Staff

Adding your team, the two credentials each of them gets, and why they are not the same thing.

Restaurant → Staff

Who works here, their role and their PIN status.

The staff list
The staff list. Click to enlarge.

The five roles

RoleDoes
ManagerNearly everything you do, except the money screens. Authorises voids and large discounts at the till.
Kitchen staffWorks the kitchen display.
Waiter / cashierTakes orders and payments at the till.
Host / hostessWorks reservations and the floor plan.
DriverDelivers — see The driver app.

Only the owner can create or remove a manager. A manager cannot appoint another manager, and cannot remove one. That is the boundary that stops the second-most-powerful account being able to multiply itself.

Adding somebody

FieldRules
First and last nameRequired, 60 characters each at most.
EmailRequired, and unique across the platform. Their invitation goes here.
RoleOne of the five.
PhoneOptional.
Profile photoOptional, from your media library.
4-digit PINRequired for a new member. Exactly four digits.
ActiveOff suspends them without deleting their history.

The two credentials, and the difference

Every staff member has two, they do different jobs, and confusing them causes most of the support questions on this screen:

CredentialUsed forSet by
PasswordSigning in to the dashboard as themselves, on their own device.Them, from the invitation email.
4-digit PINUnlocking a shared screen already signed in, and authorising a void or a large discount at the till.You, here.

They are stored independently — changing one never changes the other. Leave the PIN field blank when editing and the existing PIN is kept.

A PIN is a counter credential, not a login. It is short because it is typed at a till in front of a queue. It cannot get anybody into the dashboard from outside, which is exactly why it is allowed to be four digits.

What happens when you add somebody

They receive an invitation carrying their role, their PIN, a link to set their own password, and where to sign in. Their password is theirs — you never see it and never set it.

If an invitation is lost, changing their email address reissues it. An old invitation stops working when the address changes, so a stale link cannot be used later.

Suspending and removing

ActionEffect
Set inactiveThey cannot sign in. Their history, orders and activity stay intact. Reversible.
RemoveThe account goes, and any outstanding invitation or reset link is destroyed with it.

Set inactive when somebody leaves. It is what you want in nearly every case: their past work stays attributable, and the staff reports for last month still make sense.

Everything is logged

Role changes, status changes and PIN resets are all written to the audit record with what changed. On a screen that grants access to money, that history is worth having.

When it doesn't work

"That email is already in use"

The address belongs to another account — often the person's own customer account. Use a different address.

They never received the invitation

Mail on your platform is not being delivered. Ask your operator to check Email & templates — the message is queued either way.

"Only the restaurant owner can create or edit a manager"

You are signed in as a manager. Managers cannot appoint managers.

Their PIN does not work at the till

Wrong PIN, or too many attempts — repeated failures back off with a wait. See PIN lock.

They cannot see a screen they should

Their role, or a feature switched off entirely — see What each role can do.