Roles & permissions
Every person you add to tech-pos gets one role per store. The role decides what they see when they log in and what the till lets them do. This page lists the thirteen roles, explains the reasoning behind each one, and shows the five separate reasons a button can be missing.
What a role actually is
A role is a fixed bundle of permissions. You do not tick boxes one by one — you pick a role, and the role carries its bundle. There are thirteen of them and they cannot be edited, which is deliberate: a shop that hand-builds its own permission sets ends up with a cashier who can close the books.
Behind the scenes each permission has a name like "take a payment" or "change a price". There are 145 of them. Nothing in the software ever asks "is this person a manager?" — it asks "does this person hold the permission to void a finished sale?". That is why a store owner and a store manager can have genuinely different tills even though one is senior to the other: they hold different permissions, not different ranks.
Permissions are granted per store. Someone can be a manager at your high-street branch and a cashier at the airport kiosk. When they switch stores in the app, their menu changes with them.
The five reasons a button is missing
When somebody tells you "the refund button isn't there", it is one of five things — and they are checked in this order. Knowing the order saves an hour of guessing.
| # | The check | In plain words | Who fixes it |
|---|---|---|---|
| 1 | Is it built? | Some parts of tech-pos are deliberately switched off until they are finished and tested. If a whole area is not built, nobody sees it — not even you. See Every feature for the honest list. | Nobody. It ships when it ships. |
| 2 | Is it in your plan? | Your subscription includes a set of areas. Something outside it shows as locked rather than hidden, so you can see what an upgrade would give you. | You, by changing plan. |
| 3 | Does this person's role allow it? | The role bundle described on this page. A cashier has no "change a price" permission, so the price field is not editable for them. | You, by changing their role. |
| 4 | Does the company allow this store to have it? | A head office (or a franchisor) can forbid a branch from turning something on, or force it always on. The branch cannot override this. | Head office / the company owner. |
| 5 | Is it switched on for this store? | Each store turns on only the parts it needs — a coffee kiosk does not need purchase orders. A part can also be set to look-but-don't-touch, where old records stay readable but nothing new can be added. | The store owner or manager, in Settings. |
The first check that fails is the one you are told about. So "not in your plan" always beats "your role does not allow it" — if someone gets a plan message, changing their role will not help until the plan does.
The side menu is built from the same five checks, so nobody sees a link that would only refuse them. A cashier's menu really is that short on purpose. Nothing is hidden to be secretive — it is hidden because pressing it would fail.
The thirteen roles
"Cannot" below means genuinely cannot — the till will refuse, not merely discourage.
| Role | Who this is in a real shop | Can | Deliberately cannot |
|---|---|---|---|
| Owner | You. The person whose name is on the company. | Everything in your business: every till action, every price, every book, staff, equity and drawings, and exporting all your data. | Nothing inside your own business. Cannot touch other people's businesses or the platform's own admin. |
| Org admin | A trusted second-in-command or operations director. | Everything the owner can, day to day. | Two things only: exporting the whole business's data, and changing who owns what share of the company. |
| Brand owner | Runs one brand inside a bigger group — e.g. the coffee side of a group that also runs a bakery. | Open and set up stores and registers, invite staff and issue badges, edit products and prices, adjust stock, ring up a sale, read store reports and the whole-business overview including financials, change settings, read the audit log. | No purchase orders, no promotions, no customer records, no accounting, no cash-up. Cannot discount, void or take a return. |
| Store owner | Owns one or more branches, perhaps as a franchisee. | Everything a brand owner can, plus: change staff roles, raise and approve purchase orders, receive deliveries, run promotions, hold customer records including personal details, read the accounts and royalties, log and approve expenses, see the subscription bill, and set up integrations. | Cannot discount, void, override a price or take a return at the till. Cannot run an X or Z read or sign off a till variance. No gift cards. No stock counts or transfers. |
| Store manager | Runs one branch. On the floor most days. | The widest set at the counter: every discount including over the cap, every void including a finished sale, price overrides, returns with no receipt and over the limit, blind returns, stock counts and adjustments, raise purchase orders and receive them, run promotions, full cash-up and variance sign-off, gift cards including voiding and adjusting balances, staff hours and timesheet approval, hardware setup, age-check overrides, settings, audit log, own-store overview. | Cannot approve a purchase order they raised. No accounting or books. No billing. No equity, drawings or cross-store financials. No stock transfers between stores. Cannot adjust loyalty points. |
