Users & Roles

The four built-in roles and what each can reach, how to add staff, how PIN login works at the counter, and what a manager override actually covers.

10 min read · Updated 26 Sep 2026

On this page

Every person who touches Kassly has their own account and one of four roles. The role decides what they can reach; a four-digit PIN decides who is standing at the till.

Staff accounts live at Management → Staff. Only the Owner can open that page.

The four roles

Role Who it's for
Owner You. Full access to everything, including billing and staff
Manager A shift supervisor or branch manager who runs the store day to day
Cashier Someone whose job is the counter
Staff Office and back-of-house people who only need to clock in and read their own payslip

The table below is what each built-in role gets by default. A custom role can add to it, or replace it entirely for the staff who hold that role. The Owner is never restricted.

Staff is the one that surprises people. It is not "a general employee account" — it is deliberately the narrowest role in the system. A Staff account cannot open the POS and cannot see any admin screen. It exists so that a cleaner, a rider or an office clerk can appear on your timesheet and payroll without being given the keys to the store.

What each role can do

Task Owner Manager Cashier Staff
Ring up a sale at the POS Yes Yes Yes No
Open and close a shift Yes Yes Yes No
Print an X-reading Yes Yes Yes No
Print a Z-reading Yes Yes No No
Record cash in and cash out Yes Yes Yes No
Reopen a closed shift Yes Yes No No
Process a return or refund Yes Yes No No
Void a sale Yes Up to a limit Needs approval No
Reprint a receipt Yes Yes No No
Create and edit products Yes Yes No No
Adjust stock Yes Yes No No
See customers Yes Yes View only No
Open reports Yes Yes No No
Act on the approvals queue Yes Yes No No
See the audit trail Yes Yes No No
Run payroll Yes Yes No No
Edit pay rates and government IDs Yes No No No
Clock in and out for themselves Yes Yes Yes Yes
Read their own payslips Yes Yes Yes Yes
Add or edit staff accounts Yes No No No
Change Store Settings Yes No No No
Manage billing and add-ons Yes No No No
Create custom roles Yes No No No

Two entries deserve a note:

  • A Cashier cannot process a return. Refunds and returns require an Owner or a Manager. If your cashiers handle exchanges on their own, they need to be Managers, or a Manager needs to be reachable.
  • Discounts have no permission check. Whoever is ringing up the sale can apply a discount, including a Cashier. If discounts are a leak in your store, the control you want is the audit trail and the reports, not a role.

Managers can prepare and run payroll but cannot change what anybody is paid — editing rates and government IDs stays with the Owner. A payroll run a Manager computed still needs the Owner to sign it off.

Adding a staff member

Management → Staff → Add Staff.

Kassly does not send an invitation email. You type the password and the PIN yourself and pass them on to the person. There is no "set up your password" link, so treat the first password as temporary and change it once they've signed in.

Field Required Rule
Name Yes Up to 255 characters
Email Yes Must be a valid email, and must not already be used by any Kassly account anywhere
Password Yes, except for Staff At least 8 characters
PIN Yes, for everyone Exactly 4 digits
Role Yes Manager, Cashier or Staff
Status No Active, Inactive or Suspended. Defaults to Active
Custom Role (optional) No See Custom roles
Branches Yes At least one. One of them is marked Primary

A few things that are easy to trip on:

  • The email must be unique across all of Kassly, not just your store. If someone already has an account with another Kassly store on that address, you'll need a different one.
  • Branches are required even if you only have one. Tick it and set it as primary.
  • The Custom Role dropdown is offered for Manager, Cashier and Staff. A custom role can add permissions to the built-in role, or replace them entirely. See Custom roles.
  • A pay rate is not set here. It lives on the Payroll tab of the same page.

Roles you cannot assign

The Owner role is permanent and one-way:

  • You cannot create a second Owner. The role dropdown on a new staff member offers Manager, Cashier and Staff only.
  • You cannot promote anyone to Owner afterwards. Kassly refuses with "A non-owner cannot be promoted to owner."
  • You cannot demote the Owner. Editing the Owner shows the role locked, with the note "The owner role is permanent and cannot be changed."

If the wrong person holds the Owner account, that is not something you can fix from this page — contact support.

Turning an account off

Set the staff member's Status to Inactive or Suspended. Both do exactly the same thing; the only difference is the colour of the badge in the list, so use whichever label you prefer for your own records.

