Inviting staff
On the "Staff" tab, an owner/manager holding the team.manage permission can add a new employee, give them a starting role right away (e.g. manager, server, kitchen, cashier, warehouse, front desk, technician, housekeeping, sales), then fine-tune permissions per person on the "Roles and permissions" page.
Roles and permissions
Two layers you need to tell apart:
- Role defaults (e.g. what "Manager" gets by default) is a system-wide registry, not owned by any one shop — view only, cannot be edited from a shop
- Per-person permissions are set for real on this page — tick individual permissions for one employee. Once saved, that person uses their "per-person permissions" instead of the role default from then on, and no longer reads the role's value, until you press "Reset to role default"
Setting permissions, step by step
- Pick the employee to set up from the bar at the top
- Tick/untick permissions in the table below, grouped by category: team, finance, shop, restaurant, lodging, services, retail, accounting, assets, procurement, projects, factory, automation, memberships, events, parking, bots
- Press "Save permissions"
Rules to know before setting permissions
- You can't grant someone more than you hold yourself — a permission you don't have is disabled, with the message "You don't hold this permission yourself, so you can't grant it to someone else"
- You can't edit your own row's permissions from this page — have another owner do it, to prevent locking yourself out by revoking your own access
- The shop owner holds every permission by virtue of ownership — editing the owner's row on this table has no effect
- The "Edit member permissions" permission (team.permissions) belongs to the shop owner only and can't be delegated
Org chart
The company's department layout, reporting chain, and position levels — anyone on the team can always view this chart, no special permission needed. But creating/editing departments or moving someone in the chart needs the team.manage permission, unlike "Roles and permissions" which is about who can press what — this chart only says who's in which department and reports to whom, and has nothing to do with usage permissions.
The system automatically prevents cycles (departments referencing each other in a loop) and blocks structures that are too deep — if a move fails, check whether it would create a cycle or go too deep.
Staff cards
See who has a staff card, suspend, restore, or cancel a lost card. Needs the team.manage permission.
There's no "create card" button
A card is created automatically the first time an employee opens their own card from their side — a row with no card yet in this table isn't a bug, it just means that person has never opened one. Management buttons (suspend/restore/cancel) only appear for people who already have a card.
- Suspend — temporary, can be restored later
- Cancel — permanently dead; a new card is only issued the next time that employee opens one
Scanning/entering a token to verify a card is genuine and hasn't been cancelled is done on the "Verify staff card" page — anyone on the team can use it, no special permission needed.
Clock-in time — work-time patterns and real clock-ins
Two separate but connected screens:
- Work time — sets the shop's clock-in pattern (fixed in/out times, or a flexible hour quota). Everyone can view their own pattern; editing a pattern needs team.manage
- Clock-in log — the real daily clock in/out record, the basis for estimated wage figures
A clock-in entry can't be edited directly
An employee can't edit their own clock-in record even if they own the shop — correcting a wrong clock-in can only be done through the "Edit clock-in time" page (submit a request with a reason, then a supervisor within that person's reporting chain approves it). The system always records who edited it, when, and why — there's no silent edit.
Who can approve someone's edit request is computed by the system from the reporting chain (the org chart above), not simply by who holds team.manage — a supervisor outside that person's chain, or the requester themselves, won't see an approve button.
Leave
Two parts — actual leave requests and leave policy:
- Leave — every employee can submit their own leave request from this screen without any special permission. An owner/manager holding attendance.manage approves or rejects it
- Leave policy — set the leave types the shop offers, day counts by tenure, and the approval chain. Needs the team.manage permission to edit — the legal minimum figures the system shows are for reference only, not a system-enforced rule; the shop still needs to verify these match real law itself