
Dashboard → Settings → Point of sale
Session timeout (minutes) locks an idle terminal and sends the user back to sign-in. On a till that sits in a public area, keep it short. Staff should clock in on Shifts at the start of their run so their sales, and the drawer they are accountable for, are attributed correctly.