Staff, Roles, Permissions, And Access Logs
Invite staff safely, assign roles, control module access, review feature catalog changes, and audit organization activity.
Staff access control decides who can see what in your restaurant. Good access keeps data safe and stops counter staff from opening owner billing or branch settings by mistake.
Review permissions when people join, change role, or leave—not only on day one.
Default roles
Zesty ships with a simple role ladder. Your organization may customize permission bundles per role.
| Role | Typical access |
|---|---|
| Owner | Everything: billing plan, features, all branches, support, staff |
| Admin | Broad config and operations; may exclude subscription billing |
| Staff | Daily modules: orders, KDS, billing, POS, inventory, menu edits (as granted) |
| Member | Minimal dashboard unless expanded |
Roles are a starting point. Fine-tune with individual permissions where needed.
Permission areas
Permissions map to modules and sensitive actions, including:
| Area | Examples |
|---|---|
| Orders | Create, update lifecycle, cancel |
| KDS | Kitchen board access |
| Billing | Bill, collect, discount, refund |
| Tables | Layout, QR, sessions |
| Inventory | Adjust, count, transfer, PO |
| Expenses | Create, approve |
| POS | Register sales, void, refund |
| Customers | View, edit, loyalty adjustments |
| Menu | Edit items, availability |
| Analytics | Sales and payment reports |
| Alerts | View and acknowledge |
| Branches | Branch workspace and overrides |
| Settings | Org profile, payments, printers |
| Staff | Invites, role changes |
| Refunds | Manager-level money back |
| Campaigns | WhatsApp outreach (plan permitting) |
Principle of least access: grant the smallest set that still lets the person do their job.
People & Access, and Location Staff
Two surfaces, two scopes:
- People & Access is the organization-level list — everyone who can sign in to your workspace, their role, and their PIN for shared counter devices.
- Location Staff is who works at a given Location.
A Staff member belongs to one Location. A Manager can be assigned to several. Owners and Admins are organization-wide.
Assigning someone to a Location is what puts them on that Location's roster, on the floor list in Shift Desk, and in its reports.
Staff PINs
For shared counter devices, each staff member has a four-digit PIN set on their record in People & Access. They pick their name on "Who's on the counter?" and enter it; five wrong tries locks that PIN for five minutes.
A PIN identifies who is acting on an already-signed-in device. It is not a password and grants nothing the person's role does not already allow. See POS register.
Inviting staff
- Go to staff management in organization or branch workspace
- Enter email or phone for the invitee
- Assign role and branch scope (if multi-outlet)
- Send invite
- Confirm the person received it and signed in
Safety habits
- verify identity before inviting (wrong email = wrong access)
- remove stale invites that were never accepted
- disable or remove users on their last day
- never share one login across multiple people
A team on the Basic plan
Basic has three logins — the owner and two more — and no Staff module, so there is no clock-in, staff shift or scheduling. Here is how a small counter team runs on it:
- Inviting. The owner (or an admin) invites from People & Access: Location Settings → People & Access, or Workspace Settings → People & Access. Give a cashier or cook the Staff role and a manager the Manager role. Pending invitations count towards the three logins.
- Signing in. Each person accepts the email invitation and signs in with their own account. On a shared phone or tablet running the Zesty app they can instead tap Switch under More, pick their name, and enter their counter PIN, which they set from their own account settings. If a PIN gets locked, the owner uses Clear counter PIN on that person in People & Access and they set a new one.
- The day. The owner or a manager opens the Location shift on the Shift desk, and the cash count and close checks work as on every plan. Nobody clocks in: while the Location shift is open, anyone signed in can take orders, bill, and work the kitchen display. To let a Staff login open and close the day, switch on Staff may open and close the day in the Shift desk settings, or make that person the temporary shift lead.
- Sales. The owner and managers see today's, yesterday's and the last seven days' sales on the dashboard. Staff logins do not.
Silver adds the Staff module: per-person clock-in, staff shifts and scheduling, fifteen logins, and the Staff screen.
Feature catalog saves (owners)
Owners and admins change which modules are on from Settings → Features.
Important rules:
- save replaces the entire feature snapshot—review the full list before confirming
- requires password or one-time email code (passwordless accounts)
- plan-locked features need upgrade after trial
Staff permissions cannot enable a module the catalog turned off.
Operational shift authority
Some actions depend on who opened the shift and manager permissions:
- opening and closing branch shift
- bypassing shift gate (admins, emergencies only)
- staff shift models (per-member shifts)
Train shift leads before go-live: Operational shift
Location scope
Multi-outlet staff may be limited to one Location or several. Location scope affects:
- which orders and inventory they see
- which reports export
- which QR tables they manage
Wrong branch scope is a common cause of "I cannot see today's sales."
Access logs
Access logs record important actions across organization and branch context. Use them for:
- quarterly permission audits
- investigating unusual refunds or menu price changes
- support tickets ("who changed this setting?")
Logs complement—not replace—your internal HR and cash-control policies.
Support access
Eligible admins can allow support access when opening or managing a support ticket.
Rules:
- allow only for the ticket being worked
- state a clear reason
- review and revoke after resolution
Support access is audited like other sensitive access.
Recommended review schedule
| When | Action |
|---|---|
| New hire | Invite with minimal permissions |
| Promotion | Expand permissions deliberately |
| Role change | Remove old permissions that no longer apply |
| Departure | Remove same day |
| Plan change | Re-read feature catalog vs role needs |
| New branch | Confirm branch managers scoped correctly |
Common questions
Staff sees module owner does not expect
Check role, individual permission override, feature catalog, and branch.
Cannot refund
Refund permission is often manager-only.
Former staff still in list
Remove or disable account; do not leave dormant logins on shared tablets.