Skip to main content
Resources & navigation
Business settings & access

Manage roles, permissions, and multi-store access

Last updated 2026-08-061 min read

Give each person only the modules, locations, and manager actions required for their work.

On this page

Roles determine which pages and actions a person can use; location scope determines where that access applies.

Assign least-privilege access

  1. Identify the employee's actual job and stores.
  2. Choose the smallest suitable role or permission template.
  3. Assign only the required locations and modules.
  4. Save, then test the employee's navigation and a protected deep link.

Cash drawer, refunds, voids, taxes, sensitive customer data, employee records, settings, and exports may require distinct permissions. A hidden menu item is not the only control; unauthorized API actions should also be denied.

Manager approval at POS

When a protected action requests step-up, a manager should approve that action with their own identity. Do not leave a manager session open for general staff or disclose a reusable PIN.

Multi-store troubleshooting

If data looks missing, confirm the selected store, organization context, employee location assignment, role inheritance, and any explicit override. Test after permission changes and after removing access. Escalate with the user, location, requested action, and displayed denial; never send passwords or PINs.