Skip to content

Users & roles

Access is role-based throughout: a person’s role decides which app they can open and what they see inside it, and per-person permissions narrow that further.

Role Reaches
Admin Everything
Co-Admin Everything an admin can, and the role you should actually hand out
Outlet Owner Their own outlet — orders, catalog, customers, reports
Outlet User Only the areas granted on their record
Franchise Owner Every outlet in their franchise, with franchise reporting
Franchise User The same, narrowed by their grants
Zone Manager The outlets in their zones
Dispatch Manager The dispatcher panel, and nothing else
Driver The partner app in driver mode
Driver Group Manager Their driver group

Settings, configuration, reports and the loyalty features are admin and co-admin only. Everyone else lands on the part of the product they work in.

Create the user, pick their role, then fill in what that role needs:

  • Driver profile — type, driver group, the outlets they serve, and vehicle model, number and type. See Drivers.
  • Driver details — whatever custom fields you have defined.
  • Outlet access — for an outlet user, which outlets they work at and what they may do there.

An outlet user’s record carries feature grants — Order Management and Catalog Management — and the partner app shows only what they hold. A staff member with order management but not catalog management never sees the catalog editor at all, so there is nothing to tap by mistake.

Beyond that, money operations are permissioned separately, in the order edit and cancellation settings rather than here:

Permission Governs
Can edit Changing products on a placed order
Can add fees Adding a charge to one
Can collect payment Recording money on an edited-up order
Can process refund Issuing a refund
Can cancel Cancelling an order
Can waive cancellation fee Skipping the fee

Each is set per role. A common shape: everyone can edit, only managers refund and waive. See Editing & refunds and Cancellations.

The POS register does not use these accounts. It has its own staff roster — cashier or manager, each with a PIN — because a register signs in as a person per shift, not as a user with a password. Manager-gated actions on the register check that roster, not this one.

Managed under Dashboard → Operations → Devices → POS Staff (/configuration/devices/staff); see Devices & staff PINs.

New outlets and new drivers can apply through public forms rather than being created by hand, landing in queues at Dashboard → Operations → Approvals. Review, then approve or decline.

Worth using even at small scale: it collects the same information every time and leaves a record of who applied and when.

  • Deactivate people who leave, the same day. It takes seconds, and it is the difference between a tidy report and an unexplained one.
  • One login per person. Shared accounts make every report unanswerable — till sessions, refunds and approvals are all attributed to whoever’s credentials were used.
  • Review admin accounts quarterly. The list only ever grows on its own.
Symptom Cause
Someone cannot see a dashboard section Settings, configuration, reports and features are admin and co-admin only
Two staff see different things in the partner app Different roles, or different feature grants on their records
A staff member cannot refund Refunds are permissioned in the order edit settings, not on the user
A driver receives no orders They must be online, in a group, and assigned to the outlet
A register PIN does not work Register staff are a separate roster under Devices
A new outlet is not appearing It may be waiting in the approvals queue

Related: Devices & staff PINs · Editing & refunds · Drivers · Modules & system

Was this page helpful?