Users & Roles
Control who can access the Backoffice, what each person can see and do, and which stores they are scoped to.
Roles
The Backoffice uses role-based access control. Assign one role per user:
Role | What they can do |
|---|---|
OrgAdmin | Full access to everything — settings, catalog, inventory, reports, users, audit log, and all stores |
StoreManager | Manage operations for their assigned stores: catalog, stock, sales, shifts, and device management |
CashierSupervisor | Read-only access to operations (sales, shifts, invoices) for their assigned stores — no editing |
Reporter | Read-only access to reports and analytics across assigned stores — no operational data |
Auditor | Org-wide read-only access including the audit log — no operational editing |
Note: Where Hotel, Restaurant, or Warehouse modules are licensed, additional roles specific to those modules are available. Contact your administrator to learn which module roles are enabled in your organization.
Creating Users
Invite a new user under Users → New User:
Enter the user's Email address.
Set a temporary Password — the user should change it on first sign-in.
Select a Role from the list above.
For scoped roles (StoreManager, CashierSupervisor, Reporter), select the Stores this user can access.
Click Create — the user can now sign in.

Store Scoping
Roles marked as scoped only see data for the stores they have been assigned to:
Reports show only those stores' sales.
Inventory and device management are filtered to those stores.
The OrgAdmin and Auditor roles are always org-wide and cannot be scoped.
Tip: Assign a StoreManager to exactly the stores they are responsible for. They will not be able to see or affect other stores.
Managing Users
Find any existing user under Users and open their profile to:
Edit role or store assignment — changes take effect immediately, but the user must sign out and back in to see updated permissions.
Disable — revokes access without deleting the account. The user cannot sign in until re-enabled.
Enable — restores access to a previously disabled account.
Reset password — sends a password-reset link to the user's email.
Note: After a role change, the affected user must sign out and sign back in. Their current session retains the old role until re-authentication.