Staff
Everyone who works here — and exactly what they can touch.
One record per staff member: contact details, joining date, wage, account state — and the roles that decide which screens open when they sign in. A role is a bundle of permissions, not a rank.
106 atomic permissions·11 role bundles·access is the union·computed at sign-in
The whole team on one page.
Who is on shift, who is on leave, and which bundles each person holds. The roles column is an array, not a single value — that is the whole access model in one cell.
Back office · staff directory
A person, an account, and a boundary.
Hiring someone in the system is one form. What that form decides is which of 106 permissions travel with them for the rest of their employment.
One record per person
Name, phone, email, address, emergency contact, ID and joining date on a single profile. The phone number is the login.
Roles as bundles
Tick one or more bundles on the profile. The permissions add up — nobody needs a new role invented for them.
Checked per endpoint
Every API call tests an atomic permission such as billing.generate, never the word "manager".
Wage on the record
Monthly, daily or hourly, with the amount and employment type. Payroll reads this — you don't retype it.
Activity log
Bills generated, discounts applied, clock-ins and clock-outs, each stamped against the staff member who did it.
Deactivate, don't delete
Switching an account off ends its access immediately and leaves every bill, order and payroll row it touched intact.
A role is a bundle, not a rank.
There is no ladder to climb and nothing inherits from anything. A staff member holds an array of roles, and their effective permissions are the union of those bundles — so the same account can be a cashier on Tuesday lunch and the host on Saturday night.
- Eleven bundles: owner, manager, supervisor, cashier, waiter, kitchen, head chef, host, storekeeper, accountant, delivery agent
- Hold several at once — effective access is the union, never the highest
- 106 atomic permissions, each one checked individually on the endpoint
- Permissions are computed when the token is issued, not stored against the user
- What a bundle grants is configurable on the platform, not compiled into the app
Back office · role assignment
Back office · staff profile
The record is also the evidence.
Because every bill, order, discount and clock-in is written against the staff member who did it, the profile answers "who did this, and when" without a separate audit tool.
- Overview — contact, address, emergency contact, ID and joining date
- Attendance — month by month, clock-in and clock-out, hours, present or absent
- Payroll — every run for this person, with days worked, advances and net pay
- Activity — bills, offers applied and shift events, timestamped
- Advances and leave are logged from the profile itself
The staff record is the spine.
Rosters, hours, wages and labour reporting all hang off the same row — there is no second list of people to keep in step.
Who can open this module.
Staff records are gated on staff.hire_fire. Wage figures sit behind the payroll permissions, so a bundle can manage people without seeing what they are paid.
- Owner Everything, including money. Creates and deactivates accounts, assigns any bundle, sees wages, records advances, and runs payroll.
- Manager Hires, assigns, pays. Adds staff, edits profiles, assigns role bundles, and holds the payroll run and delete permissions.
- Supervisor Manages people, not the payout. Same staff-record access, and can view payroll and download payslips — but cannot run, approve or delete a payroll run.
- Accountant Reads the wage side only. No staff-record editing; sees payroll and payslips for reporting, with no ability to run or delete one.
- Everyone else Is a record here, not a user of it. Cashiers, waiters, kitchen, host, storekeeper and delivery agents have accounts in this module but no permission to open it.
Permissions are atomic and checked on every endpoint. A role is a bundle, not a rank — a staff member holds an array of them, and what they can do is the union, computed when their token is issued.
See it running on your menu.
We set the restaurant up with you — menu, tables, staff and printers — rather than handing over a login and wishing you luck.