| Shift supervisor | The senior person on the late shift when the manager has gone home. | Everything a cashier can, plus: void a whole finished sale, override a price, adjust stock, adjust loyalty points, issue a staff badge, run an X read, approve an age check, manage hardware, read store reports. | Cannot discount beyond the cashier cap, cannot do a no-receipt or blind return, cannot void a finished sale after the day is closed off, cannot adjust or void a gift-card balance, cannot see or change settings, cannot see the product list or the stock list. |
| Cashier | On the till. Often on their first week. | Ring up, park and recall a ticket, take payment, discount within the store's cap, void a line before the sale is finished, take a return within the store's policy, reprint and re-send a receipt, look up past sales, open and close their drawer, record a cash movement, attach a customer, issue a gift card, do an age check, handle a delivery order, use the AI helper. | Cannot change a price or override one. Cannot void a finished sale. Cannot do a no-receipt return. Cannot edit products, stock, promotions or settings. Cannot see reports or the cash-up screen. Cannot see customers' personal details. |
| Inventory clerk | The stockroom. Receives deliveries, counts shelves, prints tags. | Add and edit products, set prices, assign barcodes, print shelf labels, see and adjust stock, count stock, transfer stock between stores, raise purchase orders and receive them, add suppliers, import spreadsheets, read store reports, use and apply AI suggestions. | Cannot sell — no till at all. Cannot approve a purchase order. Cannot see past sales or customers. No cash, no settings. |
| Accountant | Your bookkeeper, in once a week or once a month. | Read and post to the books, close a period, edit the chart of accounts, set tax rules and exemptions, set fiscal details, read past sales, read customers' personal details, read and manage royalties, approve expenses, see every report and the whole-business financial overview, read settings and the audit log, see the subscription bill. | Cannot sell, refund or open a drawer. Cannot touch products, stock or purchase orders. Cannot change staff or roles. Cannot start an owner's drawing. |
| Auditor | An inspector, a franchisor's compliance check, a due-diligence reviewer. | Read past sales, customers' personal details, the accounts, royalties, every report, the whole-business financial overview, the audit log and the compliance record. | Changes nothing at all — there is not one write permission in this role. Also cannot see the product list, the stock list or settings. |
| Server | Waiting tables. | Open a table, add to it, park and recall it, discount within the cap, read the menu, look up past orders, attach a customer, declare their tips. | Cannot open or close a cash drawer. Cannot reprint or re-send a receipt. Cannot void a line. Cannot take a return. No stock, no settings, no reports. |
| Kitchen | The pass. A screen on a wall, not a person with a login they use much. | Read the menu and the store's basic details. That is all four permissions this role holds. | Everything else. See the warning below — this role currently cannot open the kitchen display screen either. |
| Viewer | A silent partner, an accountant's assistant, anyone who should look and not touch. | Read the menu, past sales, stock levels and store reports. | Everything else. No customers, no money, no settings, no selling. |
The Kitchen role holds only four read permissions, and the kitchen display screen requires one of "take a sale" or "see settings" to appear. A person given the Kitchen role therefore logs in to an empty menu and cannot open the kitchen display. Until this is corrected, put the pass screen on a device signed in as a Server or Shift supervisor, both of which can open it.
Why each role is drawn where it is
Owner and Org admin — the difference is ownership, not operations
An org admin can run the entire business: hire, fire, price, refund, close the books. Exactly two things are held back, and both are about ownership rather than running the shop — taking a full export of the business's data, and changing who holds what share of the company. That is the line: an operations director should be able to do everything except walk out with the business or quietly re-cut the cap table.
Brand owner and Store owner — they own it, they do not work the till
This is the pairing that surprises people most, so it is worth being blunt about it. A store owner can create a product, set its price, approve the purchase order that brought it in, read the accounts and see the profit — but at the till they can only ring a sale up. They cannot discount a line, void a line, override a price or take a return. Those belong to the manager and the cashier, the people who are actually standing there.
