Users & Roles
The four built-in roles and what each can reach, how to add staff, how PIN login works at the counter, and what a manager override actually covers.
10 min read · Updated 26 Sep 2026
On this page
Every person who touches Kassly has their own account and one of four roles. The role decides what they can reach; a four-digit PIN decides who is standing at the till.
Staff accounts live at Management → Staff. Only the Owner can open that page.
The four roles
| Role | Who it's for |
|---|---|
| Owner | You. Full access to everything, including billing and staff |
| Manager | A shift supervisor or branch manager who runs the store day to day |
| Cashier | Someone whose job is the counter |
| Staff | Office and back-of-house people who only need to clock in and read their own payslip |
The table below is what each built-in role gets by default. A custom role can add to it, or replace it entirely for the staff who hold that role. The Owner is never restricted.
Staff is the one that surprises people. It is not "a general employee account" — it is deliberately the narrowest role in the system. A Staff account cannot open the POS and cannot see any admin screen. It exists so that a cleaner, a rider or an office clerk can appear on your timesheet and payroll without being given the keys to the store.
What each role can do
| Task | Owner | Manager | Cashier | Staff |
|---|---|---|---|---|
| Ring up a sale at the POS | Yes | Yes | Yes | No |
| Open and close a shift | Yes | Yes | Yes | No |
| Print an X-reading | Yes | Yes | Yes | No |
| Print a Z-reading | Yes | Yes | No | No |
| Record cash in and cash out | Yes | Yes | Yes | No |
| Reopen a closed shift | Yes | Yes | No | No |
| Process a return or refund | Yes | Yes | No | No |
| Void a sale | Yes | Up to a limit | Needs approval | No |
| Reprint a receipt | Yes | Yes | No | No |
| Create and edit products | Yes | Yes | No | No |
| Adjust stock | Yes | Yes | No | No |
| See customers | Yes | Yes | View only | No |
| Open reports | Yes | Yes | No | No |
| Act on the approvals queue | Yes | Yes | No | No |
| See the audit trail | Yes | Yes | No | No |
| Run payroll | Yes | Yes | No | No |
| Edit pay rates and government IDs | Yes | No | No | No |
| Clock in and out for themselves | Yes | Yes | Yes | Yes |
| Read their own payslips | Yes | Yes | Yes | Yes |
| Add or edit staff accounts | Yes | No | No | No |
| Change Store Settings | Yes | No | No | No |
| Manage billing and add-ons | Yes | No | No | No |
| Create custom roles | Yes | No | No | No |
Two entries deserve a note:
- A Cashier cannot process a return. Refunds and returns require an Owner or a Manager. If your cashiers handle exchanges on their own, they need to be Managers, or a Manager needs to be reachable.
- Discounts have no permission check. Whoever is ringing up the sale can apply a discount, including a Cashier. If discounts are a leak in your store, the control you want is the audit trail and the reports, not a role.
Managers can prepare and run payroll but cannot change what anybody is paid — editing rates and government IDs stays with the Owner. A payroll run a Manager computed still needs the Owner to sign it off.
Adding a staff member
Management → Staff → Add Staff.
Kassly does not send an invitation email. You type the password and the PIN yourself and pass them on to the person. There is no "set up your password" link, so treat the first password as temporary and change it once they've signed in.
| Field | Required | Rule |
|---|---|---|
| Name | Yes | Up to 255 characters |
| Yes | Must be a valid email, and must not already be used by any Kassly account anywhere | |
| Password | Yes, except for Staff | At least 8 characters |
| PIN | Yes, for everyone | Exactly 4 digits |
| Role | Yes | Manager, Cashier or Staff |
| Status | No | Active, Inactive or Suspended. Defaults to Active |
| Custom Role (optional) | No | See Custom roles |
| Branches | Yes | At least one. One of them is marked Primary |
A few things that are easy to trip on:
- The email must be unique across all of Kassly, not just your store. If someone already has an account with another Kassly store on that address, you'll need a different one.
- Branches are required even if you only have one. Tick it and set it as primary.
- The Custom Role dropdown is offered for Manager, Cashier and Staff. A custom role can add permissions to the built-in role, or replace them entirely. See Custom roles.
- A pay rate is not set here. It lives on the Payroll tab of the same page.
Roles you cannot assign
The Owner role is permanent and one-way:
- You cannot create a second Owner. The role dropdown on a new staff member offers Manager, Cashier and Staff only.
- You cannot promote anyone to Owner afterwards. Kassly refuses with "A non-owner cannot be promoted to owner."
- You cannot demote the Owner. Editing the Owner shows the role locked, with the note "The owner role is permanent and cannot be changed."
