Roles & permissions

Every person you add to tech-pos gets one role per store. The role decides what they see when they log in and what the till lets them do. This page lists the thirteen roles, explains the reasoning behind each one, and shows the five separate reasons a button can be missing.

What a role actually is

A role is a fixed bundle of permissions. You do not tick boxes one by one — you pick a role, and the role carries its bundle. There are thirteen of them and they cannot be edited, which is deliberate: a shop that hand-builds its own permission sets ends up with a cashier who can close the books.

Behind the scenes each permission has a name like "take a payment" or "change a price". There are 145 of them. Nothing in the software ever asks "is this person a manager?" — it asks "does this person hold the permission to void a finished sale?". That is why a store owner and a store manager can have genuinely different tills even though one is senior to the other: they hold different permissions, not different ranks.

Permissions are granted per store. Someone can be a manager at your high-street branch and a cashier at the airport kiosk. When they switch stores in the app, their menu changes with them.

Screenshot to come: the staff list in Settings, showing a person's name with a role dropdown next to it and the store they hold it at
Roles are assigned per person per store, from the staff list in Settings.

The five reasons a button is missing

When somebody tells you "the refund button isn't there", it is one of five things — and they are checked in this order. Knowing the order saves an hour of guessing.

# The check In plain words Who fixes it
1 Is it built? Some parts of tech-pos are deliberately switched off until they are finished and tested. If a whole area is not built, nobody sees it — not even you. See Every feature for the honest list. Nobody. It ships when it ships.
2 Is it in your plan? Your subscription includes a set of areas. Something outside it shows as locked rather than hidden, so you can see what an upgrade would give you. You, by changing plan.
3 Does this person's role allow it? The role bundle described on this page. A cashier has no "change a price" permission, so the price field is not editable for them. You, by changing their role.
4 Does the company allow this store to have it? A head office (or a franchisor) can forbid a branch from turning something on, or force it always on. The branch cannot override this. Head office / the company owner.
5 Is it switched on for this store? Each store turns on only the parts it needs — a coffee kiosk does not need purchase orders. A part can also be set to look-but-don't-touch, where old records stay readable but nothing new can be added. The store owner or manager, in Settings.
Reading the order

The first check that fails is the one you are told about. So "not in your plan" always beats "your role does not allow it" — if someone gets a plan message, changing their role will not help until the plan does.

Why the menu is short for some people

The side menu is built from the same five checks, so nobody sees a link that would only refuse them. A cashier's menu really is that short on purpose. Nothing is hidden to be secretive — it is hidden because pressing it would fail.

The thirteen roles

"Cannot" below means genuinely cannot — the till will refuse, not merely discourage.

