Staff accounts

Help centre · Setting up your shop

Who can sign in to your shop's admin, and what each of them can do. You are the owner — that account always has full access and can't be locked out.

Adding someone

The add-a-staff-member form with name, email, password, role, till PIN and active
FieldWhat to put in it
NameTheir name — it's what appears against the till sessions and stock moves they make, so use something you'll recognise on a report.
EmailWhat they sign in with. Must be their own; two people sharing a login makes every audit trail useless.
PasswordAt least 10 characters. Set one now and have them change it.
RoleThe bundle of permissions they get — see Roles. Start with the closest fit; you can adjust with overrides below.
Till PINOptional, and worth setting for anyone who serves. It's the short code they punch in at the till to identify themselves on a sale, rather than typing an email and password at a busy counter.
ActiveUntick to suspend someone without deleting them — a seasonal helper, someone on leave. Their history stays intact and they simply can't sign in.

Permission overrides

Open Permission overrides to add or remove one permission on top of whatever the role gives. That's for the exception — "Cashier, but this one can also do refunds" — not for building a role a person at a time. If you find yourself giving three people the same overrides, make a role instead.

Managing existing staff

The staff list with each person as an expandable row

Each person is a row you expand. Inside you can change their name, email, role, till PIN and active flag, adjust overrides, reset their password, or remove them.

  • You can't remove your own account — that's the guard against locking yourself out.
  • Only the owner can hand out the owner role.
  • Prefer unticking Active to removing. Someone who leaves and comes back keeps their history, and their past till sessions stay attributed either way.

When a change actually bites

Two of these behave differently from each other, and the difference matters on the day somebody leaves:

What you changeWhat happens to them right now
Their role, or an overrideImmediately. They don't have to sign out and back in — the next screen they open is judged by the new role. Move someone from Content editor to Cashier and the page editor is refused on their very next click, while the orders list opens.
Their passwordNot immediately. The old password is dead at the login screen, but a session they already have open stays open. Resetting a password is how you stop somebody signing in again; it is not how you throw them out of a session they are sitting in.
Untick Active, or RemoveStops them signing in from then on. If you need somebody out of the building and out of the admin in the same minute, do this and make sure they are actually signed out.

Did that not answer it?

Raise a ticket
🍪