Grant module access and granular actions per employee — and per location — across 22 modules. Build permission templates for roles like cashier and manager, push template changes to everyone assigned, and let employees request permissions in-app for their manager to approve.
Employee accounts say who someone is; permissions say what they can do. PHP Point Of Sale's permissions run from whole modules down to single actions — giving a discount, seeing an item's cost price, deleting a sale — so a cashier's screen can look very different from a manager's.
You set permissions in the Employee Permissions and Access section of the employee profile in the Employees module, and you can save common setups as permission templates so you never build the same role twice.
How permissions work
- Permissions are grouped by module. Checking a module's box puts that module in the employee's left menu; unchecked modules are invisible to them. See customizing the menu and modules for how the menu is built.
- Inside each module, granular action permissions cover the sensitive parts — so you can let someone ring up sales without also letting them delete one.
- A new employee starts with no permissions checked. Checking the box at the top of a module's section selects every action in that set at once.
- You can only grant permissions you hold yourself. Boxes for permissions the logged-in editor does not have are locked, so a supervisor cannot hand out access beyond their own.
- If an employee cannot do something in the software — a button missing, a menu entry gone, a report refusing to open — check their permissions first. It is the most common cause.
Set permissions on an employee
- Go to Employees and click Edit on the employee.
- Scroll to Employee Permissions and Access.
- Either pick a template from the Permission Templates dropdown (it checks the template's boxes for you) or check modules and actions by hand.
- Click Save.
The 22 permission modules
Sales, Items, Item Kits, Customers, Suppliers, Employees, Receiving, Reports, Gift Cards, Expenses, Locations, Price Rules, Label Designs, Receipt Template, Artificial Intelligence, Messages, Deliveries, Appointments, Work Orders, Invoices, Store Config and Permission Requests.
Store Config has no sub-actions — the module checkbox alone decides who can change store settings. Every other module carries the granular actions below.
Granular actions, module by module
These are the exact permission names as they appear on the employee form.
Sales — Search Sales; Complete Sale; Suspend Sale; Edit Suspended Sale; Edit Suspended Sale Details; Delete Suspended Sale; Delete Sale; Edit Sale; Change Sale Date; Edit Sale Price; Edit sale cost price; Edit Sale Tier; Give Discount; Process Returns; Edit Taxes; Delete Taxes; Can Delete Item Added To Sale; Can Create Estimate; Can lookup receipt; Can Lookup Last Receipt; View Suspended Receipts; Receive Store Account Payment; Add Remove Amounts From Cash Drawer; Allow Item Search Suggestions For Sales; Allow Customer Search Suggestions For Sales; Show Sales 3-Dot Menu; Close Register; View/Edit Card Transactions.
Receipt Template — Add, Update; Delete; Search. Governs who can build and edit receipt layouts; the module only appears when your plan includes the Receipt Designer. See the Receipt Designer.
Artificial Intelligence — POS Genie. Controls who can open the AI assistant; see Genie.
Items — Add, Update; Delete; Search items; Edit Prices; Can change Global Pricing; Can change Location Pricing; See cost price; Edit quantity; See Item Quantity; Count inventory; See inventory count when counting inventory; Can Edit Inventory Comment; View Inventory Print List; View Inventory at ALL locations; See All Items; Manage categories; Manage tags; Manage Manufacturers; Excel Export.
Item Kits — Add, Update; Delete; Search Item Kits; Edit Prices; See cost price; See All Item Kits; Excel Export.
Customers — Add, Update; Delete; Search customers; Edit Store Account Balance; Edit customer points/Number of sales until discount; Edit Tier; Can Set Credit Limit; Excel Export; Export to Sidekick.
Suppliers — Add, Update; Delete; Search suppliers; Edit Store Account Balance; Excel Export.
Employees — Add, Update; Delete; Search employees; Assign all locations; Edit profile; Excel Export.
Receiving — Edit receiving; Delete receiving; Delete Suspended Receiving; Edit Taxes; Delete Taxes; Give Discount; Receive Store Account Payment; Send Transfer; Complete Transfer; View Suspended Receipts; Allow Item Search Suggestions For Receivings; Allow Supplier Search Suggestions For Receivings.
Reports — one view permission per report family: Sales, Closeout, Commission, Custom Report, Categories, Customers, Deleted Sales, Deliveries, Discounts, Employees, Expenses, Giftcards, Inventory Reports, Invoices, Items, Item Kits, Manufacturers, Payments, Price Rules, Profit and Loss, Receivings, Registers, Register Logs, Store Accounts, Supplier Store Accounts, Suppliers, Suspended Sales, Tags, Taxes, Tiers, Appointments, Audit Trail and Time clock. On top of those: Show profit in all reports; Show cost price in all reports; View Inventory Reports at ALL locations; View all employee commissions; View Dashboard Statistics; Can Change Report Date; Edit Register Log; Delete Register Log. See running reports.
Gift Cards — Add, Update; Delete; Search Giftcards; Edit Giftcard value; Can Sell Gift Card; Excel Export.
Expenses — Add, Update; Delete; Search; Manage categories.
Locations — Add, Update; Delete; Search locations.
Price Rules — Add, Update; Delete; Search Price Rules.
Label Designs — Add, Update; Delete; Search Label Designs.
Messages — Send Message.