A non-active account:

  • cannot sign in — they get "Your account has been deactivated."
  • cannot be picked as a manager for an override
  • disappears from the timesheet kiosk roster

Deactivating does not sign someone out of a device they are already using. If someone has walked out with a paired tablet, deactivating their account is not enough. Change their password — that revokes every device they are signed in on immediately — or unlink the terminal's device. See Terminal management.

Deleting a staff member

Deleting is for people who have genuinely left. It signs them out of every device at once, and their name stays on every sale and shift they handled — Kassly never rewrites history.

Two behaviours worth knowing:

  • You cannot delete your own account. Kassly refuses with "Cannot delete your own account."
  • The email address is freed. If the same person comes back, you can create a fresh account on the same address.

Cashier PIN login

On a shared tablet at the counter, nobody wants to type an email and password between customers. Kassly's answer is the PIN.

The owner pairs the device once. After that, staff switch in by typing their own four-digit PIN. The terminal stays linked, and each person's sales are recorded against them individually under the same terminal.

Length Exactly 4 digits
Who sets it The Owner, on the staff form
Can staff change their own? No
Works offline? Yes
Lockout after wrong attempts? No

Some honest detail on that last row. Kassly limits how fast PINs can be tried — ten login attempts a minute, five manager-override checks a minute — but there is no counter that locks an account after so many wrong tries, and nobody gets notified. Every attempt, right or wrong, is written to the audit trail.

Because there are only 10,000 possible four-digit PINs and the PIN alone identifies the person, treat a PIN like a till key rather than a password:

  • Don't use 1234, the year, or a birthday.
  • Change a PIN when someone leaves, and change any PIN they might have watched being typed.
  • Never give two people the same PIN. Kassly matches whoever's PIN it is, so shared PINs make your sales-per-cashier figures meaningless.

Staying signed in

There is no session timeout and no auto-lock. Once a staff member signs in, they stay signed in until one of these happens:

Event Effect
They sign out That device only
The Owner changes their password Signed out of every device, immediately
The Owner deletes the account Signed out of every device, immediately
The Owner sets the account to Inactive Blocks new sign-ins only — existing devices are not kicked out

A tablet left signed in stays signed in indefinitely. If your counter tablet is somewhere the public can reach, this matters. Kassly has no screen lock of its own, so use your device's own lock screen and auto-lock timer.

Manager override

An override is a manager standing at the till and typing their PIN to authorise something a cashier is not allowed to do on their own. It is narrower than most people expect. Exactly two things use it:

  1. Voiding a sale
  2. Reopening a closed shift — and this one is a permission on the signed-in user, not a PIN prompt. A Cashier cannot reopen a shift even with a manager next to them; the manager has to sign in.

Price overrides, discounts, no-sale drawer opens, deleting a line after scanning, and reprinting a Z-reading have no override path. They are either allowed for that role or not.

How a void override works

When a cashier voids a sale, they must type a reason of at least 5 characters, then a manager types their PIN. Kassly matches the PIN against everyone active in your store, so the cashier never learns which manager approved and never needs to be told a name.

What happens next depends on who typed the PIN:

Situation Result
A manager's or owner's PIN The void goes through there and then
No manager PIN given "Void submitted for manager approval." The sale stays as it is until someone acts on the approvals queue
A PIN that matched someone without override rights "This PIN does not have permission to void."
A wrong PIN "Manager PIN verification failed."

Managers cannot void anything. Above ₱10,000, a void needs the Owner. A manager who tries gets refused, and the void has to be queued for the Owner or done by them.

Voiding a sale that was paid in cash needs an open shift, because the cash has to come out of a drawer that is being counted. If there's no shift open you'll see "Open a shift to refund cash on a void, or choose store credit instead."

Every void ends up in the approvals queue whether it was authorised on the spot or queued for later, so the history is complete. Every PIN check, successful or failed, is written to the audit trail.

The two-person rule

Kassly has an optional stricter mode for destructive actions — voids, refunds and discount overrides. With it on:

  • No void is ever done on the spot. Every one queues for approval.
  • A manager's own PIN cannot authorise their own request. Kassly answers "A different user must approve this action."
  • Approving one of these requires the approver to re-type their own PIN.

The two-person rule cannot be switched on from the web dashboard yet. There is no Security page in Settings. If you want it enabled, ask support.