Built-in roles
There is no separate Administrator role. Managers get broad access automatically, but certain sensitive permissions (payroll, tips, billing, settings, LAN) must still be granted explicitly — even for managers.
How permissions work
DishInk uses a two-track permission system: Track 1 — Role bypass. Managers automatically pass permission checks for most features without needing individual toggles. Owners always pass every check unconditionally. Track 2 — Explicit only. A set of sensitive permissions are never auto-granted by role. They must be turned on individually per staff member, even for managers. These are:can_edit_contact,can_edit_hours,can_edit_social,can_edit_featurescan_manage_settings,can_manage_terminals,can_view_settingscan_manage_payroll,can_manage_tipscan_delete_staffcan_view_all_reportscan_view_all_tablescan_view_lan_conflictscan_view_billing,can_manage_billingcan_switch_locationsand all cross-location sub-permissions
Permission categories
Permissions are grouped into the following categories in the role editor:Growth Pro views
Controls which Back Operations modules a staff member can open.Sales reports
Every staff member with POS access can generate and print their own shift report — no toggle needed. Enablingcan_view_all_reports upgrades this to the full manager-style report: all staff numbers, staff picker, summary/detailed toggle, and CSV exports. Explicit only — manager role is not enough.
Admin page access
Controls which Front Operations pages a staff member can visit: Dashboard, Menu, Gallery, Messages, QR Codes, Orders, Website Content.Admin page editing
Controls which Front Operations pages a staff member can make changes on: Menu, Gallery, Content, QR Codes, Messages, Inventory, Orders.Management controls
can_manage_staff— add and edit staff memberscan_delete_staff— permanently remove staff (explicit only)can_edit_shifts— modify shift records
Analytics access
Requirescan_view_analytics to be enabled first. Managers get all four automatically. Other roles need individual grants:
can_view_analytics_kitchencan_view_analytics_revenuecan_view_analytics_menucan_view_analytics_staff
Transaction overrides
can_process_payments— process and finalise paymentscan_apply_discounts— apply discounts on orderscan_void_orders— void active orders
HR — Payroll & Tips
Explicit only. Manager role is not enough.can_manage_payroll— approve payroll records, mark wages as paid, run payroll calculationscan_manage_tips— distribute tips, change tip distribution mode and settings, mark tips as paid
Settings access
All explicit only, even for managers.can_view_settings— open the settings panelcan_manage_settings— change general settingscan_edit_contact,can_edit_hours,can_edit_social,can_edit_features— granular website settingscan_manage_terminals— add and configure POS terminals
LAN & Network
Explicit only. Controls access to the LAN Monitor page, connected devices, offline sync queue, and conflict log. Owners always have this access.can_view_lan_conflicts
Multi-location access
Explicit only. Growth Pro required. Staff are locked to their home location unlesscan_switch_locations is enabled. Sub-permissions only apply after switching:
can_switch_locations— master switchcan_manage_cross_location_menu— edit menu and price overrides at switched locationcan_manage_cross_location_inventory— manage stock at switched locationcan_view_cross_location_analytics— view analytics at switched location
Billing access
Explicit only. Manager role is not enough. Controls access to the subscription and billing panel in Back Ops Settings.can_view_billing— view current plan, billing dates, usage stats, request historycan_manage_billing— submit upgrade, downgrade, cancel, and payment method change requests
can_manage_billing automatically grants can_view_billing as well — you only need to enable one.Creating and editing role templates
Go to Staff Management → Roles to manage role templates. Select an existing role to edit its permissions, or click Create New Role to start from scratch. Role templates can be assigned to staff members when creating or editing their account. The template sets the defaults — individual permissions can still be adjusted per staff member after assignment.Only owners and staff with
can_manage_staff can create or edit role templates.
