Access and permissions
Which permission each Point of Sale screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (17)
Permissions by screenTill - WorkspaceTill - Open registerTill - Close sessionTill - Cash in / outTill - ReturnVoid a bill (API)Approve close (API)Manager override decision (API)Registers / Promotions / Coupons / Loyalty / Stored valueDevice monitorExceptions and audit logSellingGift cards, vouchers, store creditProvider settlement (API)Device enrolmentOffline selling
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| POS dashboard | Point of Sale > Dashboard | pos.view |
| Till - Workspace | Point of Sale > Point of sale > Launch POS / Register workspace / My session | pos.view (list), pos.sell (bootstrap), pos.session.open |
| Till - Open register | Till > Workspace > Open session | pos.session.open |
| Till - Sell | Till > Sell | pos.sell |
| Till - Payment | Till > Sell > Payment | pos.sell |
| Till - Receipt | Till > Receipt | pos.sell |
| Till - Cash in / out | Till > Sell > Cash in/out (F11) | pos.cash.move |
| Till - Return | Till > Sell > Return (F8) | pos.return (look-up route) then pos.sell (the return bill) |
| Till - Pop-ups | Till > Sell > Suspended bills (F7), Customer (F2), Coupon, Loyalty, Gift card / voucher / store credit, Price check (F5), Search (F1), Number pad | pos.sell |
| Till - Close session | Till > Close | pos.session.close |
| Register sessions | Point of Sale > Operations > Register sessions | pos.view |
| POS sales and returns lists | Point of Sale > Transactions > POS sales / Point of sale > My transactions; Operations > Returns; Transactions > POS returns / Offline audit / Offline reports | pos.view |
| Voids and cancelled bills | Point of Sale > Transactions > Voids / Cancelled bills | pos.view |
| Cash movements | Point of Sale > Operations > Cash in / cash out; Cash drops | pos.view |
| Exceptions and audit log | Point of Sale > Transactions > Exception transactions; Administration > POS audit log; Reports > Exception reports | pos.report.view |
| Promotions | Point of Sale > Pricing & promotions > Promotions | pos.view (list), pos.configure (save); screen buttons show only to company admins |
| Coupons | Point of Sale > Pricing & promotions > Coupons | pos.view / pos.configure; company admins only on screen |
| Loyalty programs | Point of Sale > Pricing & promotions > Loyalty | pos.view / pos.configure; company admins only on screen |
| Gift cards, vouchers, store credit | Point of Sale > Pricing & promotions > Gift cards / Vouchers / Store credit | pos.view / pos.configure; company admins only on screen |
| Registers | Point of Sale > POS setup > Registers / Devices | pos.view (list), pos.configure (API create/edit) |
| POS profiles | Point of Sale > POS setup > POS profiles / Offline profiles / Session profiles / Cash control profiles | pos.view |
| Payment methods | Point of Sale > POS setup > Payment methods | pos.view |
| Reason codes | Point of Sale > Administration > Reason codes | pos.view |
| Device monitor | Point of Sale > Hardware > Device monitor; Synchronisation > Sync monitor / Device status | pos.sync.manage |
| Pending transactions | Point of Sale > Synchronisation > Pending transactions / Failed sync | pos.view |
| Planned screens | Point of Sale > Operations > Cashier shifts, Suspended sales, Tender declarations, Opening/Closing control; Transactions > POS payments, Reprints; Pricing > POS price rules; POS setup > Screen layouts, Quick keys, Hardware profiles, Receipt templates, Return policies, Number series; Hardware > Printer/Scale/Payment terminal monitor; Reports (all 9 except Exception and Offline); Administration > POS permissions, Manager overrides, Alert rules | None |
| POS features and field settings | Applications > Point of Sale > Features / Fields | company administrator |
Till - Workspace
| Rule | What the system does |
|---|---|
| A pos.view-only user cannot sell | Lists and the dashboard work; bootstrap, bills, holds, sync and tenders are refused by permission (pos.sell is needed) |
Till - Open register
| Rule | What the system does |
|---|---|
| Opening a session needs pos.session.open | Refused by the server; a user with the permission opens it |
Till - Close session
| Rule | What the system does |
|---|---|
| Closing needs pos.session.close | Both refused; with the permission both work |
| Blind close hides the expected figure on the server | expected_cash, cash_sales, cash_movements are null in the answer, not merely hidden on screen; after close the figures show |
Till - Cash in / out
| Rule | What the system does |
|---|---|
| Cash movements need pos.cash.move | Refused; nothing moves |
Till - Return
| Rule | What the system does |
|---|---|
| Looking up a bill for return needs pos.return | The look-up route is refused ('No bill ...' toast) |
Void a bill (API)
| Rule | What the system does |
|---|---|
| Voiding needs pos.void (sensitive permission) | Refused; with the permission the void works and an approval row is stored |
Approve close (API)
| Rule | What the system does |
|---|---|
| Variance approval: pos.variance.approve and a different person | Refused by permission; then 'A close is approved by somebody other than the person who counted it.' |
Manager override decision (API)
| Rule | What the system does |
|---|---|
| Override decision: pos.override and not the requester | Cashier refused (needs pos.override, and 'The requester cannot approve their own override.'); manager first decision works; second -> 'This approval already has a decision.' |
Registers / Promotions / Coupons / Loyalty / Stored value
| Rule | What the system does |
|---|---|
| Configuration needs pos.configure | All refused; GET lists work with pos.view |
Device monitor
| Rule | What the system does |
|---|---|
| Device and sync administration needs pos.sync.manage | Refused. Note: /sync/pending (Pending transactions list) only needs pos.view |
Exceptions and audit log
| Rule | What the system does |
|---|---|
| Audit and exception reports need pos.report.view | Refused by the server (the menu entries are still visible) |
| Every sensitive action leaves an audit row | One audit row each (session.opened, cash.out, cash.safe_drop, sale.voided, session.close_refused, sale.recorded offline, approval.discount_override) with user, approver, reason and offline flag |
Selling
| Rule | What the system does |
|---|---|
| Viewer role cannot change anything | Every change is refused for a Viewer even with the permission (edit access is checked as well) |
| Company isolation | 'Record not found.' / not valid for every one; lists show only own company; a stored-value token of B is 'not valid' in A |
| Retries cannot double-spend or double-post | One bill / movement / hold, one journal; second spend refused; balance 20.00 |
Gift cards, vouchers, store credit
| Rule | What the system does |
|---|---|
| Tokens are hashed, shown once, masked everywhere else | Only the masked code (GC-XXXX-1A2B) is shown after the banner; the full token cannot be read again; the database holds a SHA-256 hash |
Provider settlement (API)
| Rule | What the system does |
|---|---|
| Card numbers are never accepted | 'Never send or store PAN, CVV, PIN or card track data.' |
Device enrolment
| Rule | What the system does |
|---|---|
| Signed device and quarantine protect against forged uploads | 'The offline item signature is not valid.' / 'The signed payload hash does not match the item.' / 'This device is not bound to that register.' / 'This device credential has been revoked.'; changed data quarantined |
Offline selling
| Rule | What the system does |
|---|---|
| Offline limits use the server's clock and amounts | Server still refuses by its own last-contact time, projected amount and tender rule |