Skip to content

Stratamize POS

Users and roles in Admin

Where roles and permissions are edited and how it relates to the Employees page.

Menus and available actions depend on your role and enabled services. In the local demos, use sample records only; no real payments or messages are sent.

Two tabs of Administration deal with people: Users lists the accounts that can sign in, and Roles & Permissions decides what each role may do. You need the admin or super role to use either.

If you have a lower role, the Administration item still appears in the menu and the screen still opens, but the tabs come back empty. That is the permission check, not a fault.

Use the Employees page for staff, not this one

For everyday hiring and rota work, go to Employees, not here. The Employees page is the only place that sets a lock-screen PIN, and a cashier without a PIN cannot unlock a locked terminal or be picked as the active cashier.

Add a user on the Users tab only when you need an account that signs in with its own phone number and does not stand at a till.

The Users tab

The table lists everyone with a name, email, phone number, role badge and status.

  • The search box filters by name, phone or email.
  • Show archived brings archived accounts into the list. It is a view toggle only — there is no button on this tab that archives or reactivates an account.
  • Add User asks for full name, phone number, email and role, all four required. The phone number is what they will sign in with, so enter it with the country code: +15551234567.
  • The pencil on a row opens the account. The only thing you can change there is Role Assignment. Pick the new role and press Save Changes.

What you cannot do, and why

  • You cannot change your own roles.
  • You cannot give anyone a role higher than your own. The built-in ladder is super → admin → manager → cashier and employee → viewer, so an admin cannot make someone a super, and a manager cannot make someone an admin. Appointing a peer is allowed.
  • For a role you created yourself, the rule is different: you can only grant it if every permission it carries is one you hold. You cannot hand out access you do not have.
  • You cannot overwrite the lock-screen PIN of someone who outranks you.

These are refusals from the server, not just hidden buttons. If a change you expect to work is rejected, it is because of one of these rules.

The Roles & Permissions tab

The left column lists your roles. The ones marked System — super, admin, manager, cashier, employee, viewer — ship with the product.

Click a role and its permissions appear on the right, grouped into categories, with a count at the top: N of M permissions enabled.

  • For a System role, the boxes are dimmed and Save is disabled. You can read what a system role can do; you cannot change it.
  • For a role you created, tick and untick permissions and press Save.

Create a role

Press Add above the role list, give it a name and a short description, and press Create Role. It starts with no permissions — open it and tick what it should have.

A custom role is useful when a system role is close but not right: a shift lead who needs refunds but not admin, for example.

Delete a role

Hover a custom role and press the bin. You are asked to confirm. System roles have no bin — attempting it says Cannot delete system roles.

Move anyone using a role to another role before you delete it.

Where the change takes effect

Role and permission changes apply the next time that person's request reaches the server. Someone already signed in does not need to sign out, but a screen they already have open will not redraw on its own — tell them to reload.