Permissions reference
What each built-in role can do, permission by permission.
User guide
What each built-in role can do, permission by permission.
The grid below is the five built-in roles against every module, verified against the server's own rules. Columns: SA Store Admin · Ca Cashier · IM Inventory Manager · RV Reports Viewer. The Administrator and the Admin role can do everything, so they are omitted; ✓ = allowed, — = not.
| Action | SA | Ca | IM | RV |
|---|---|---|---|---|
| View orders, invoices, tables, returns, refunds | ✓ | ✓ | — | ✓ |
| Create and edit orders; move statuses; send payment links; print labels | ✓ | ✓ | — | — |
| Configure what order labels show | ✓ | — | — | — |
| Create, edit, send invoices; record payments; use the designer | ✓ | ✓ | — | — |
| Seat and move dine-in parties | ✓ | ✓ | — | — |
| Add or remove the tables themselves | ✓ | — | — | — |
| Create and process returns and refunds | ✓ | ✓ | — | — |
The Cashier is deliberately strong here: a till that can take an order but not refund it sends the customer to find a manager.
| Action | SA | Ca | IM | RV |
|---|---|---|---|---|
| View products and categories | ✓ | ✓ | ✓ | ✓ |
| View the image library | ✓ | — | ✓ | ✓ |
| Create, edit, import, delete products; manage categories and images | — | — | ✓ | — |
| View stock | ✓ | ✓ | ✓ | ✓ |
| Adjust stock, intake, link/unlink products | ✓ | — | ✓ | — |
The catalogue is business-wide, which is why a store-scoped Store Admin only views it — editing a product from inside one store would change every store.
| Action | SA | Ca | IM | RV |
|---|---|---|---|---|
| View customers | ✓ | ✓ | — | ✓ |
| Add customers (walk-in capture, import, groups) | ✓ | ✓ | — | — |
| Edit customers; send verification codes and profile invites | ✓ | — | — | — |
| Delete customers | — | — | — | — |
| View discounts | ✓ | — | — | ✓ |
| Create, edit, delete discounts | — | — | — | — |
Applying a discount at checkout rides order permissions — a Cashier applies promotions without being able to author them.
| Action | SA | Ca | IM | RV |
|---|---|---|---|---|
| View the staff list | ✓ | — | — | ✓ |
| Edit staff access (not invite/enable — Administrator-only) | ✓ | — | — | — |
| Delete staff | — | — | — | — |
| View roles; create and edit custom roles | ✓ | — | — | view only |
| Read the staff activity log | — | — | — | ✓ |
| Analytics pages | ✓ | — | overview & inventory | ✓ |
| See and download finished exports | ✓ | — | — | ✓ |
| Build or schedule exports | — | — | — | — |
| View stores | ✓ | — | — | ✓ |
A staff member's abilities are the union of their roles (global roles plus the selected store's), a disabled role grants nothing, and someone with no roles at all is silently view-only. Nobody can grant a permission they don't hold themselves. And the server checks every call regardless of what the screen shows — a hidden button and a refused API are two layers of the same answer.