Staff, Roles, Permissions, And Access Logs
Invite staff safely, assign roles, control module access, review feature catalog changes, and audit organization activity.
Staff access control decides who can see what in your restaurant. Good access keeps data safe and stops counter staff from opening owner billing or branch settings by mistake.
Review permissions when people join, change role, or leave—not only on day one.
Default roles
Zesty ships with a simple role ladder. Your organization may customize permission bundles per role.
| Role | Typical access |
|---|---|
| Owner | Everything: billing plan, features, all branches, support, staff |
| Admin | Broad config and operations; may exclude subscription billing |
| Staff | Daily modules: orders, KDS, billing, POS, inventory, menu edits (as granted) |
| Member | Minimal dashboard unless expanded |
Roles are a starting point. Fine-tune with individual permissions where needed.
Permission areas
Permissions map to modules and sensitive actions, including:
| Area | Examples |
|---|---|
| Orders | Create, update lifecycle, cancel |
| KDS | Kitchen board access |
| Billing | Bill, collect, discount, refund |
| Tables | Layout, QR, sessions |
| Inventory | Adjust, count, transfer, PO |
| Expenses | Create, approve |
| POS | Register sales, void, refund |
| Customers | View, edit, loyalty adjustments |
| Menu | Edit items, availability |
| Analytics | Sales and payment reports |
| Alerts | View and acknowledge |
| Branches | Branch workspace and overrides |
| Settings | Org profile, payments, printers |
| Staff | Invites, role changes |
| Refunds | Manager-level money back |
| Campaigns | WhatsApp outreach (plan permitting) |
Principle of least access: grant the smallest set that still lets the person do their job.
Inviting staff
- Go to staff management in organization or branch workspace
- Enter email or phone for the invitee
- Assign role and branch scope (if multi-outlet)
- Send invite
- Confirm the person received it and signed in
Safety habits
- verify identity before inviting (wrong email = wrong access)
- remove stale invites that were never accepted
- disable or remove users on their last day
- never share one login across multiple people
Feature catalog saves (owners)
Owners and admins change which modules are on from Settings → Features.
Important rules:
- save replaces the entire feature snapshot—review the full list before confirming
- requires password or one-time email code (passwordless accounts)
- plan-locked features need upgrade after trial
Staff permissions cannot enable a module the catalog turned off.
Operational shift authority
Some actions depend on who opened the shift and manager permissions:
- opening and closing branch shift
- bypassing shift gate (admins, emergencies only)
- staff shift models (per-member shifts)
Train shift leads before go-live: Operational shift
Branch scope
Multi-outlet staff may be limited to one branch or several. Branch scope affects:
- which orders and inventory they see
- which reports export
- which QR tables they manage
Wrong branch scope is a common cause of "I cannot see today's sales."
Access logs
Access logs record important actions across organization and branch context. Use them for:
- quarterly permission audits
- investigating unusual refunds or menu price changes
- support tickets ("who changed this setting?")
Logs complement—not replace—your internal HR and cash-control policies.
Support access
Eligible admins can allow support access when opening or managing a support ticket.
Rules:
- allow only for the ticket being worked
- state a clear reason
- review and revoke after resolution
Support access is audited like other sensitive access.
Recommended review schedule
| When | Action |
|---|---|
| New hire | Invite with minimal permissions |
| Promotion | Expand permissions deliberately |
| Role change | Remove old permissions that no longer apply |
| Departure | Remove same day |
| Plan change | Re-read feature catalog vs role needs |
| New branch | Confirm branch managers scoped correctly |
Common questions
Staff sees module owner does not expect
Check role, individual permission override, feature catalog, and branch.
Cannot refund
Refund permission is often manager-only.
Former staff still in list
Remove or disable account; do not leave dormant logins on shared tablets.