Guide contents
Back to help center
Help guide

Staff, PINs & permissions

Give every cashier their own PIN, set what each role can reach, and keep the shop's records honest.

Give every person their own PIN

Open Staff in the back office and add each person with their own PIN and role. Never share one PIN between two people — the entire value of the system is that every action has a name attached.

PINs are stored as one-way hashes on the shop's server. Nobody, including you, can read one back; a forgotten PIN is replaced, not recovered.

The four roles

  • Cashier — sells, opens and closes a shift, and logs nothing else.
  • Supervisor — adds refunds, order discounts, cash movements, margin figures and the shift reports.
  • Manager — adds stock adjustments, the catalog, tax rates, staff and terminal settings.
  • Admin — everything, including pairing devices.

What each role can reach

Cashier Supervisor Manager Admin
Sell, open and close a shift ✅ ✅ ✅ ✅
Line discount ✅ ✅ ✅ ✅
Order discount ⛔ ✅ ✅ ✅
Price override ⛔ ✅ ✅ ✅
See cost and margin ⛔ ✅ ✅ ✅
Refund against a receipt ⛔ ✅ ✅ ✅
Refund without a receipt ⛔ ⛔ ✅ ✅
Refund to a different method ⛔ ⛔ ✅ ✅
Cash in and cash out ⛔ ✅ ✅ ✅
Close somebody else's shift ⛔ ✅ ✅ ✅
X and Z reports ⛔ ✅ ✅ ✅
Sales figures for all staff ⛔ ⛔ ✅ ✅
Receive stock and count stock ⛔ ✅ ✅ ✅
Adjust stock ⛔ ⛔ ✅ ✅
Manage the catalog and tax rates ⛔ ⛔ ✅ ✅
Manage staff and terminal settings ⛔ ⛔ ✅ ✅
Pair a terminal ⛔ ⛔ ⛔ ✅

Discount limits are set per role, so a supervisor's ceiling can differ from a manager's without either of them being blocked entirely.

Permissions are enforced, not hidden

Every gated action is refused by the shop's server, not merely greyed out on screen. A cashier's till never even receives the cost figures behind a margin view.

That matters because the checks have to hold when the shop has no internet at all. They run on the server in the shop, which is always there.

Switch cashier

Tap the name in the header to end that person's session without closing the shift. The next cashier signs in with their own PIN, and the drawer carries on.

When somebody needs a one-off exception

An action above a cashier's role asks for a supervisor's PIN there and then. The exception is granted, the sale continues, and the override is recorded against the person who gave it — which is the point.

Rotate or remove a PIN

A manager can change any PIN from Staff. Deactivate someone who has left and their sign-in stops immediately, while everything they did stays in the records under their name.

The shop's server refuses any sale, refund, shift or cash movement attributed to nobody, or to somebody who has been deactivated.

What gets recorded

Every discount, price override, refund, void, stock correction and cash movement carries the person, the till and the moment. Sales cannot be edited or deleted after the fact, by anyone, at the database level.

The reports turn that record into something readable: every discounted line with its reason, and every refund with the name behind it.

Keep the server safe

The shop's server holds your whole shop, so treat it like the safe:

  • put it somewhere less accessible than the counter;
  • turn on Windows drive encryption — the installer checks and warns if it is off;
  • protect the server's own local admin page with the passphrase set at first boot;
  • keep backups somewhere other than that machine.

The server never accepts connections from outside your shop's own network. Nothing on the internet can reach it.

Need more help?

If this guide did not solve your issue, contact our support team.

Email support Contact the team