Skip to main content

Manage employee access and approvals

Give each employee an individual account and the smallest role that supports their work. Location assignment and permissions determine which counters, records, and approval actions a person can use.

Before you begin

  • Sign in as an Owner, or as a Manager with employee-management permission.
  • Create the locations or sub-accounts the employee needs.
  • Decide whether the employee sells, supervises shifts, manages inventory, approves exceptions, or administers the workspace.

Role model

RoleTypical workImportant boundary
CashierSell, take payment, view own shiftDoes not receive broad management access by default
ManagerSupervise permitted locations, operational exceptions, and reportsAccess still depends on assigned locations and permissions
OwnerConfigure and administer the tenantReserve for people accountable for workspace-wide changes

The current role and capability matrix is the detailed reference. Check it before telling an employee they can complete a task.

Add an employee

  1. Open Employees and choose Add employee.
  2. Enter the employee’s own identity and select the intended role.
  3. Assign only the locations where they work.
  4. Configure the sign-in method offered by the surface. Do not reuse another employee’s PIN or password.
  5. Save, then have the employee sign in on the intended device and confirm the resolved counter.

Review permissions

Open Permissions on web to inspect the capabilities attached to roles or policies. Treat permission changes as operational changes:

  • state why the access is needed;
  • apply it to the narrowest role or employee set;
  • test with a non-production action;
  • review the audit history;
  • schedule removal when the access is temporary.

Handle approval queues

Approvals can be raised by configured discount thresholds, shift variance policy, customer duplicate merges, or other guarded operations. The exact queue depends on enabled features and permissions.

sequenceDiagram
participant Staff
participant Nox as Nox Billings
participant Approver
Staff->>Nox: Submit guarded action
Nox-->>Staff: Record pending state
Nox-->>Approver: Show approval work
Approver->>Nox: Review context and approve or reject
Nox-->>Staff: Record final status and audit event

For every approval:

  1. Open the underlying invoice, shift, customer, or operation.
  2. Compare the request with the business rule; do not approve from the queue title alone.
  3. Approve or reject once. Include a reason whenever the interface requires or the decision needs context.
  4. Confirm the final state and related audit record.

Remove or change access

When an employee changes role or leaves, deactivate or update the individual account promptly. Do not delete evidence needed for historical invoices, shifts, or approvals. Confirm that active sessions and location access no longer exceed the employee’s current duties.

Expected result

The employee sees only assigned work, approval decisions are attributable to an individual, and management changes remain reviewable in audit history.

Recovery

  • Wrong counter after sign-in: switch to an allowed sub-account or correct the employee’s location assignment.
  • Action is hidden: check both role permission and current location; do not work around the control with a shared Owner account.
  • Approval is stale: reopen the underlying record before deciding, then refresh the queue.
  • Employee cannot sign in: confirm the account is active and use the supported credential reset flow.