Page is loading
Operations

Staff & Permissions

A permission is not one switch: the role's matrix, the user's branch scope and the manager PIN asked for at the moment of the action are set independently. Thirty-two resources, seven actions — and what somebody may NOT see is a decision too.

Custom rolesPOS PINsAudit trailShift management
Custom role · Operations manager19 permissions on
RCUDEFS
Orders & payments
Orders
Payments
Refunds
Staff
Staff
Roles
Reports & analytics
Reports
Analytics
R ReadC CreateU UpdateD DeleteE ExportF PriceS Status
32 × 7
The permission matrix: 32 resources in ten groups, seven fixed actions
19
System roles and their numeric levels, owner 200 down to host 70
7
Till actions that can require manager approval, all off by default
7/24
Turkish support, around two hours to a reply
Two axes

A permission is a cell, not a switch.

The custom role editor asks two questions at once: which resource, and which action. The permission sits in the cell where they cross — 32 resources in ten groups, seven fixed actions. A column header opens that action across every resource; a row header opens that resource's whole row.

  1. Resource — the row

    Orders, payments, products, stock, staff, reports, devices. 32 resources, gathered under ten headings.

  2. Action — the column

    Read, create, update, delete, export, price update, status update. The seven columns are the same for every resource.

A dashed cell is not empty, it is closed: reports and analytics are read-only, staff and roles take no price or status action. The grid has a shape.

Custom role · Operations manager19 permissions on
RCUDEFS
Orders & payments
Orders
Payments
Refunds
Staff
Staff
Roles
Reports & analytics
Reports
Analytics
R ReadC CreateU UpdateD DeleteE ExportF PriceS Status

Three groups are drawn; the editor holds ten groups and 32 rows. The counter in the header counts ticked cells.

The matrix is the inside of one row in a list.

Custom roles live on a page of their own: each row carries the role's name, how many people hold it and the resources its permissions touch. A role with no permission cannot be saved — whoever held it could open no page at all.

Custom roles3 · 12 users
Operations manager· 3

Floor, payments and end of day. Cannot add staff.

OrdersPaymentsTables+4
IT administrator· 1

Devices, screens and printer settings. Sees no sales data.

DevicesScreensPrinters+1
Kitchen staff· 8

Kitchen display and stock counts only.

KitchenStock
A role with no permission cannot be saved: a user holding one can open no page.
Custom roles3 · 12 users
Operations manager· 3

Floor, payments and end of day. Cannot add staff.

OrdersPaymentsTables+4
IT administrator· 1

Devices, screens and printer settings. Sees no sales data.

DevicesScreensPrinters+1
Kitchen staff· 8

Kitchen display and stock counts only.

KitchenStock
A role with no permission cannot be saved: a user holding one can open no page.
Access window

Authority is granted with a day and an hour attached.

A user's access window is written day by day: a start and an end for each day, one time zone, and an end date if you want one. Outside the window the admin panel locks.

  • A separate start and end for every day of the week, in one time zone
  • An optional end date: for a seasonal team, access ends on its own
  • Outside the window the panel shows its Outside access hours screen
  • That screen asks again every 60 seconds; extend the window and the lock lifts by itself
The team list

Four layers, read in one row.

A user's authority does not come from one place. That is why the team list writes four fields side by side: what the role can do, where the scope holds, when the window is open, and the state of the PIN at the till. All four are set independently.

Manager approval
Enter the manager PIN
123456789C0
It verifies on the fourth digit. Only manager roles pass this step.

Revoking access is reversible: the person's sign-in account and their roles in other organisations are untouched.

  1. RoleSays what can be done. A system role, or a custom one you wrote; a custom permission map replaces the system role's map rather than adding to it.
  2. Branch scopeHeld by the user, not by the role: every branch, or named branches. Pick a role with enterprise access and the scope returns to every branch on its own.
  3. Access windowWhich days and hours it holds on, with an optional end date. Outside the window the admin panel locks.
  4. POS PINFour digits for signing in at the till, valid only in the branches you chose. It has three states: set, none, locked.
Features

Every control works joined to the others.

Where authority is set and where it is enforced are not the same screen — one is in the panel, the other at the till.

Set in the panel

The role's permission matrix, and the branches a PIN will hold in.

The permission matrix

A custom role is where 32 resources in ten groups cross seven actions: read, create, update, delete, export, price update, status update. Combinations that mean nothing cannot be ticked; reports and analytics stay read-only.

A POS PIN per branch

The till PIN is four digits, and it belongs to a person and a branch rather than to a person. You choose the branches it holds in when you set it. It has three states — set, none, locked — and a manager opens a locked one.

Enforced at the till

Which action asks for approval, and how that approval is given.

Manager approval policies

Order void, payment refund, discount, comp, on-the-spot price change, cash drawer and charging a house account. Seven actions, each opened as its own branch policy, and all seven off by default.

The PIN sheet at the moment of the action

The till reads the branch policy first: if the feature is off, the action is refused without asking for a PIN. If it is on, the manager approval sheet opens, verifies on the fourth digit, and only manager roles pass it.

Get started

Let us set your permission structure up with you.

We list your current team, write each role's permission matrix with you, and set the branch scopes and the till PINs. The average business goes live in 14 days.

No brand lock-in — it runs on the hardware you already haveLive in 14 days on average, from a single site to a chain24/7 Turkish-language support, included on every planGİB compliant, KVKK compliant — no add-on module needed
Support hotline
24/7
Average setup time
14 days
Uptime guarantee
99.9%