Role Who this is in a real shop Can Deliberately cannot
Owner You. The person whose name is on the company. Everything in your business: every till action, every price, every book, staff, equity and drawings, and exporting all your data. Nothing inside your own business. Cannot touch other people's businesses or the platform's own admin.
Org admin A trusted second-in-command or operations director. Everything the owner can, day to day. Two things only: exporting the whole business's data, and changing who owns what share of the company.
Brand owner Runs one brand inside a bigger group — e.g. the coffee side of a group that also runs a bakery. Open and set up stores and registers, invite staff and issue badges, edit products and prices, adjust stock, ring up a sale, read store reports and the whole-business overview including financials, change settings, read the audit log. No purchase orders, no promotions, no customer records, no accounting, no cash-up. Cannot discount, void or take a return.
Store owner Owns one or more branches, perhaps as a franchisee. Everything a brand owner can, plus: change staff roles, raise and approve purchase orders, receive deliveries, run promotions, hold customer records including personal details, read the accounts and royalties, log and approve expenses, see the subscription bill, and set up integrations. Cannot discount, void, override a price or take a return at the till. Cannot run an X or Z read or sign off a till variance. No gift cards. No stock counts or transfers.
Store manager Runs one branch. On the floor most days. The widest set at the counter: every discount including over the cap, every void including a finished sale, price overrides, returns with no receipt and over the limit, blind returns, stock counts and adjustments, raise purchase orders and receive them, run promotions, full cash-up and variance sign-off, gift cards including voiding and adjusting balances, staff hours and timesheet approval, hardware setup, age-check overrides, settings, audit log, own-store overview. Cannot approve a purchase order they raised. No accounting or books. No billing. No equity, drawings or cross-store financials. No stock transfers between stores. Cannot adjust loyalty points.
Shift supervisor The senior person on the late shift when the manager has gone home. Everything a cashier can, plus: void a whole finished sale, override a price, adjust stock, adjust loyalty points, issue a staff badge, run an X read, approve an age check, manage hardware, read store reports. Cannot discount beyond the cashier cap, cannot do a no-receipt or blind return, cannot void a finished sale after the day is closed off, cannot adjust or void a gift-card balance, cannot see or change settings, cannot see the product list or the stock list.
Cashier On the till. Often on their first week. Ring up, park and recall a ticket, take payment, discount within the store's cap, void a line before the sale is finished, take a return within the store's policy, reprint and re-send a receipt, look up past sales, open and close their drawer, record a cash movement, attach a customer, issue a gift card, do an age check, handle a delivery order, use the AI helper. Cannot change a price or override one. Cannot void a finished sale. Cannot do a no-receipt return. Cannot edit products, stock, promotions or settings. Cannot see reports or the cash-up screen. Cannot see customers' personal details.
Inventory clerk The stockroom. Receives deliveries, counts shelves, prints tags. Add and edit products, set prices, assign barcodes, print shelf labels, see and adjust stock, count stock, transfer stock between stores, raise purchase orders and receive them, add suppliers, import spreadsheets, read store reports, use and apply AI suggestions. Cannot sell — no till at all. Cannot approve a purchase order. Cannot see past sales or customers. No cash, no settings.
Accountant Your bookkeeper, in once a week or once a month. Read and post to the books, close a period, edit the chart of accounts, set tax rules and exemptions, set fiscal details, read past sales, read customers' personal details, read and manage royalties, approve expenses, see every report and the whole-business financial overview, read settings and the audit log, see the subscription bill. Cannot sell, refund or open a drawer. Cannot touch products, stock or purchase orders. Cannot change staff or roles. Cannot start an owner's drawing.
Auditor An inspector, a franchisor's compliance check, a due-diligence reviewer. Read past sales, customers' personal details, the accounts, royalties, every report, the whole-business financial overview, the audit log and the compliance record. Changes nothing at all — there is not one write permission in this role. Also cannot see the product list, the stock list or settings.
Server Waiting tables. Open a table, add to it, park and recall it, discount within the cap, read the menu, look up past orders, attach a customer, declare their tips. Cannot open or close a cash drawer. Cannot reprint or re-send a receipt. Cannot void a line. Cannot take a return. No stock, no settings, no reports.
Kitchen The pass. A screen on a wall, not a person with a login they use much. Read the menu and the store's basic details. That is all four permissions this role holds. Everything else. See the warning below — this role currently cannot open the kitchen display screen either.
Viewer A silent partner, an accountant's assistant, anyone who should look and not touch. Read the menu, past sales, stock levels and store reports. Everything else. No customers, no money, no settings, no selling.
Known gap — the Kitchen role

The Kitchen role holds only four read permissions, and the kitchen display screen requires one of "take a sale" or "see settings" to appear. A person given the Kitchen role therefore logs in to an empty menu and cannot open the kitchen display. Until this is corrected, put the pass screen on a device signed in as a Server or Shift supervisor, both of which can open it.

Why each role is drawn where it is

Owner and Org admin — the difference is ownership, not operations

An org admin can run the entire business: hire, fire, price, refund, close the books. Exactly two things are held back, and both are about ownership rather than running the shop — taking a full export of the business's data, and changing who holds what share of the company. That is the line: an operations director should be able to do everything except walk out with the business or quietly re-cut the cap table.

