Custom Roles

Build your own permission sets. Add to a built-in role, or replace it outright, so a staff member can do exactly what you trust them with.

10 min read · Updated 26 Sep 2026

On this page

The four built-in roles cover most stores, but they are fixed. A custom role changes what one group of staff can do. Examples: a cashier who can also receive deliveries, a stockman who can see the warehouse but never the sales figures, or a supervisor who runs the till but never sees the reports.

You'll find this at Settings → Custom Roles. Creating, editing and deleting roles needs the Manage Custom Roles permission. The Owner always has it.

Two kinds of custom role

Every custom role works in one of two ways. The Replaces the base role's permissions switch on the role form decides which.

Switch What staff with the role get
Off (the default) Everything their built-in role already allows, plus the permissions ticked on the custom role
On Only the permissions ticked on the custom role, plus clocking in and out and reading their own payslips

Every role created before this switch existed works the first way. Nothing about them changed.

The role list marks roles with the switch on as Replaces base role.

Adding to a built-in role

With the switch off, the custom role is layered on top of the built-in role. Every permission the built-in role carries stays, and the ticked ones are added. Use this to lift a Cashier or Staff account up, such as a cashier who can also adjust stock.

A role in this mode can never take anything away. Giving it to a Manager usually changes little, because Managers already hold most permissions.

Replacing a built-in role

With the switch on, the built-in role's permissions no longer apply. The staff member can do what is ticked on the custom role and nothing else. Use this to take something away, such as a Manager who runs the floor but must not see the reports, or a cashier who needs a manager's PIN for every manual discount.

Two things are always kept, whatever you tick: Clock In / Out (Self) and View Own Payslips. Every employee is entitled to their own time records and payslips.

Tick everything the job needs. A role in this mode starts from nothing. If these staff run a till, tick Open the POS. If they open the dashboard, tick View Dashboard. Anything left unticked disappears from their menus and screens.

The Owner is never restricted by a custom role.

Creating a role

Settings → Custom Roles → New Role opens a form with these fields:

Field Required Limit
Name Yes 255 characters, and must be unique within your store
Description No 255 characters
Replaces the base role's permissions No Off unless you switch it on
Capabilities Yes At least one must be ticked

The name is what you'll see in the staff form later, so make it describe the job: "Senior Cashier", "Stockman", "Warehouse Clerk". The description is only ever shown on this page.

The capability list is a long set of tickboxes grouped by area. Each one shows a plain-language label and, underneath it, the technical key it maps to. Tick what you need and press Create.

You can also start from a template, or use the copy button on an existing role to clone it. A clone keeps the original's switch setting.

What you can grant

Each permission covers one action. Holding it means the staff member can do that action directly. At the POS, some actions can still be done without the permission if a manager enters their PIN. The manager must hold the permission themselves.

In the web back office there is no manager-PIN prompt. A button for an action the signed-in person lacks the permission for is simply not shown.

These are the permissions people most often grant:

Group Capability What it allows
POS & Cash Open the POS Run a till
POS & Cash End Shift Without Manager PIN Close a shift without a manager standing by
POS & Cash Void Sales Without Manager PIN Void a sale on their own
POS & Cash See All Staff's Transactions See everyone's sales, not just their own
POS & Cash Process Returns Process a return straight away and approve other people's returns. Without it, a return is sent for approval
POS & Cash Set Up Tables & Floor Plan Add, edit and remove tables. Seating and clearing tables stays open to everyone at the POS
Catalog & Inventory View Products See the product catalog
Catalog & Inventory Create / Edit Products Add, edit, import and delete products, services and modifiers
Catalog & Inventory Manage Categories Add, edit and delete categories
Catalog & Inventory Stock In / Adjust Inventory Stock in, adjust stock and use bulk stock-in
Catalog & Inventory Receive Stock (POs & Transfers) See purchase orders and stock transfers, and receive them
Catalog & Inventory Create / Submit / Cancel Purchase Orders & Suppliers Raise and manage purchase orders and suppliers
Catalog & Inventory View Compositions/Ingredients Read recipes and see ingredient consumption, without editing them
Catalog & Inventory Create / Edit Recipes (Compositions) Create and edit recipes
Warehouse View Warehouses See warehouses, their zones and bins, stock levels, and receiving history
Warehouse Manage Warehouses Create and edit warehouses, zones and bins; create, approve and cancel stock transfers
Warehouse Request Stock Transfers Raise a stock transfer request
Production Run Production (Commissary) Approve, reject and complete production runs
Production Generate Delivery Receipts Print delivery receipts for purchase orders, production orders and transfers
Customers Manage Customers Add, edit and delete customers
Reports & Compliance View Reports / View Financial Reports Open the reports, and the profit and margin reports
Reports & Compliance Schedule Report Emails & Saved Views Set up scheduled report emails
Finance & Accounting Approve / Reject Expenses Approve or reject pending expenses
Finance & Accounting Edit Approved / Rejected Expenses Change or delete an expense after it has been approved or rejected
Workforce Act on Approvals Approve or reject items in the approvals queue (see below)
Workforce View Everyone's Attendance & Timesheets Open the Timesheet for all staff
Workforce Add / Edit / Deactivate Staff Manage staff accounts
Loans Approve Loans / Write Off Loans Approve loan requests; write off a loan
Payroll Approve Payroll Runs / Mark Payroll Paid Sign off a computed payroll run; mark a posted run paid
Settings & Admin Edit Store, Receipt & Inventory Settings Save Store Settings and Receipt Settings. Everyone can still read them
Settings & Admin Edit Security Settings Change the manager-approval and two-person rules
Settings & Admin Manage Branches, Manage Subscription & Billing, Manage Custom Roles What they say

If you created roles before September 2026, check them. Some tickboxes used to do nothing: products, categories, customers, stock in and adjust, shift management, returns and BIR readings. They now do what their labels say. A cashier whose role has Create / Edit Products ticked can now edit products.

