Roles & permissions
The five built-in roles and how permissions are decided.
User guide
The five built-in roles and how permissions are decided.
Staff get their abilities through roles, and through nothing else — there are no per-person permission tweaks. What a staff member can do is the sum of the roles they hold; the Administrator bypasses the system entirely.
Who can do this: staff with Manage Role permissions can view the roles pages; authoring your own roles is a separate, plan-gated ability — see Custom roles.
Every business ships with five ready-made roles. They cannot be edited or deleted — "System roles are managed by the platform and cannot be edited." — so they are always there to fall back on.

| Role | Scope | What it is for |
|---|---|---|
| Admin | Global | Full access to every business feature — the closest a staff member gets to the Administrator. |
| Store Admin | Store | Runs a store end to end: orders, invoices, returns, refunds, inventory in full; sees (but does not change) the catalogue and business-level settings. |
| Cashier | Store | Runs the counter — orders, invoices, returns and refunds end to end, looking up products and customers. Cannot change the catalogue, prices or staff. |
| Inventory Manager | Global | Full control of products, categories, images and inventory across every store — business-wide, because the catalogue itself is business-wide. |
| Reports Viewer | Global | Read-only oversight: every report and every list, business-wide, with no ability to change anything. |
When a page or button is missing for someone, it is usually not a bug: the app hides actions a person cannot take, so a view-only screen looks clean rather than broken. If they open a page they truly cannot use, it says which permission is missing.