Custom Roles
Build your own permission sets. Add to a built-in role, or replace it outright, so a staff member can do exactly what you trust them with.
10 min read · Updated 26 Sep 2026
On this page
- Two kinds of custom role
- Adding to a built-in role
- Replacing a built-in role
- Creating a role
- What you can grant
- Approvals need two permissions
- Add-ons still apply
- Assigning a role to a staff member
- Branch assignment
- Editing and deleting
- Worked examples
- A receiving clerk
- A floor supervisor who doesn't see the numbers
The four built-in roles cover most stores, but they are fixed. A custom role changes what one group of staff can do. Examples: a cashier who can also receive deliveries, a stockman who can see the warehouse but never the sales figures, or a supervisor who runs the till but never sees the reports.
You'll find this at Settings → Custom Roles. Creating, editing and deleting roles needs the Manage Custom Roles permission. The Owner always has it.
Two kinds of custom role
Every custom role works in one of two ways. The Replaces the base role's permissions switch on the role form decides which.
| Switch | What staff with the role get |
|---|---|
| Off (the default) | Everything their built-in role already allows, plus the permissions ticked on the custom role |
| On | Only the permissions ticked on the custom role, plus clocking in and out and reading their own payslips |
Every role created before this switch existed works the first way. Nothing about them changed.
The role list marks roles with the switch on as Replaces base role.
Adding to a built-in role
With the switch off, the custom role is layered on top of the built-in role. Every permission the built-in role carries stays, and the ticked ones are added. Use this to lift a Cashier or Staff account up, such as a cashier who can also adjust stock.
A role in this mode can never take anything away. Giving it to a Manager usually changes little, because Managers already hold most permissions.
Replacing a built-in role
With the switch on, the built-in role's permissions no longer apply. The staff member can do what is ticked on the custom role and nothing else. Use this to take something away, such as a Manager who runs the floor but must not see the reports, or a cashier who needs a manager's PIN for every manual discount.
Two things are always kept, whatever you tick: Clock In / Out (Self) and View Own Payslips. Every employee is entitled to their own time records and payslips.
Tick everything the job needs. A role in this mode starts from nothing. If these staff run a till, tick Open the POS. If they open the dashboard, tick View Dashboard. Anything left unticked disappears from their menus and screens.
The Owner is never restricted by a custom role.
Creating a role
Settings → Custom Roles → New Role opens a form with these fields:
| Field | Required | Limit |
|---|---|---|
| Name | Yes | 255 characters, and must be unique within your store |
| Description | No | 255 characters |
| Replaces the base role's permissions | No | Off unless you switch it on |
| Capabilities | Yes | At least one must be ticked |
The name is what you'll see in the staff form later, so make it describe the job: "Senior Cashier", "Stockman", "Warehouse Clerk". The description is only ever shown on this page.
The capability list is a long set of tickboxes grouped by area. Each one shows a plain-language label and, underneath it, the technical key it maps to. Tick what you need and press Create.
You can also start from a template, or use the copy button on an existing role to clone it. A clone keeps the original's switch setting.
What you can grant
Each permission covers one action. Holding it means the staff member can do that action directly. At the POS, some actions can still be done without the permission if a manager enters their PIN. The manager must hold the permission themselves.
In the web back office there is no manager-PIN prompt. A button for an action the signed-in person lacks the permission for is simply not shown.
These are the permissions people most often grant:
| Group | Capability | What it allows |
|---|---|---|
| POS & Cash | Open the POS | Run a till |
| POS & Cash | End Shift Without Manager PIN | Close a shift without a manager standing by |
| POS & Cash | Void Sales Without Manager PIN | Void a sale on their own |
| POS & Cash | See All Staff's Transactions | See everyone's sales, not just their own |
| POS & Cash | Process Returns | Process a return straight away and approve other people's returns. Without it, a return is sent for approval |
| POS & Cash | Set Up Tables & Floor Plan | Add, edit and remove tables. Seating and clearing tables stays open to everyone at the POS |
| Catalog & Inventory | View Products | See the product catalog |
| Catalog & Inventory | Create / Edit Products | Add, edit, import and delete products, services and modifiers |
| Catalog & Inventory | Manage Categories | Add, edit and delete categories |
| Catalog & Inventory | Stock In / Adjust Inventory | Stock in, adjust stock and use bulk stock-in |
| Catalog & Inventory | Receive Stock (POs & Transfers) | See purchase orders and stock transfers, and receive them |
| Catalog & Inventory | Create / Submit / Cancel Purchase Orders & Suppliers | Raise and manage purchase orders and suppliers |
| Catalog & Inventory | View Compositions/Ingredients | Read recipes and see ingredient consumption, without editing them |
| Catalog & Inventory | Create / Edit Recipes (Compositions) | Create and edit recipes |
| Warehouse | View Warehouses | See warehouses, their zones and bins, stock levels, and receiving history |
| Warehouse | Manage Warehouses | Create and edit warehouses, zones and bins; create, approve and cancel stock transfers |
| Warehouse | Request Stock Transfers | Raise a stock transfer request |
| Production | Run Production (Commissary) | Approve, reject and complete production runs |
| Production | Generate Delivery Receipts | Print delivery receipts for purchase orders, production orders and transfers |
| Customers | Manage Customers | Add, edit and delete customers |
| Reports & Compliance | View Reports / View Financial Reports | Open the reports, and the profit and margin reports |
| Reports & Compliance | Schedule Report Emails & Saved Views | Set up scheduled report emails |
| Finance & Accounting | Approve / Reject Expenses | Approve or reject pending expenses |
| Finance & Accounting | Edit Approved / Rejected Expenses | Change or delete an expense after it has been approved or rejected |
| Workforce | Act on Approvals | Approve or reject items in the approvals queue (see below) |
| Workforce | View Everyone's Attendance & Timesheets | Open the Timesheet for all staff |
| Workforce | Add / Edit / Deactivate Staff | Manage staff accounts |
| Loans | Approve Loans / Write Off Loans | Approve loan requests; write off a loan |
| Payroll | Approve Payroll Runs / Mark Payroll Paid | Sign off a computed payroll run; mark a posted run paid |
| Settings & Admin | Edit Store, Receipt & Inventory Settings | Save Store Settings and Receipt Settings. Everyone can still read them |
| Settings & Admin | Edit Security Settings | Change the manager-approval and two-person rules |
| Settings & Admin | Manage Branches, Manage Subscription & Billing, Manage Custom Roles | What they say |
If you created roles before September 2026, check them. Some tickboxes used to do nothing: products, categories, customers, stock in and adjust, shift management, returns and BIR readings. They now do what their labels say. A cashier whose role has Create / Edit Products ticked can now edit products.