Brand owner and Store owner — they own it, they do not work the till

This is the pairing that surprises people most, so it is worth being blunt about it. A store owner can create a product, set its price, approve the purchase order that brought it in, read the accounts and see the profit — but at the till they can only ring a sale up. They cannot discount a line, void a line, override a price or take a return. Those belong to the manager and the cashier, the people who are actually standing there.

The reasoning is that till exceptions are audited events tied to a shift and a drawer. An owner reaching over the counter to zero a line leaves a record nobody on the floor can explain at cash-up. If you are an owner who also works the counter, give yourself the Store manager role at that store as well — roles are per store, and the manager role is the one built for standing at a register.

Two practical consequences follow from the same fact, and both catch people out: a store owner does not get the cash-up screen (that needs the X-read permission, which sits with the manager and the supervisor), and does not get the gift cards screen (no gift-card permissions at all).

Store manager — the one built for the shop floor

The manager role is where nearly every exception lives: discount above the cap, void a finished sale, override a price, refund without a receipt, refund above the limit, blind refund, adjust or void a gift card, override an age check, sign off a till variance. If a cashier is stuck, a manager is the person the till is asking for.

What a manager is kept out of is the money behind the money. No books, no billing, no equity, no cross-store financials. And a manager can raise a purchase order but not approve one — the person who orders the stock is not the person who authorises the spend, which is the oldest control in retail.

Two smaller gaps worth knowing: a manager cannot transfer stock to another store (that is the inventory clerk's permission), and cannot adjust a customer's loyalty points, even though the loyalty screen is visible to them.

Shift supervisor — trusted with the floor, not with the money trail

The supervisor exists so a cashier is not stranded at 9pm. They can void a sale, override a price, adjust stock, run an X read and approve an age check — the things that come up on a shift.

But the supervisor is not a half-manager. They cannot discount beyond the cashier's cap, cannot refund without a receipt, cannot touch a gift-card balance, and cannot see settings. The dividing line is roughly: a supervisor can fix the sale in front of them, but cannot do anything that would still be invisible tomorrow morning.

One oddity to be aware of: a shift supervisor can adjust stock but cannot open the stock list, and can take a sale but cannot open the product list. Their menu is short — till, orders, stock import, cash-up, gift cards, reports, hardware.

Cashier — speed, and one honest reason for every refusal

A cashier cannot change a price because a price change at the till has no paper trail leading back to a decision. A discount is different: it is capped at a percentage you set per store, it is recorded against the sale, and above the cap the till asks a manager to authorise that one action. That is the whole philosophy — a cashier gets the fast path, and anything with a lasting consequence gets a second person's name on it.

The manager does not log the cashier out to authorise something. They put in a PIN or scan a badge, that single action is approved, and the cashier carries on. The record keeps both names: who did it, and who allowed it. There is no "manager mode" that leaves a till unlocked for the next hour.

A cashier can open and close their own drawer and record a cash movement, but the cash-up screen in the back office needs the X-read permission, which a cashier does not have. Day-end totals are a supervisor's or manager's job.

Inventory clerk — can price, cannot sell

The clerk is the mirror image of the cashier, and it is worth noticing: a clerk can change prices, and a cashier cannot. That is not inconsistent. Setting a price on a product record is a considered back-office act with a history; changing a price mid-sale at the counter is not. A clerk has no till at all, cannot see past sales and cannot see customers.

A clerk can also transfer stock between stores — the only non-owner role that can — and can approve nothing. Purchase orders they raise still need a store owner to approve.

Accountant — reads the shop, writes the books

The accountant is not a read-only role, and it is worth being clear about that. They post journals, close periods, edit the chart of accounts, set tax rules and exemptions, approve expenses and manage royalties. What they cannot do is touch the shop: no selling, no refunds, no drawer, no products, no stock, no staff changes. Books yes, floor no.

Auditor — reads everything that matters, changes nothing

The auditor role contains no write permission of any kind. That is the point: you can hand it to an inspector, a franchisor or a buyer's due-diligence team without any risk of them altering a record.

"Reads everything" needs one honest qualification. An auditor sees past sales, customers' personal details, the accounts, royalties, all reports, the whole-business financial view, the audit log and the compliance record — but not the product list, not the stock list and not settings. If your auditor needs to reconcile stock, they will need a Viewer role alongside, which is the one that carries stock and product reading.