Deliveries — Add Deliveries; Edit Deliveries; Delete Deliveries; Search Deliveries; Manage categories; Manage Statuses.
Appointments — Add Appointments; Edit Appointments; Delete Appointments; Search Appointments.
Work Orders — Edit Work Order; Delete Work Order; Delete Log Activity; Manage Statuses; Search Work Orders.
Invoices — Add Invoice; Edit Invoice; Delete Invoices; Search Invoices.
Permission Requests — Request; Approve.
A few pairings worth calling out:
- Edit Sale Price and Give Discount decide whether a clerk can reprice or discount; the per-employee Max discount percent and Override Price Adjustments settings on the profile decide how far. See discounts and price overrides.
- See cost price (Items) and Show cost price in all reports / Show profit in all reports (Reports) are separate switches — hide cost at the item level and in reporting independently.
- View all employee commissions (Reports) controls whose numbers appear in commission reports: without it, an employee only sees their own commissions. See sales commissions.
- Assign all locations (Employees) lets a manager give employees access to every location, including locations the manager is not assigned to themselves.
Grant by location
Both module access and individual actions can be scoped per location. Next to each module and each action checkbox there is an Override Location control — open it and check only the locations where the grant should apply. Left alone, a granted permission applies at every location the employee is assigned to.
Typical uses: a supervisor who can process returns only at the store they run, or a bookkeeper who sees reports at every location. A single-location store can ignore this layer entirely. Note that an editor can only assign location access they hold themselves, unless they have the Assign all locations permission.
Create a permission template
A permission template is a saved set of permissions you can assign to any employee — build "Cashier" once and every new hire starts from it.
- Go to Employees, click the ellipsis (...) in the top right, and choose Permission Templates.
- Click + New Permission Template.
- Give the template a recognizable name — for a role's standard set, something like Manager Permissions.
- Check the modules and actions the role needs. The box at the top of a section still selects the whole set, and Override Location works here too.
- Click Save.
Assign the template from the Permission Templates dropdown when creating or editing an employee. The template checks the boxes; you can still adjust individual permissions on that employee afterwards as an exception.
Edit a template — and push the change to everyone
- Go to Employees → ... → Permission Templates and click Edit on the template.
- Change the checked permissions.
-
Decide about Update all Employees With Template Assigned:
- Checked — everyone who has this template assigned is rewritten to match the template exactly. Any extra permissions you had granted to individuals on top of the template are removed. This is the one-step way to change a whole role.
- Unchecked — existing employees keep what they have; the new version of the template only applies to employees it is assigned to from now on.
- Click Save.
Delete or restore a template
- On the Permission Templates page, check one or more templates and click Delete above the list, then confirm. Employees who were created with that template keep every permission they already have — deleting a template never strips anyone's access. Adjust those employees by hand if their permissions should change.
- Deleted templates can come back: click the ellipsis (...), choose Manage Deleted Permission Templates, check the templates, click Undelete, then Done.
Let employees request permissions
When a clerk hits a wall mid-task — a return they cannot process, a report they cannot open — they do not have to track you down:
- Give clerks the Request action and approvers the Approve action in the Permission Requests module.
- The employee opens Permission Requests in their menu, picks the module and the specific action they need, and submits.
- The request is routed up the Manager chain set on the employee's profile: the approver is the first manager above them who holds that permission themselves.
- The approver sees pending requests in their own Permission Requests module and clicks approve. Approving grants the employee the module (if they lacked it) plus the requested action immediately.
You keep control while the queue at the register keeps moving. The Manager field lives on the employee profile — see employee accounts.
Start from roles, not people
Resist the urge to hand-pick permissions person by person. Sketch your real roles — Cashier, Floor Manager, Bookkeeper — build a template for each, and assign templates. You will make the odd exception for an individual, but starting from templates keeps most of your staff consistent, and updating a role stays a one-step job.
Common questions
An employee can't see a module in their left menu — why? The module's permission box is unchecked on their profile. Edit the employee, check the module under Employee Permissions and Access, and save. If it should be visible for their whole role, add it to the role's template instead and push the update.
Why can't I check a certain permission box when editing an employee? You can only grant permissions you hold yourself. Ask an administrator with that permission (or with full access) to grant it.
I updated a template but existing employees didn't change. What happened? Editing a template only rewrites assigned employees when Update all Employees With Template Assigned is checked at save time. Edit the template again, check that box, and save.
Updating a template removed extra permissions I had given one employee. Is that expected? Yes. Pushing a template update makes every assigned employee match the template exactly, wiping per-person additions. Re-add the individual's extras after the push, or keep such employees off the template.
If I delete a permission template, do its employees lose access? No. Employees keep all the permissions they already have; only the reusable template goes away. Restore it any time from Manage Deleted Permission Templates.
How do I stop cashiers from seeing cost and profit? Uncheck See cost price in the Items group and Show cost price in all reports plus Show profit in all reports in the Reports group. All three are separate.
Who receives an employee's permission request? The first person up their Manager chain who has the requested permission and the Approve action. If requests are going nowhere, check that the employee's Manager field is set and that the manager can approve.
Can one employee have different permissions at different stores? Yes — use the Override Location control next to the module or action and check only the locations where it should apply.
Comments
0 comments
Please sign in to leave a comment.