Manager PIN Override (older app versions) only matters for phones and tablets that haven't updated the Kassly app. Newer versions check the specific permission for each action instead.
Approvals need two permissions
Act on Approvals lets someone work the approvals queue. For each request, they also need the permission for that kind of request:
| Request | Also needs |
|---|---|
| Void | Void Sales Without Manager PIN |
| Refund or return | Process Returns |
| Expense | Approve / Reject Expenses |
| Purchase order | Create / Submit / Cancel Purchase Orders & Suppliers |
| Stock transfer | Manage Warehouses |
| Stock count or receiving variance | Stock In / Adjust Inventory |
| Production run | Run Production (Commissary) |
| Loan | Approve Loans |
| Payroll run | Approve Payroll Runs |
| Leave | Approve Leave |
| Discount override, stock adjustment | Nothing extra |
Requests they can't act on still show in the queue, but without the Approve and Reject buttons.
Two permissions change money flow rather than just visibility:
- Manage Warehouses and Run Production (Commissary) both auto-approve the requests their holder creates. A stock transfer raised by someone with Manage Warehouses skips the approval step entirely; the same is true of a production run raised by someone with Run Production. Grant these two only to people you would have approved the request for anyway.
Add-ons still apply
A capability is permission, not entitlement. The warehouse, production, loans and payroll capabilities all sit behind paid add-ons, and granting the capability to a staff member does not turn the add-on on:
| Capabilities | Needs |
|---|---|
| Warehouse, Production, Generate Delivery Receipts | Warehouse & Commissary (₱500 per branch each month) |
| Receive Stock, purchase orders | Inventory Pro (₱400 per branch each month) |
| Stock transfers | Stock Transfers Between Branches (₱300 per branch each month) |
| View Compositions/Ingredients | Recipe Costing (₱350 per branch each month) |
| Loans | Loans (₱300 per branch each month) |
| Payroll, View Own Payslips | Payroll (₱300 per branch each month) |
| Configure Job Order Board | Job Orders & Service Tickets (₱400 per branch each month) |
Any bundle that includes the add-on works too. See Plans and add-ons.
Assigning a role to a staff member
Custom roles do nothing until someone holds one. Open the staff member on the staff page and use the Custom Role (optional) dropdown. It is offered for Manager, Cashier and Staff accounts. One custom role per staff member. You cannot stack two.
The change takes effect the next time that person's app loads their account, so ask them to sign out and back in if they don't see the new screens.
Branch assignment
Every staff member must be assigned to at least one branch, and one of those is their primary branch. That is set on the staff form, not on the custom role.
Branch assignment does not currently limit what a staff member can see. It records where they work, and the POS uses it, but reports and lists are not filtered by it — a manager or cashier at one branch can still see figures from your other branches. If you need a manager who is walled off to their own branch, Kassly does not enforce that yet. The only account that is genuinely store-wide by design is the Owner.
Editing and deleting
Editing a role changes what every staff member holding it can do, immediately. That includes flipping Replaces the base role's permissions: switching it on for a role that Managers hold takes away everything that role doesn't tick. There is no per-person exception. If one person needs something different, make a second role.
You cannot delete a role while it is still assigned to anyone. Kassly refuses with "Cannot delete a role that is still assigned to staff." Move those people off the role first, then delete it. Deleting a role does not delete the staff accounts; they simply fall back to their built-in role's permissions.
Worked examples
A receiving clerk
A hardware store wants the person on the delivery bay to receive deliveries without seeing sales.
- Create a role named Receiving Clerk, with the switch off.
- Tick Receive Stock (POs & Transfers) and Generate Delivery Receipts. Leave everything else alone.
- Create the staff account as Staff, then set its Custom Role to Receiving Clerk.
That person can still clock in and read their payslips, and now also sees Purchase Orders and Transfers in the sidebar. They cannot open the POS, the reports or the product catalog, because neither Staff nor the custom role allows it.
A floor supervisor who doesn't see the numbers
A restaurant wants a supervisor who runs the till and signs off voids, but never sees the dashboard, the reports or the expenses.
- Create a role named Floor Supervisor and switch on Replaces the base role's permissions.
- Tick Open the POS, Manage Own Shift, End Shift Without Manager PIN, Void Sales Without Manager PIN, View Approvals Queue and Act on Approvals, plus anything else the job needs on the floor.
- Create the staff account as a Manager, then set its Custom Role to Floor Supervisor.
The supervisor gets the till, their shift, voids and the void approvals, and nothing else a Manager would normally have. The dashboard, reports and expenses are gone from their sidebar.