Server and Kitchen — the restaurant pair

A server opens tables, adds to them, discounts within the cap and declares their tips. They have no drawer of their own and cannot reprint a receipt — in a restaurant the payment and the receipt are usually a supervisor's or a cashier-terminal's job at the pass, not the server's tablet.

The kitchen role is a screen, not a person: read the menu, read the store. It holds nothing that could change a bill. See the warning above about the kitchen display screen.

Viewer — the deliberately boring one

Read the menu, past sales, stock levels and store reports. Nothing else, and every permission in it is written out one by one rather than being "read anything" — so when a new part of tech-pos ships, a viewer does not silently gain access to it.

What each role sees when they log in

Assuming every optional part of tech-pos is switched on for the store. If something is off for your store, it drops off this list too.

Role Menu they get
Owner / Org adminEverything, including Super Admin if they hold a platform login.
Brand ownerTill, Orders, Products, Departments, Import, Stock, Stock import, Recipes, Delivery, Waitlist, Kitchen display, Service report, Restaurant floor, Time clock, Reports, Opportunities, Business overview, Settings, Hardware.
Store ownerAll of the brand owner's, plus Purchasing, Customers, Subscriptions, Customer import, Loyalty, Promotions, Accounting, Billing, Integrations. Not Cash drawer, not Gift cards.
Store managerEverything except Accounting, Billing and Super Admin.
Shift supervisorTill, Orders, Stock import, Delivery, Waitlist, Kitchen display, Cash drawer, Gift cards, Reports, Service report, Hardware.
CashierTill, Orders, Gift cards, Delivery, Waitlist, Kitchen display. Nothing else.
Inventory clerkProducts, Departments, Labels, Import, Stock, Stock import, Purchasing, Supplier import, Recipes, Reports. No till. Lands on Stock at login.
AccountantOrders, Accounting, Billing, Reports, Service report, Time clock, Waitlist, Restaurant floor, Opportunities, Business overview, Settings.
AuditorOrders, Reports, Service report, Opportunities, Business overview. No Settings.
ServerTill, Orders, Delivery, Waitlist, Kitchen display. Lands on the restaurant till at a restaurant store.
KitchenNothing — see the warning above.
ViewerOrders, Stock, Reports.
Three exceptions

Shelf labels, Integrations and the whole Clinic area are currently switched off in the app for everybody, whatever their role. They are built and tested, just not turned on — see Every feature. Where they appear in the table above, that is what the role would get once they are switched on.

Screenshot to come: the same app side by side — a cashier's six-item menu next to a store manager's full menu
The menu is built from the role, so nobody sees a link that would only refuse them.

Signing in as someone else, and emergency access

An owner or org admin can step into a staff member's account to see what they are seeing — a franchisee's manager, a cashier who says a button is missing. Three rules make this safe:

Separately, tech-pos support staff have no access to your data by default. If you need them to look at a problem, they get a time-boxed grant that is strictly read-only — past sales, stock, products, store reports, accounts and the audit log, and nothing else. There is no mechanism by which support can be granted permission to change anything. Every grant and every use of one is logged.

Permission reference

For when you need the exact name of something — reading an audit entry, or telling support precisely which permission is missing. These are grouped by area; every one of the 145 permissions appears somewhere below.

Selling

What it lets someone doPermission names
Ring up a sale, park it, bring it backsale:create sale:hold sale:recall
Discount a line, and discount past the store's capsale:discount sale:discount_over_threshold
Void a line, void a sale, void a finished salesale:void_line sale:void_sale sale:manager_void
Type a different price at the tillsale:price_override
Refunds — normal, no receipt, blind, over the limitreturn:create return:no_receipt return:blind return:approve_over_limit
Look up past sales, reprint, re-send a receiptsale:history_read sale:reprint sale:resend
Age-restricted sales and overriding a refused checkage_verify age_override
Tips — declaring your own, managing everyone'stip:declare tip:manage
Gift cards — see, issue, void, adjust a balancegift_card:read gift_card:issue gift_card:void gift_card:adjust
Quotes and layaway / lay-by plansquote:write quote:reprice layaway:write layaway:payment layaway:cancel
Delivery orders and delivery setupdelivery:manage delivery:config

