Documentation

Staff, Roles, Permissions, And Access Logs

Invite staff safely, assign roles, control module access, review feature catalog changes, and audit organization activity.

Staff access control decides who can see what in your restaurant. Good access keeps data safe and stops counter staff from opening owner billing or branch settings by mistake.

Review permissions when people join, change role, or leave—not only on day one.

1InviteRightperson2RoleOwneradmin3PermissionSmallestaccess4AuditLogsreview

Default roles

Zesty ships with a simple role ladder. Your organization may customize permission bundles per role.

RoleTypical access
OwnerEverything: billing plan, features, all branches, support, staff
AdminBroad config and operations; may exclude subscription billing
StaffDaily modules: orders, KDS, billing, POS, inventory, menu edits (as granted)
MemberMinimal dashboard unless expanded

Roles are a starting point. Fine-tune with individual permissions where needed.

Permission areas

Permissions map to modules and sensitive actions, including:

AreaExamples
OrdersCreate, update lifecycle, cancel
KDSKitchen board access
BillingBill, collect, discount, refund
TablesLayout, QR, sessions
InventoryAdjust, count, transfer, PO
ExpensesCreate, approve
POSRegister sales, void, refund
CustomersView, edit, loyalty adjustments
MenuEdit items, availability
AnalyticsSales and payment reports
AlertsView and acknowledge
BranchesBranch workspace and overrides
SettingsOrg profile, payments, printers
StaffInvites, role changes
RefundsManager-level money back
CampaignsWhatsApp outreach (plan permitting)

Principle of least access: grant the smallest set that still lets the person do their job.

Inviting staff

  1. Go to staff management in organization or branch workspace
  2. Enter email or phone for the invitee
  3. Assign role and branch scope (if multi-outlet)
  4. Send invite
  5. Confirm the person received it and signed in

Safety habits

  • verify identity before inviting (wrong email = wrong access)
  • remove stale invites that were never accepted
  • disable or remove users on their last day
  • never share one login across multiple people

Feature catalog saves (owners)

Owners and admins change which modules are on from Settings → Features.

Important rules:

  • save replaces the entire feature snapshot—review the full list before confirming
  • requires password or one-time email code (passwordless accounts)
  • plan-locked features need upgrade after trial

Staff permissions cannot enable a module the catalog turned off.

Operational shift authority

Some actions depend on who opened the shift and manager permissions:

  • opening and closing branch shift
  • bypassing shift gate (admins, emergencies only)
  • staff shift models (per-member shifts)

Train shift leads before go-live: Operational shift

Branch scope

Multi-outlet staff may be limited to one branch or several. Branch scope affects:

  • which orders and inventory they see
  • which reports export
  • which QR tables they manage

Wrong branch scope is a common cause of "I cannot see today's sales."

Access logs

Access logs record important actions across organization and branch context. Use them for:

  • quarterly permission audits
  • investigating unusual refunds or menu price changes
  • support tickets ("who changed this setting?")

Logs complement—not replace—your internal HR and cash-control policies.

Support access

Eligible admins can allow support access when opening or managing a support ticket.

Rules:

  • allow only for the ticket being worked
  • state a clear reason
  • review and revoke after resolution

Support access is audited like other sensitive access.

WhenAction
New hireInvite with minimal permissions
PromotionExpand permissions deliberately
Role changeRemove old permissions that no longer apply
DepartureRemove same day
Plan changeRe-read feature catalog vs role needs
New branchConfirm branch managers scoped correctly

Common questions

Staff sees module owner does not expect
Check role, individual permission override, feature catalog, and branch.

Cannot refund
Refund permission is often manager-only.

Former staff still in list
Remove or disable account; do not leave dormant logins on shared tablets.