Documentation

Staff, Roles, Permissions, And Access Logs

Invite staff safely, assign roles, control module access, review feature catalog changes, and audit organization activity.

Staff access control decides who can see what in your restaurant. Good access keeps data safe and stops counter staff from opening owner billing or branch settings by mistake.

Review permissions when people join, change role, or leave—not only on day one.

1InviteRightperson2RoleOwneradmin3PermissionSmallestaccess4AuditLogsreview

Default roles

Zesty ships with a simple role ladder. Your organization may customize permission bundles per role.

RoleTypical access
OwnerEverything: billing plan, features, all branches, support, staff
AdminBroad config and operations; may exclude subscription billing
StaffDaily modules: orders, KDS, billing, POS, inventory, menu edits (as granted)
MemberMinimal dashboard unless expanded

Roles are a starting point. Fine-tune with individual permissions where needed.

Permission areas

Permissions map to modules and sensitive actions, including:

AreaExamples
OrdersCreate, update lifecycle, cancel
KDSKitchen board access
BillingBill, collect, discount, refund
TablesLayout, QR, sessions
InventoryAdjust, count, transfer, PO
ExpensesCreate, approve
POSRegister sales, void, refund
CustomersView, edit, loyalty adjustments
MenuEdit items, availability
AnalyticsSales and payment reports
AlertsView and acknowledge
BranchesBranch workspace and overrides
SettingsOrg profile, payments, printers
StaffInvites, role changes
RefundsManager-level money back
CampaignsWhatsApp outreach (plan permitting)

Principle of least access: grant the smallest set that still lets the person do their job.

People & Access, and Location Staff

Two surfaces, two scopes:

  • People & Access is the organization-level list — everyone who can sign in to your workspace, their role, and their PIN for shared counter devices.
  • Location Staff is who works at a given Location.

A Staff member belongs to one Location. A Manager can be assigned to several. Owners and Admins are organization-wide.

Assigning someone to a Location is what puts them on that Location's roster, on the floor list in Shift Desk, and in its reports.

Staff PINs

For shared counter devices, each staff member has a four-digit PIN set on their record in People & Access. They pick their name on "Who's on the counter?" and enter it; five wrong tries locks that PIN for five minutes.

A PIN identifies who is acting on an already-signed-in device. It is not a password and grants nothing the person's role does not already allow. See POS register.

Inviting staff

  1. Go to staff management in organization or branch workspace
  2. Enter email or phone for the invitee
  3. Assign role and branch scope (if multi-outlet)
  4. Send invite
  5. Confirm the person received it and signed in

Safety habits

  • verify identity before inviting (wrong email = wrong access)
  • remove stale invites that were never accepted
  • disable or remove users on their last day
  • never share one login across multiple people

A team on the Basic plan

Basic has three logins — the owner and two more — and no Staff module, so there is no clock-in, staff shift or scheduling. Here is how a small counter team runs on it:

  • Inviting. The owner (or an admin) invites from People & Access: Location Settings → People & Access, or Workspace Settings → People & Access. Give a cashier or cook the Staff role and a manager the Manager role. Pending invitations count towards the three logins.
  • Signing in. Each person accepts the email invitation and signs in with their own account. On a shared phone or tablet running the Zesty app they can instead tap Switch under More, pick their name, and enter their counter PIN, which they set from their own account settings. If a PIN gets locked, the owner uses Clear counter PIN on that person in People & Access and they set a new one.
  • The day. The owner or a manager opens the Location shift on the Shift desk, and the cash count and close checks work as on every plan. Nobody clocks in: while the Location shift is open, anyone signed in can take orders, bill, and work the kitchen display. To let a Staff login open and close the day, switch on Staff may open and close the day in the Shift desk settings, or make that person the temporary shift lead.
  • Sales. The owner and managers see today's, yesterday's and the last seven days' sales on the dashboard. Staff logins do not.

Silver adds the Staff module: per-person clock-in, staff shifts and scheduling, fifteen logins, and the Staff screen.

Feature catalog saves (owners)

Owners and admins change which modules are on from Settings → Features.

Important rules:

  • save replaces the entire feature snapshot—review the full list before confirming
  • requires password or one-time email code (passwordless accounts)
  • plan-locked features need upgrade after trial

Staff permissions cannot enable a module the catalog turned off.

Operational shift authority

Some actions depend on who opened the shift and manager permissions:

  • opening and closing branch shift
  • bypassing shift gate (admins, emergencies only)
  • staff shift models (per-member shifts)

Train shift leads before go-live: Operational shift

Location scope

Multi-outlet staff may be limited to one Location or several. Location scope affects:

  • which orders and inventory they see
  • which reports export
  • which QR tables they manage

Wrong branch scope is a common cause of "I cannot see today's sales."

Access logs

Access logs record important actions across organization and branch context. Use them for:

  • quarterly permission audits
  • investigating unusual refunds or menu price changes
  • support tickets ("who changed this setting?")

Logs complement—not replace—your internal HR and cash-control policies.

Support access

Eligible admins can allow support access when opening or managing a support ticket.

Rules:

  • allow only for the ticket being worked
  • state a clear reason
  • review and revoke after resolution

Support access is audited like other sensitive access.

WhenAction
New hireInvite with minimal permissions
PromotionExpand permissions deliberately
Role changeRemove old permissions that no longer apply
DepartureRemove same day
Plan changeRe-read feature catalog vs role needs
New branchConfirm branch managers scoped correctly

Common questions

Staff sees module owner does not expect
Check role, individual permission override, feature catalog, and branch.

Cannot refund
Refund permission is often manager-only.

Former staff still in list
Remove or disable account; do not leave dormant logins on shared tablets.