Catalog

What it lets someone doPermission names
See the product list; add and edit productscatalog:read catalog:write
Set a selling price; assign barcodescatalog:price_write barcode:write
Organise departmentsdepartment:write
Print shelf labels; design the label layoutlabel:print label:template_write
Recipes and made-in-house productionrecipe:read recipe:write production:write
Promotions, brand-wide promotions, coupons, and excluding a store from onepromo:read promo:write promo:brand_write coupon:write store:promo_exclusion

Inventory & purchasing

What it lets someone doPermission names
See stock; adjust it; move it between stores; count itinventory:read inventory:adjust inventory:transfer inventory:count
Batch and expiry tracking; reorder rulesinventory:lot_write reorder:write
Supplierssupplier:read supplier:write
Raise a purchase order, approve it, book the delivery inpo:read po:write po:approve grn:write
Import a spreadsheet; export data outimport:run export:create

Money

What it lets someone doPermission names
Open and close a drawer, move cash, sign off a variancedrawer:open drawer:close cash:movement cash:variance_signoff
Mid-day read, end-of-day read, bank depositsxreport:read zreport:run deposit:manage
The books — read, post, close a period, chart of accountsaccounting:read accounting:post period:close coa:write
Tax rates, customer tax exemptions, fiscal registration detailstax:read tax:write exemption:write fiscal:write
Expenses — log, enter, approveexpense:read expense:write expense:approve
Shares, owner drawings, investment, franchise royaltiesequity:read equity:write draw:write investment:write royalty:read royalty:manage
Your tech-pos subscriptionbilling:read billing:manage

People

What it lets someone doPermission names
See staff, invite them, change their role, remove themuser:read user:invite user:role_change user:remove
Issue and cancel staff badgesbadge:issue badge:revoke
Timesheets — read, correct a punch, approve the weektime:read time:edit time:approve
Customers — see, edit, see their personal details, erase themcustomer:read customer:write customer:pii_read customer:erase
Loyalty points and customer accounts on creditloyalty:read loyalty:adjust house_account:manage
Clinic — patients and appointments, and charging a visit to a saleclinic:read clinic:write clinic:charge

Settings & oversight

What it lets someone doPermission names
The company and its brandsorg:read org:write brand:read brand:write
Decide what branches are allowed to switch onorg:module_policy
Stores — see, edit, open a new onestore:read store:write store:provision
Switch parts of tech-pos on for a store, and configure themstore:module_config store:module_settings
Registers — see, edit, pair a new deviceregister:read register:write register:pair
Store settings, language and region, printers and card machinessettings:read settings:write localization:write hardware:manage
Connections to outside systemsintegration:read integration:write
Reports — one store, all stores, scheduled by emailreport:store_read report:read report:schedule
The owner's overview, its money figures, and across storesowner:overview owner:store_overview owner:financials owner:cross_store
Take a full export of the businessowner:data_export
Suggested actions — see, act on, hand to someone, dismissopportunity:read opportunity:act opportunity:assign opportunity:dismiss
The AI helper, and applying what it suggestsai:use ai:apply_suggestion
The audit log, compliance records, and data requests from customersaudit:read compliance:read data_request:manage
Platform administration — not held by any shop roleplatform:tenant_write platform:runtime_write platform:usage_read platform:impersonate

Choosing a role — a short answer

New starter on the till

Cashier. Add Shift supervisor once they close up alone.

Person who runs the branch

Store manager. Give Store owner as well only if they should also approve spending and read the accounts.

Owner who also serves customers

Store owner and Store manager at that store — the owner role alone cannot discount or refund.

Bookkeeper

Accountant. If they should not post journals, use Auditor instead.

Stockroom

Inventory clerk. They can price and count but never sell.

Someone who should only look

Viewer. Auditor if they also need the accounts and the audit log.