The reasoning is that till exceptions are audited events tied to a shift and a drawer. An owner reaching over the counter to zero a line leaves a record nobody on the floor can explain at cash-up. If you are an owner who also works the counter, give yourself the Store manager role at that store as well — roles are per store, and the manager role is the one built for standing at a register.
Two practical consequences follow from the same fact, and both catch people out: a store owner does not get the cash-up screen (that needs the X-read permission, which sits with the manager and the supervisor), and does not get the gift cards screen (no gift-card permissions at all).
Store manager — the one built for the shop floor
The manager role is where nearly every exception lives: discount above the cap, void a finished sale, override a price, refund without a receipt, refund above the limit, blind refund, adjust or void a gift card, override an age check, sign off a till variance. If a cashier is stuck, a manager is the person the till is asking for.
What a manager is kept out of is the money behind the money. No books, no billing, no equity, no cross-store financials. And a manager can raise a purchase order but not approve one — the person who orders the stock is not the person who authorises the spend, which is the oldest control in retail.
Two smaller gaps worth knowing: a manager cannot transfer stock to another store (that is the inventory clerk's permission), and cannot adjust a customer's loyalty points, even though the loyalty screen is visible to them.
Shift supervisor — trusted with the floor, not with the money trail
The supervisor exists so a cashier is not stranded at 9pm. They can void a sale, override a price, adjust stock, run an X read and approve an age check — the things that come up on a shift.
But the supervisor is not a half-manager. They cannot discount beyond the cashier's cap, cannot refund without a receipt, cannot touch a gift-card balance, and cannot see settings. The dividing line is roughly: a supervisor can fix the sale in front of them, but cannot do anything that would still be invisible tomorrow morning.
One oddity to be aware of: a shift supervisor can adjust stock but cannot open the stock list, and can take a sale but cannot open the product list. Their menu is short — till, orders, stock import, cash-up, gift cards, reports, hardware.
Cashier — speed, and one honest reason for every refusal
A cashier cannot change a price because a price change at the till has no paper trail leading back to a decision. A discount is different: it is capped at a percentage you set per store, it is recorded against the sale, and above the cap the till asks a manager to authorise that one action. That is the whole philosophy — a cashier gets the fast path, and anything with a lasting consequence gets a second person's name on it.
The manager does not log the cashier out to authorise something. They put in a PIN or scan a badge, that single action is approved, and the cashier carries on. The record keeps both names: who did it, and who allowed it. There is no "manager mode" that leaves a till unlocked for the next hour.
A cashier can open and close their own drawer and record a cash movement, but the cash-up screen in the back office needs the X-read permission, which a cashier does not have. Day-end totals are a supervisor's or manager's job.
Inventory clerk — can price, cannot sell
The clerk is the mirror image of the cashier, and it is worth noticing: a clerk can change prices, and a cashier cannot. That is not inconsistent. Setting a price on a product record is a considered back-office act with a history; changing a price mid-sale at the counter is not. A clerk has no till at all, cannot see past sales and cannot see customers.
A clerk can also transfer stock between stores — the only non-owner role that can — and can approve nothing. Purchase orders they raise still need a store owner to approve.
Accountant — reads the shop, writes the books
The accountant is not a read-only role, and it is worth being clear about that. They post journals, close periods, edit the chart of accounts, set tax rules and exemptions, approve expenses and manage royalties. What they cannot do is touch the shop: no selling, no refunds, no drawer, no products, no stock, no staff changes. Books yes, floor no.
Auditor — reads everything that matters, changes nothing
The auditor role contains no write permission of any kind. That is the point: you can hand it to an inspector, a franchisor or a buyer's due-diligence team without any risk of them altering a record.
"Reads everything" needs one honest qualification. An auditor sees past sales, customers' personal details, the accounts, royalties, all reports, the whole-business financial view, the audit log and the compliance record — but not the product list, not the stock list and not settings. If your auditor needs to reconcile stock, they will need a Viewer role alongside, which is the one that carries stock and product reading.
Server and Kitchen — the restaurant pair
A server opens tables, adds to them, discounts within the cap and declares their tips. They have no drawer of their own and cannot reprint a receipt — in a restaurant the payment and the receipt are usually a supervisor's or a cashier-terminal's job at the pass, not the server's tablet.