Manager PIN Override (older app versions) only matters for phones and tablets that haven't updated the Kassly app. Newer versions check the specific permission for each action instead.

Approvals need two permissions

Act on Approvals lets someone work the approvals queue. For each request, they also need the permission for that kind of request:

Request Also needs
Void Void Sales Without Manager PIN
Refund or return Process Returns
Expense Approve / Reject Expenses
Purchase order Create / Submit / Cancel Purchase Orders & Suppliers
Stock transfer Manage Warehouses
Stock count or receiving variance Stock In / Adjust Inventory
Production run Run Production (Commissary)
Loan Approve Loans
Payroll run Approve Payroll Runs
Leave Approve Leave
Discount override, stock adjustment Nothing extra

Requests they can't act on still show in the queue, but without the Approve and Reject buttons.

Two permissions change money flow rather than just visibility:

  • Manage Warehouses and Run Production (Commissary) both auto-approve the requests their holder creates. A stock transfer raised by someone with Manage Warehouses skips the approval step entirely; the same is true of a production run raised by someone with Run Production. Grant these two only to people you would have approved the request for anyway.

Add-ons still apply

A capability is permission, not entitlement. The warehouse, production, loans and payroll capabilities all sit behind paid add-ons, and granting the capability to a staff member does not turn the add-on on:

Capabilities Needs
Warehouse, Production, Generate Delivery Receipts Warehouse & Commissary (₱500 per branch each month)
Receive Stock, purchase orders Inventory Pro (₱400 per branch each month)
Stock transfers Stock Transfers Between Branches (₱300 per branch each month)
View Compositions/Ingredients Recipe Costing (₱350 per branch each month)
Loans Loans (₱300 per branch each month)
Payroll, View Own Payslips Payroll (₱300 per branch each month)
Configure Job Order Board Job Orders & Service Tickets (₱400 per branch each month)

Any bundle that includes the add-on works too. See Plans and add-ons.

Assigning a role to a staff member

Custom roles do nothing until someone holds one. Open the staff member on the staff page and use the Custom Role (optional) dropdown. It is offered for Manager, Cashier and Staff accounts. One custom role per staff member. You cannot stack two.

The change takes effect the next time that person's app loads their account, so ask them to sign out and back in if they don't see the new screens.

Branch assignment

Every staff member must be assigned to at least one branch, and one of those is their primary branch. That is set on the staff form, not on the custom role.

Branch assignment does not currently limit what a staff member can see. It records where they work, and the POS uses it, but reports and lists are not filtered by it — a manager or cashier at one branch can still see figures from your other branches. If you need a manager who is walled off to their own branch, Kassly does not enforce that yet. The only account that is genuinely store-wide by design is the Owner.

Editing and deleting

Editing a role changes what every staff member holding it can do, immediately. That includes flipping Replaces the base role's permissions: switching it on for a role that Managers hold takes away everything that role doesn't tick. There is no per-person exception. If one person needs something different, make a second role.

You cannot delete a role while it is still assigned to anyone. Kassly refuses with "Cannot delete a role that is still assigned to staff." Move those people off the role first, then delete it. Deleting a role does not delete the staff accounts; they simply fall back to their built-in role's permissions.

Worked examples

A receiving clerk

A hardware store wants the person on the delivery bay to receive deliveries without seeing sales.

  1. Create a role named Receiving Clerk, with the switch off.
  2. Tick Receive Stock (POs & Transfers) and Generate Delivery Receipts. Leave everything else alone.
  3. Create the staff account as Staff, then set its Custom Role to Receiving Clerk.

That person can still clock in and read their payslips, and now also sees Purchase Orders and Transfers in the sidebar. They cannot open the POS, the reports or the product catalog, because neither Staff nor the custom role allows it.

A floor supervisor who doesn't see the numbers

A restaurant wants a supervisor who runs the till and signs off voids, but never sees the dashboard, the reports or the expenses.

  1. Create a role named Floor Supervisor and switch on Replaces the base role's permissions.
  2. Tick Open the POS, Manage Own Shift, End Shift Without Manager PIN, Void Sales Without Manager PIN, View Approvals Queue and Act on Approvals, plus anything else the job needs on the floor.
  3. Create the staff account as a Manager, then set its Custom Role to Floor Supervisor.

The supervisor gets the till, their shift, voids and the void approvals, and nothing else a Manager would normally have. The dashboard, reports and expenses are gone from their sidebar.