Staff Management
The portal separates staff identity, store assignment, and permission design:
- Store Operations > Staff manages membership and the effective role for the selected store.
- Organization > Staff manages the organization roster and invitations.
- Organization > Access manages organization roles, permission groups, and member role assignments.
A person must belong to the organization before they can be added to a store. Removing someone from one store does not remove their organization membership or access to another store.
Page access requirements
Each navigation entry requires every permission listed for it:
| Page | Scope | Required permissions |
|---|---|---|
| Store Staff | Selected store | org.admin and org.members.read and store.members.read |
| Organization Staff | Organization | org.admin and org.members.read |
| Organization Access | Organization | org.admin and org.members.read and store.members.read |
These page gates do not grant every action on the page. In particular, being called a manager does not automatically allow a person to invite users.
Invite organization staff
Inviting or importing organization staff, and cancelling a pending invitation, requires org.invites.write in addition to access to Organization Staff.
- Open Organization > Staff.
- Select Invite Organization Staff.
- Enter the person's email address.
- Choose an Organization Role from the available organization-scoped roles.
- Select Send Invite.
- Open Pending Invites and verify the email, role, status, and expiration.
Use Cancel invite if a pending invitation was sent to the wrong address or with the wrong role. If delivery could not be confirmed but a pending invite exists, cancel that invite before attempting another.
For a bulk invitation, select Import CSV, download the current template, complete it, and upload it. Each accepted row sends an organization invitation; it does not directly assign the person to a store.
Add an organization member to a store
Adding or changing store membership requires:
store.members.write; and- either
store.members.adminororg.members.admin.
To add a member:
- Select the target store.
- Open Store Operations > Staff.
- Select Add to Store.
- Choose an existing Organization Member who is not already assigned to the store.
- Choose a Store Role belonging to the selected store.
- Select Add.
- Confirm the person appears in Selected Store Staff with the expected role.
The list shows name, email, effective store role, active state, and last login. It is scoped only to the selected store.
Change or remove selected-store access
To change a store role:
- Select Edit role next to the member.
- Choose the new Selected-store role.
- Select Save role.
- Confirm the effective role in the list.
Saving replaces the member's effective role for the selected store. It does not change organization access or another store's role.
Removing someone from the selected store requires both store.members.admin and store.transactions.admin.
- Select Remove from store.
- Verify the person's identity and selected store in the confirmation.
- Confirm the removal.
- Check the other store and organization memberships separately if the person is leaving the business.
Manage organization roles and permissions
Open Organization > Access to review:
- Organization Members: people who belong to the organization;
- Roles: named access sets, optionally scoped to a store;
- Groups: advanced reusable permission bundles shared by roles; and
- Permissions: the read-only catalog of available capabilities.
Create a role
- Select Create Role.
- Enter a clear name that describes the job rather than a person's name.
- Choose organization scope or the intended store scope.
- Select only the permissions required for that job.
- Save the role and review its scope and permission count.
System roles cannot be edited or deleted. Editing or deleting a custom role can remove access from every assigned user, so read the affected-user warning before confirming. Use Groups only when the same advanced permission bundle must be shared across multiple roles.
Assign roles to a member
Assigning or removing member roles requires org.members.admin; org.admin alone is not sufficient for that action.
- Under Roles, choose the person in Assign roles to member.
- Wait for the person's current assignments to load.
- Review each role's organization or store scope.
- Enable or disable the intended role.
- Confirm that the assignment reloads successfully.
The portal only permits you to grant a role that you already possess. If the assignment control is unavailable, ask an administrator with org.members.admin and the intended role to perform the change.
Review access safely
After an invitation, assignment, role change, or removal:
- Check the organization roster.
- Check every store the person should or should not access.
- Confirm the effective role at each store.
- Ask the person to sign in and verify that the expected navigation and actions appear.
Do not share logins between staff. Individual accounts preserve attribution for sales, returns, cash activity, and administrative changes.