Staff & shifts
The Staff page gives your team personal logins to the admin panel: everyone signs in with their own email and password and sees only the sections their role allows. The same page hosts the shift schedule and time tracking.
Open: Admin panel → Staff (only the account owner manages the list).
Roles and access#
| Role | What they see and can do |
|---|---|
| Manager | Menu, orders, POS, inventory, locations and devices |
| Waiter | Orders and POS only |
| Cook | Orders and the kitchen screen (KDS) only |
| Courier | Delivery screen only: their orders, map and routes |
The owner keeps full access to everything, including finance, subscription and settings.
Three levels per section#
A section is not granted "all or nothing": every section allowed to a role has three levels — 👁 view, ✏️ edit data and ⚙️ section settings. You can, for example, let a stock keeper view and edit inventory but keep them out of its settings, and leave an accountant with read-only finance.
What the level changes on the employee's screen:
- 👁 view only — the section header shows a "View only" note explaining who grants the edit level, and the "add", "create", "delete" buttons are disabled (hovering explains why). Lists, search, filters, printing and exports keep working.
- ✏️ edit — normal work with the section. The server additionally issues a write grant for that section's data; without this level writing is physically impossible, even around the interface.
- ⚙️ settings — the "Section settings" gear in the window header. Without this level the gear is simply not there. In the general Settings hub such a role keeps only the personal tabs — "Interface" (how the admin panel looks for them) and "Personal SIP accounts"; account-wide parameters are hidden.
The levels are already honoured by Menu, Orders, Inventory, Staff, Customers, Appointments, Tables & bookings, POS, Finance and Settings; the "Section settings" gear is gated by the ⚙️ level in every section at once. The remaining sections still show a role everything they contain, without splitting view from edit — we are rolling them out one by one.
Adding an employee#
- Click "Add employee".
- Enter the email (used as the login), name and role.
- Set a password or click "Generate".
- Hand the credentials to the employee — the password is shown only once (there's a "Copy credentials" button).
At any time you can reset the password, add notes (schedule preferences, contacts, documents) or delete the employee — they immediately lose access.
Workspaces#
The admin sidebar has a Workspace switcher: Administration, Hall, Kitchen, Delivery, Marketing. It trims the menu to relevant sections — handy on a waiter's tablet (just Orders, POS, Kitchen, Floor Plan) or a kitchen device. A workspace is a filter on top of role permissions: access is defined by the role, the workspace just hides the clutter.
Shifts: plan vs fact#
The staff page includes a shift schedule:
- Plan — the manager lays out shifts per day (start and end time). Once a month's timesheet is closed, its shifts can no longer be added or edited: the grid says so with a “🔒 The <month> timesheet is closed” note before the first click, and the account owner can reopen the month on the Plan vs fact tab;
- Fact — the employee taps clock-in and clock-out; time is recorded server-side, so it can't be forged from a device. Clock-in can be restricted to the venue — by geofence or only from a venue terminal (a tablet with a PIN pad or a monitor with a QR code) — and forgotten shifts can be closed automatically, see Clock-in and clock-out;
- Plan vs fact — the summary highlights deviations: late arrivals, overtime, no-shows. Plan and deviation are counted as of today: shifts still ahead are not treated as unworked hours — their hours are shown on a separate grey line, “ahead: 16h 40m”. “Today” and “already over” follow the location’s time zone (from its profile), not your computer’s clock. The timesheet sign-off block uses the same rule: a shift without a clock-out lands in the “to resolve” list only once its planned time is over, and only then does it get the “Mark as absent” button — you can’t mark an absence for tomorrow’s shift. Shifts are grouped by role.
Worked hours feed into Finance (the Staff tab) — labor costs are visible next to revenue.
What you need to get started#
- Owner permissions — employees are created by the account owner; the "Employees", "Roles and access", "Payroll" and "Labour cost" views are available to them only, while the schedule and HR views are also open to a manager.
- The employee's email and a chosen role — with those the person signs into the admin panel as themselves.
- A shift schedule — for plan vs. fact and for distributing tips into a pool.
- Pay rates — for payroll and labour cost calculations.
- Login codes and device QR codes — to put the POS, kitchen display or kiosk on a tablet (QR codes and devices).
Limitations#
- The invitation email may not arrive — the access is not lost then. If mail fails, the invitation dialog itself shows the sign-in address, login and temporary password: hand them over any way you like. The previous password no longer works at that point.
- Access levels are enforced in the interface. Writing a section's data to storage is already refused by the server for an employee without the "edit" level, but individual API operations are so far limited by the interface only — the server-side check of levels is still being written.
- Restricting an employee to specific locations does not apply yet — the field exists in the contract but access is not narrowed by it.
- Russian HR records are written only on the Russian contour (a personal-data residency requirement); for Kazakhstan the HR module is unavailable anywhere — the system says so honestly and shows an article.
- The "My documents" block does not work for line staff — a known access defect.
- A shift reminder arrives within a window, not to the minute — the mailing runs on a shared half-hourly tick, so "2 hours before" in practice means 1.5–2 hours before. Employee self-service itself works: shift swaps, leave requests, clock-in from a phone and the "My details" block in the "Mine" section (phone and emergency contact change instantly; address, payout details and the identity document — type, number, issuing authority, issue date and "valid until" — go to the manager for approval).
- There is no export to 1C.
- The target labour-cost percentage is stored in the browser — on another device you will have to set it again.
- The "Roles and access", "Payroll" and "HR records" screens are complex — our internal clarity review gives them 2 out of 5; they were written for an HR specialist, not for an owner.
Troubleshooting#
The employee did not receive an invitation. Check the address in their card and the spam folder — the email is sent from the brand address. If it did not go out at all, the invitation dialog shows the login and the temporary password: give them in person. The previous password no longer works after an invitation.
The employee sees the wrong sections. Check the role: the set of sections is defined by it, and the "workspace" only narrows the interface visually. On the POS the real permission layer is role plus PIN.
The employee cannot open "My documents". A known access defect for line staff — hand the document over another way.
The HR section is blocked. This is the personal-data residency gate: Russian HR records are kept only on the Russian brand.
Payroll was not calculated. Pay rates are missing, or there are no closed shifts in the period.
Payroll does not cover every employee. A payroll calculation is a snapshot of the moment it was made: anyone added (or given a pay rate) later is not in it. The screen says so — above the table of an approved month there is a line "These employees are not in the approved calculation" with every name and reason. To include them in that month, go back to the draft (undo the payment record → correct the approved calculation) and press "Refresh the data and recalculate" — manual amounts survive a recalculation. You can also leave a paid month alone and pay these people in the next one.
Related#
- Clock-in and clock-out — venue terminal, QR from a monitor, auto clock-out
- POS — the waiter's work screen
- Kitchen (KDS) — the cook's work screen
- Own delivery — the courier's work screen
- Floor plan — assigning waiters to tables
- Finance — staff reports
FAQ#
How many employees can I add?#
Depends on your plan — see pricing. The system tells you when the limit is reached.
Can a waiter see finance or settings?#
No. A waiter sees only orders and the POS. Role isolation applies to every section of the admin panel.
How does a waiter get bound to an order?#
Automatically: an order created by a waiter at the POS is bound to them; orders from the waiter's tables ("Waiters" mode on the Floor Plan) too. The binding is visible in the order card.
Can I track shifts without daily admin usage?#
Yes, the shift schedule works for any employee regardless of how often they use the admin panel.