The kitchen role is a screen, not a person: read the menu, read the store. It holds nothing that could change a bill. See the warning above about the kitchen display screen.
Viewer — the deliberately boring one
Read the menu, past sales, stock levels and store reports. Nothing else, and every permission in it is written out one by one rather than being "read anything" — so when a new part of tech-pos ships, a viewer does not silently gain access to it.
What each role sees when they log in
Assuming every optional part of tech-pos is switched on for the store. If something is off for your store, it drops off this list too.
| Role | Menu they get |
|---|---|
| Owner / Org admin | Everything, including Super Admin if they hold a platform login. |
| Brand owner | Till, Orders, Products, Departments, Import, Stock, Stock import, Recipes, Delivery, Waitlist, Kitchen display, Service report, Restaurant floor, Time clock, Reports, Opportunities, Business overview, Settings, Hardware. |
| Store owner | All of the brand owner's, plus Purchasing, Customers, Subscriptions, Customer import, Loyalty, Promotions, Accounting, Billing, Integrations. Not Cash drawer, not Gift cards. |
| Store manager | Everything except Accounting, Billing and Super Admin. |
| Shift supervisor | Till, Orders, Stock import, Delivery, Waitlist, Kitchen display, Cash drawer, Gift cards, Reports, Service report, Hardware. |
| Cashier | Till, Orders, Gift cards, Delivery, Waitlist, Kitchen display. Nothing else. |
| Inventory clerk | Products, Departments, Labels, Import, Stock, Stock import, Purchasing, Supplier import, Recipes, Reports. No till. Lands on Stock at login. |
| Accountant | Orders, Accounting, Billing, Reports, Service report, Time clock, Waitlist, Restaurant floor, Opportunities, Business overview, Settings. |
| Auditor | Orders, Reports, Service report, Opportunities, Business overview. No Settings. |
| Server | Till, Orders, Delivery, Waitlist, Kitchen display. Lands on the restaurant till at a restaurant store. |
| Kitchen | Nothing — see the warning above. |
| Viewer | Orders, Stock, Reports. |
Shelf labels, Integrations and the whole Clinic area are currently switched off in the app for everybody, whatever their role. They are built and tested, just not turned on — see Every feature. Where they appear in the table above, that is what the role would get once they are switched on.
Signing in as someone else, and emergency access
An owner or org admin can step into a staff member's account to see what they are seeing — a franchisee's manager, a cashier who says a button is missing. Three rules make this safe:
- You get their permissions, never yours. An owner looking through a cashier's eyes gets the cashier's short menu.
- You cannot step up — never into another owner or admin, never into another company.
- Everything done during the session is recorded against your name, with a note of whose account it appeared under. Sessions expire after at most eight hours, and you can only be inside one at a time.
Separately, tech-pos support staff have no access to your data by default. If you need them to look at a problem, they get a time-boxed grant that is strictly read-only — past sales, stock, products, store reports, accounts and the audit log, and nothing else. There is no mechanism by which support can be granted permission to change anything. Every grant and every use of one is logged.
Permission reference
For when you need the exact name of something — reading an audit entry, or telling support precisely which permission is missing. These are grouped by area; every one of the 145 permissions appears somewhere below.
