Setting up
Users
Menu: Users · Who: owner (all branches), branch manager (their own branch)
Adding someone

| Field | Notes |
|---|---|
| Name | As it should appear on the receipt ("Attendant") and in reports |
| How they sign in. Unique across the whole platform — if someone works for two companies they need two addresses | |
| Password | At least 8 characters. They cannot change it themselves yet; a manager resets it here |
| Role | See below |
| Branch | Owners are company-wide and have no branch. Everyone else is fixed to one |
| Approval PIN | 4–8 digits, optional. Only needed for people who approve discounts, FOC, voids or a day reopen |
Roles, in plain words
In one shop
- Company owner — sees every branch, changes settings, reads every report, handles billing. Give this to the person who owns the business, not to a manager.
- Branch manager — runs one shop: sells, receives stock, reads that branch's reports, closes the day, dispatches riders, and approves what a cashier cannot do alone.
- Cashier — the till and nothing else.
- Kitchen — kitchen tickets.
Across the whole company (these have no branch, like an owner)
- Call centre operator — takes orders down the phone into any outlet. Takes no money.
- Call centre manager — the above, plus the board across every outlet.
- Call centre HOD — the above, plus standing discounts and editing complaints. Cannot mint another HOD.
- HR — the employee book and the Staff reports. No settings, no billing, no catalog, no stock, no day close, no till.
See Call centre, Employees and staff meals and Who can do what.
Two things that are grants, not roles
"The cashier who is allowed to haggle" and "the accountant who sees the payroll" are not job titles, so they are tick boxes on the user rather than roles. Only the owner gives them.
| Tick box | What it allows | Who has it by position |
|---|---|---|
| Can override price | Type a price at the till instead of the shelf price — Price at the counter | Owner, branch manager |
| Can view salary | Read salaries in the employee book | Owner, HR |
A salary somebody may not see is absent from the screen, never blank — so nobody reads "you may not see this" as "nobody set one".
The PIN
The PIN is how a manager approves something at the till without signing the cashier out: a discount over the cashier's limit, a free-of-charge order, a void, reopening a closed day. Which of those need a PIN is set in Settings → Approvals & Security.
The PIN is checked on the server and is never stored in the browser. A manager types it on the till, the till gets a one-time token that is spent on that one action, and it expires after 15 minutes.
Rules the system enforces
- A branch manager can only create users in their own branch, and cannot make an owner.
- Your plan limits how many users a company may have; past it, creating one is refused with the limit named.
- Deleting a user hides them; past sales still show who rang them up.
For the full picture — every screen against every role, and what a manager may not touch — see Who can do what.