Access and permissions

Which permission each Point of Sale screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (17)

Permissions by screen

ScreenMenuPermission needed
POS dashboardPoint of Sale > Dashboardpos.view
Till - WorkspacePoint of Sale > Point of sale > Launch POS / Register workspace / My sessionpos.view (list), pos.sell (bootstrap), pos.session.open
Till - Open registerTill > Workspace > Open sessionpos.session.open
Till - SellTill > Sellpos.sell
Till - PaymentTill > Sell > Paymentpos.sell
Till - ReceiptTill > Receiptpos.sell
Till - Cash in / outTill > Sell > Cash in/out (F11)pos.cash.move
Till - ReturnTill > Sell > Return (F8)pos.return (look-up route) then pos.sell (the return bill)
Till - Pop-upsTill > Sell > Suspended bills (F7), Customer (F2), Coupon, Loyalty, Gift card / voucher / store credit, Price check (F5), Search (F1), Number padpos.sell
Till - Close sessionTill > Closepos.session.close
Register sessionsPoint of Sale > Operations > Register sessionspos.view
POS sales and returns listsPoint of Sale > Transactions > POS sales / Point of sale > My transactions; Operations > Returns; Transactions > POS returns / Offline audit / Offline reportspos.view
Voids and cancelled billsPoint of Sale > Transactions > Voids / Cancelled billspos.view
Cash movementsPoint of Sale > Operations > Cash in / cash out; Cash dropspos.view
Exceptions and audit logPoint of Sale > Transactions > Exception transactions; Administration > POS audit log; Reports > Exception reportspos.report.view
PromotionsPoint of Sale > Pricing & promotions > Promotionspos.view (list), pos.configure (save); screen buttons show only to company admins
CouponsPoint of Sale > Pricing & promotions > Couponspos.view / pos.configure; company admins only on screen
Loyalty programsPoint of Sale > Pricing & promotions > Loyaltypos.view / pos.configure; company admins only on screen
Gift cards, vouchers, store creditPoint of Sale > Pricing & promotions > Gift cards / Vouchers / Store creditpos.view / pos.configure; company admins only on screen
RegistersPoint of Sale > POS setup > Registers / Devicespos.view (list), pos.configure (API create/edit)
POS profilesPoint of Sale > POS setup > POS profiles / Offline profiles / Session profiles / Cash control profilespos.view
Payment methodsPoint of Sale > POS setup > Payment methodspos.view
Reason codesPoint of Sale > Administration > Reason codespos.view
Device monitorPoint of Sale > Hardware > Device monitor; Synchronisation > Sync monitor / Device statuspos.sync.manage
Pending transactionsPoint of Sale > Synchronisation > Pending transactions / Failed syncpos.view
Planned screensPoint of Sale > Operations > Cashier shifts, Suspended sales, Tender declarations, Opening/Closing control; Transactions > POS payments, Reprints; Pricing > POS price rules; POS setup > Screen layouts, Quick keys, Hardware profiles, Receipt templates, Return policies, Number series; Hardware > Printer/Scale/Payment terminal monitor; Reports (all 9 except Exception and Offline); Administration > POS permissions, Manager overrides, Alert rulesNone
POS features and field settingsApplications > Point of Sale > Features / Fieldscompany administrator

Till - Workspace

RuleWhat the system does
A pos.view-only user cannot sellLists and the dashboard work; bootstrap, bills, holds, sync and tenders are refused by permission (pos.sell is needed)

Till - Open register

RuleWhat the system does
Opening a session needs pos.session.openRefused by the server; a user with the permission opens it

Till - Close session

RuleWhat the system does
Closing needs pos.session.closeBoth refused; with the permission both work
Blind close hides the expected figure on the serverexpected_cash, cash_sales, cash_movements are null in the answer, not merely hidden on screen; after close the figures show

Till - Cash in / out

RuleWhat the system does
Cash movements need pos.cash.moveRefused; nothing moves

Till - Return

RuleWhat the system does
Looking up a bill for return needs pos.returnThe look-up route is refused ('No bill ...' toast)

Void a bill (API)

RuleWhat the system does
Voiding needs pos.void (sensitive permission)Refused; with the permission the void works and an approval row is stored

Approve close (API)

RuleWhat the system does
Variance approval: pos.variance.approve and a different personRefused by permission; then 'A close is approved by somebody other than the person who counted it.'

Manager override decision (API)

RuleWhat the system does
Override decision: pos.override and not the requesterCashier refused (needs pos.override, and 'The requester cannot approve their own override.'); manager first decision works; second -> 'This approval already has a decision.'

Registers / Promotions / Coupons / Loyalty / Stored value

RuleWhat the system does
Configuration needs pos.configureAll refused; GET lists work with pos.view

Device monitor

RuleWhat the system does
Device and sync administration needs pos.sync.manageRefused. Note: /sync/pending (Pending transactions list) only needs pos.view

Exceptions and audit log

RuleWhat the system does
Audit and exception reports need pos.report.viewRefused by the server (the menu entries are still visible)
Every sensitive action leaves an audit rowOne audit row each (session.opened, cash.out, cash.safe_drop, sale.voided, session.close_refused, sale.recorded offline, approval.discount_override) with user, approver, reason and offline flag

Selling

RuleWhat the system does
Viewer role cannot change anythingEvery change is refused for a Viewer even with the permission (edit access is checked as well)
Company isolation'Record not found.' / not valid for every one; lists show only own company; a stored-value token of B is 'not valid' in A
Retries cannot double-spend or double-postOne bill / movement / hold, one journal; second spend refused; balance 20.00

Gift cards, vouchers, store credit

RuleWhat the system does
Tokens are hashed, shown once, masked everywhere elseOnly the masked code (GC-XXXX-1A2B) is shown after the banner; the full token cannot be read again; the database holds a SHA-256 hash

Provider settlement (API)

RuleWhat the system does
Card numbers are never accepted'Never send or store PAN, CVV, PIN or card track data.'

Device enrolment

RuleWhat the system does
Signed device and quarantine protect against forged uploads'The offline item signature is not valid.' / 'The signed payload hash does not match the item.' / 'This device is not bound to that register.' / 'This device credential has been revoked.'; changed data quarantined

Offline selling

RuleWhat the system does
Offline limits use the server's clock and amountsServer still refuses by its own last-contact time, projected amount and tender rule