Selling
| What it lets someone do | Permission names |
|---|---|
| Ring up a sale, park it, bring it back | sale:create sale:hold sale:recall |
| Discount a line, and discount past the store's cap | sale:discount sale:discount_over_threshold |
| Void a line, void a sale, void a finished sale | sale:void_line sale:void_sale sale:manager_void |
| Type a different price at the till | sale:price_override |
| Refunds — normal, no receipt, blind, over the limit | return:create return:no_receipt return:blind return:approve_over_limit |
| Look up past sales, reprint, re-send a receipt | sale:history_read sale:reprint sale:resend |
| Age-restricted sales and overriding a refused check | age_verify age_override |
| Tips — declaring your own, managing everyone's | tip:declare tip:manage |
| Gift cards — see, issue, void, adjust a balance | gift_card:read gift_card:issue gift_card:void gift_card:adjust |
| Quotes and layaway / lay-by plans | quote:write quote:reprice layaway:write layaway:payment layaway:cancel |
| Delivery orders and delivery setup | delivery:manage delivery:config |
Catalog
| What it lets someone do | Permission names |
|---|---|
| See the product list; add and edit products | catalog:read catalog:write |
| Set a selling price; assign barcodes | catalog:price_write barcode:write |
| Organise departments | department:write |
| Print shelf labels; design the label layout | label:print label:template_write |
| Recipes and made-in-house production | recipe:read recipe:write production:write |
| Promotions, brand-wide promotions, coupons, and excluding a store from one | promo:read promo:write promo:brand_write coupon:write store:promo_exclusion |
Inventory & purchasing
| What it lets someone do | Permission names |
|---|---|
| See stock; adjust it; move it between stores; count it | inventory:read inventory:adjust inventory:transfer inventory:count |
| Batch and expiry tracking; reorder rules | inventory:lot_write reorder:write |
| Suppliers | supplier:read supplier:write |
| Raise a purchase order, approve it, book the delivery in | po:read po:write po:approve grn:write |
| Import a spreadsheet; export data out | import:run export:create |
Money
| What it lets someone do | Permission names |
|---|---|
| Open and close a drawer, move cash, sign off a variance | drawer:open drawer:close cash:movement cash:variance_signoff |
| Mid-day read, end-of-day read, bank deposits | xreport:read zreport:run deposit:manage |
| The books — read, post, close a period, chart of accounts | accounting:read accounting:post period:close coa:write |
| Tax rates, customer tax exemptions, fiscal registration details | tax:read tax:write exemption:write fiscal:write |
| Expenses — log, enter, approve | expense:read expense:write expense:approve |
| Shares, owner drawings, investment, franchise royalties | equity:read equity:write draw:write investment:write royalty:read royalty:manage |
| Your tech-pos subscription | billing:read billing:manage |
People
| What it lets someone do | Permission names |
|---|---|
| See staff, invite them, change their role, remove them | user:read user:invite user:role_change user:remove |
| Issue and cancel staff badges | badge:issue badge:revoke |
| Timesheets — read, correct a punch, approve the week | time:read time:edit time:approve |
| Customers — see, edit, see their personal details, erase them | customer:read customer:write customer:pii_read customer:erase |
| Loyalty points and customer accounts on credit | loyalty:read loyalty:adjust house_account:manage |
| Clinic — patients and appointments, and charging a visit to a sale | clinic:read clinic:write clinic:charge |
Settings & oversight
| What it lets someone do | Permission names |
|---|---|
| The company and its brands | org:read org:write brand:read brand:write |
| Decide what branches are allowed to switch on | org:module_policy |
| Stores — see, edit, open a new one | store:read store:write store:provision |
| Switch parts of tech-pos on for a store, and configure them | store:module_config store:module_settings |
| Registers — see, edit, pair a new device | register:read register:write register:pair |
| Store settings, language and region, printers and card machines | settings:read settings:write localization:write hardware:manage |
| Connections to outside systems | integration:read integration:write |
| Reports — one store, all stores, scheduled by email | report:store_read report:read report:schedule |
| The owner's overview, its money figures, and across stores | owner:overview owner:store_overview owner:financials owner:cross_store |
| Take a full export of the business | owner:data_export |
| Suggested actions — see, act on, hand to someone, dismiss | opportunity:read opportunity:act opportunity:assign opportunity:dismiss |
| The AI helper, and applying what it suggests | ai:use ai:apply_suggestion |
| The audit log, compliance records, and data requests from customers | audit:read compliance:read data_request:manage |
| Platform administration — not held by any shop role | platform:tenant_write platform:runtime_write platform:usage_read platform:impersonate |
Choosing a role — a short answer
New starter on the till
Cashier. Add Shift supervisor once they close up alone.
Person who runs the branch
Store manager. Give Store owner as well only if they should also approve spending and read the accounts.
Owner who also serves customers
Store owner and Store manager at that store — the owner role alone cannot discount or refund.
Bookkeeper
Accountant. If they should not post journals, use Auditor instead.
Stockroom
Inventory clerk. They can price and count but never sell.
Someone who should only look
Viewer. Auditor if they also need the accounts and the audit log.