If the wrong person holds the Owner account, that is not something you can fix from this page — contact support.
Turning an account off
Set the staff member's Status to Inactive or Suspended. Both do exactly the same thing; the only difference is the colour of the badge in the list, so use whichever label you prefer for your own records.
A non-active account:
- cannot sign in — they get "Your account has been deactivated."
- cannot be picked as a manager for an override
- disappears from the timesheet kiosk roster
Deactivating does not sign someone out of a device they are already using. If someone has walked out with a paired tablet, deactivating their account is not enough. Change their password — that revokes every device they are signed in on immediately — or unlink the terminal's device. See Terminal management.
Deleting a staff member
Deleting is for people who have genuinely left. It signs them out of every device at once, and their name stays on every sale and shift they handled — Kassly never rewrites history.
Two behaviours worth knowing:
- You cannot delete your own account. Kassly refuses with "Cannot delete your own account."
- The email address is freed. If the same person comes back, you can create a fresh account on the same address.
Cashier PIN login
On a shared tablet at the counter, nobody wants to type an email and password between customers. Kassly's answer is the PIN.
The owner pairs the device once. After that, staff switch in by typing their own four-digit PIN. The terminal stays linked, and each person's sales are recorded against them individually under the same terminal.
| Length | Exactly 4 digits |
| Who sets it | The Owner, on the staff form |
| Can staff change their own? | No |
| Works offline? | Yes |
| Lockout after wrong attempts? | No |
Some honest detail on that last row. Kassly limits how fast PINs can be tried — ten login attempts a minute, five manager-override checks a minute — but there is no counter that locks an account after so many wrong tries, and nobody gets notified. Every attempt, right or wrong, is written to the audit trail.
Because there are only 10,000 possible four-digit PINs and the PIN alone identifies the person, treat a PIN like a till key rather than a password:
- Don't use
1234, the year, or a birthday. - Change a PIN when someone leaves, and change any PIN they might have watched being typed.
- Never give two people the same PIN. Kassly matches whoever's PIN it is, so shared PINs make your sales-per-cashier figures meaningless.
Staying signed in
There is no session timeout and no auto-lock. Once a staff member signs in, they stay signed in until one of these happens:
| Event | Effect |
|---|---|
| They sign out | That device only |
| The Owner changes their password | Signed out of every device, immediately |
| The Owner deletes the account | Signed out of every device, immediately |
| The Owner sets the account to Inactive | Blocks new sign-ins only — existing devices are not kicked out |
A tablet left signed in stays signed in indefinitely. If your counter tablet is somewhere the public can reach, this matters. Kassly has no screen lock of its own, so use your device's own lock screen and auto-lock timer.
Manager override
An override is a manager standing at the till and typing their PIN to authorise something a cashier is not allowed to do on their own. It is narrower than most people expect. Exactly two things use it:
- Voiding a sale
- Reopening a closed shift — and this one is a permission on the signed-in user, not a PIN prompt. A Cashier cannot reopen a shift even with a manager next to them; the manager has to sign in.
Price overrides, discounts, no-sale drawer opens, deleting a line after scanning, and reprinting a Z-reading have no override path. They are either allowed for that role or not.
How a void override works
When a cashier voids a sale, they must type a reason of at least 5 characters, then a manager types their PIN. Kassly matches the PIN against everyone active in your store, so the cashier never learns which manager approved and never needs to be told a name.
What happens next depends on who typed the PIN:
| Situation | Result |
|---|---|
| A manager's or owner's PIN | The void goes through there and then |
| No manager PIN given | "Void submitted for manager approval." The sale stays as it is until someone acts on the approvals queue |
| A PIN that matched someone without override rights | "This PIN does not have permission to void." |
| A wrong PIN | "Manager PIN verification failed." |
Managers cannot void anything. Above ₱10,000, a void needs the Owner. A manager who tries gets refused, and the void has to be queued for the Owner or done by them.
Voiding a sale that was paid in cash needs an open shift, because the cash has to come out of a drawer that is being counted. If there's no shift open you'll see "Open a shift to refund cash on a void, or choose store credit instead."
Every void ends up in the approvals queue whether it was authorised on the spot or queued for later, so the history is complete. Every PIN check, successful or failed, is written to the audit trail.
The two-person rule
Kassly has an optional stricter mode for destructive actions — voids, refunds and discount overrides. With it on:
- No void is ever done on the spot. Every one queues for approval.
- A manager's own PIN cannot authorise their own request. Kassly answers "A different user must approve this action."
- Approving one of these requires the approver to re-type their own PIN.
The two-person rule cannot be switched on from the web dashboard yet. There is no Security page in Settings. If you want it enabled, ask support.