Your people
Who can do what
Sellify has nine roles. Eight of them are yours to hand out; the ninth belongs to Sellify.
| Role | Belongs to | Sees |
|---|---|---|
| Platform admin | Sellify's own staff | The commercial side of your account. No till, no catalog, and none of your reports |
| Company owner | The customer who pays | Their whole company, every branch |
| Branch manager | One shop | Only their own branch |
| Cashier | One shop | The till, and what it needs |
| Kitchen | One shop | Kitchen tickets |
| Call centre operator | The whole company | The call screen and the customer book |
| Call centre manager | The whole company | The above, plus the board across every outlet |
| Call centre HOD | The whole company | The above, plus standing discounts and complaints |
| HR | The whole company | The employee book and the Staff reports. Nothing else |
Company-wide roles have no branch: the owner, the three call-centre roles and HR. An agent orders into any outlet; HR keeps a book that is not one shop's. Everybody else is bound to exactly one branch, and that binding is enforced on the server: a manager who asks for another branch's figures is answered with their own, never with a refusal they could work around.
Two things are grants, not roles, because "the cashier who is allowed to haggle" and "the accountant who sees the payroll" are not job titles. The owner gives each on the user:
| Grant | What it allows | Who has it anyway |
|---|---|---|
| Can override price | Type a price at the till — see Price at the counter | Owner, branch manager |
| Can view salary | Read salaries in the employee book | Owner, HR |
The company-wide roles in one line each
- A call-centre agent takes orders, and takes no money. The order is confirmed; the branch takes the cash on its own till. So an agent needs no terminal to quote or to place an order — and still needs one to complete, void or correct anything.
- A call-centre HOD staffs their own floor and gives standing discounts. They cannot mint another HOD, and they touch no settings, no billing, no catalog, no stock and no day close.
- HR keeps the employee book. No settings, no billing, no catalog, no stock, no day close, no till. A role that exists to keep the book has no business in the sales summary, and asking for one is refused rather than merely hidden.
The short version
- Sellify handles the account. Your plan, your invoices, your payments, and approving a new till. They cannot ring a sale, read your reports or touch your catalog — that is not a hidden menu, the API refuses it.
- The owner runs the business. Everything inside their company, except the commercial terms they are being sold.
- The manager runs one shop. Everything operational, in their branch only, except the things that are company-wide by nature.
- The cashier sells. Nothing else.
The table
✅ can · ⛔ cannot · 🏬 own branch only
| Sellify | Owner | Manager | Cashier | |
|---|---|---|---|---|
| Selling | ||||
| Take a sale on the POS | ⛔ | ✅ | ✅ | ✅ |
| Hold, recall, void a sale | ⛔ | ✅ | ✅ | ✅ |
| Give a manual discount / FOC | ⛔ | ✅ | ✅ | with a PIN |
| Approve someone else's discount (PIN) | ⛔ | ✅ | ✅ | ⛔ |
| Setting up | ||||
| Create a branch | ⛔ | ✅ | ⛔ | ⛔ |
| Edit a branch (prefix, day start, NTN) | ⛔ | ✅ | ⛔ sees own only | ⛔ |
| Add staff | ⛔ | ✅ any role | 🏬 cashier / kitchen only | ⛔ |
| Change company settings | ⛔ | ✅ | ⛔ | ⛔ |
| Change branch settings | ⛔ | ✅ | 🏬 | ⛔ |
| Edit the company profile, logo, colours | ⛔ | ✅ | ⛔ | ⛔ |
| Set up taxes | ⛔ | ✅ | ⛔ read only | ⛔ read only |
| Set up printers | ⛔ | ✅ | 🏬 | ⛔ |
| Catalog | ||||
| Categories, products, variants, modifiers | ⛔ | ✅ | ✅ | ⛔ read only |
| Recipes | ⛔ | ✅ | ✅ | ⛔ |
| Stock | ||||
| Items, suppliers, units | ⛔ | ✅ | ✅ | ⛔ |
| Purchases, adjustments, transfers, counts | ⛔ | ✅ | 🏬 | ⛔ |
| Production — making a batch | ⛔ | ✅ | 🏬 | ⛔ |
| Selling more | ||||
| Campaigns and promo codes | ⛔ | ✅ | ✅ | ⛔ |
| Knowing where you stand | ||||
| Reports | ⛔ | ✅ all branches | 🏬 | ⛔ |
| Insights (AI) | ⛔ | ✅ | 🏬 | ⛔ |
| Close the day | ⛔ | ✅ | 🏬 | ⛔ |
| Reopen a closed day | ⛔ | ✅ with a PIN | ✅ with a PIN | ⛔ |
| Money and the account | ||||
| See the plan, usage and invoices | ✅ everyone's | ✅ own | ⛔ | ⛔ |
| Say "I have paid" with a reference | ⛔ | ✅ | ⛔ | ⛔ |
| Change the plan | ✅ | ⛔ | ⛔ | ⛔ |
| Mark an invoice paid | ✅ | ⛔ | ⛔ | ⛔ |
| Suspend / reopen a company | ✅ | ⛔ | ⛔ | ⛔ |
| Switch AI on for a company | ✅ | ⛔ | ⛔ | ⛔ |
| Create packages and prices | ✅ | ⛔ | ⛔ | ⛔ |
The kitchen role signs in for kitchen tickets only; it takes no sale and changes no data.
What stays with Sellify
These are the commercial controls, and they stay with us deliberately — an owner who could move their own company onto a bigger plan, or mark their own invoice paid, is not on a plan at all. Asking for one of these is not blocked by a hidden menu: the API refuses the request, so it makes no difference what is sent to it.
| Ask us to | |
|---|---|
| Set your company up — the company, its first branch and your owner login | Done once, on the call |
| Approve a new till | See Terminals |
| Move you to another plan | |
| Raise an invoice, and record that you have paid it | |
| Switch AI on for your company, and set its monthly budget | |
| Suspend or reopen a company | |
| Give a late account a fresh grace window |
You can see your plan, your usage and your invoices, and you can tell us you have transferred the money — see Billing. That is the whole of the boundary, and it is the same for every customer.
Two things worth knowing, because they surprise people:
- A company owner cannot change their own plan, status or trial dates. The API rejects the attempt rather than quietly ignoring it, so nobody is left wondering whether it worked.
- Shutting a lost till out is yours; letting a new one in is ours. You can disable a stolen tablet the second you notice, without ringing anybody. Approving a device is our call, and a re-enabled terminal pairs again from scratch.