A cashier needs to refund a damaged item during a busy afternoon. The manager is on a delivery call. If the only choices are “give everyone full access” or “stop every return until the owner arrives,” the store has a permissions problem, not just a training problem. A better POS buying process tests which actions staff can perform, when approval is required, and what record remains afterward.

Staff permissions should make ordinary work possible while placing clear boundaries around refunds, discounts, cash handling, customer information, and configuration changes. More settings are not automatically better. The useful system is the one your team can operate without shared credentials, vague exceptions, or unnecessary manager interruptions.

Scope: This 2026 buying guide compares access-control approaches and uses current Shopify documentation as a product-specific example. Sources were reviewed September 22, 2026. It is not a fraud-prevention guarantee or a certification assessment. POSadvice.com helps you compare POS systems; it is not a POS vendor.

Compare permission models before comparing plans

POS staff-control approaches and their operational tradeoffs
ModelHow it worksPotential advantageBuying question
Broad preset rolesStaff receive a small set of predefined access levelsFast setup for straightforward operationsDoes each role grant unrelated powers merely to enable one necessary task?
Custom rolesThe business groups selected permissions into reusable job rolesCloser fit to cashier, supervisor, inventory, and administrative dutiesWhich plan and locations support the custom rules?
Custom roles with approval gatesSelected actions require approval from an authorized colleagueAllows controlled exceptions without granting permanent accessWho can approve, how is approval recorded, and what happens when nobody is available?

These models may coexist within one product. The comparison is about the control you need, not a claim that every POS implements each option. Ask providers to demonstrate the same staff scenarios so a feature-rich description does not substitute for observed behavior.

Build a permission matrix from real jobs

List the work each role performs in a normal week. A cashier may need sales, customer lookup, and receipt reprints. A supervisor may also handle disputed returns and selected discounts. A stockroom employee may receive deliveries without needing refund authority. An accountant may need exports without changing the product catalog.

For each action, choose one of three intended outcomes: allowed, denied, or approval required. This is your requirement, not an assumption about the software. If the provider cannot separate two permissions, ask whether changing the workflow is acceptable or whether that limitation rules out the system.

Include less obvious actions: creating custom-priced sales, changing taxes, issuing store credit, opening the cash drawer outside a sale, changing sales attribution, adjusting stock, exporting customer records, and editing roles. A cashier who cannot issue a refund might still be able to make an economically similar adjustment elsewhere.

Do not build roles around individual personalities. Use reusable job definitions and document approved exceptions. When someone changes duties, you should be able to update their role without reconstructing a long list of one-off settings.

Check subscription and location boundaries

Shopify’s Point of Sale permissions documentation states that POS roles are available only at locations on the POS Pro subscription. That makes plan coverage a purchasing requirement, not a footnote. Ask for the proposed subscription at every location where you expect a role to apply.

The same documentation separates many actions, including returns and exchanges, ineligible returns, unverified returns, custom discounts, customer details, and store-credit management. Those distinctions can matter more than a generic “manager permissions” checkbox. Have the supplier map your matrix to the available controls.

When comparing any multi-location system, test an employee at each type of location you operate. Do not assume identical restrictions across different plans, devices, applications, or online administrative interfaces. Ask what happens when a location changes subscription and whether existing roles continue to behave as intended.

Price the full deployment. A quote for advanced controls at one flagship store does not establish the cost or behavior across five stores. Request a list of subscriptions, staff limits if any, and optional modules that affect your required permissions.

Separate register access from administration

The ability to operate a register should not automatically imply permission to edit the store’s configuration. Review the POS application, browser-based administration, connected inventory tools, reporting tools, and third-party apps separately. Restricting one screen does not prove that an equivalent action is restricted everywhere.

Shopify’s roles documentation describes roles as groups of granular permissions associated with a job. Use that structure to ask a concrete question: which assigned role grants each person access to the task you are reviewing? Have the demonstrator show the user’s effective permissions, not just the role name.

Protect role editing itself. An employee who can grant themselves more access can undermine a carefully designed cashier role. Keep responsibility for assigning roles clear, and retain a way for the owner to recover legitimate administration without sharing an everyday staff login.

Use individual identities where the product supports them, with the vendor’s supported login and account-protection options. Individual access makes records more useful only if staff actually switch users and avoid sharing PINs. Include that behavior in onboarding and shift-change practice.

Design approvals around the shift, not just the owner

An approval requirement works only if an authorized person is available. Identify a backup for each shift, define which exceptions they can approve, and decide how staff handle a request when no approver is present. A written customer-service fallback is better than an unofficial shared manager PIN.

Shopify documents that an approver needs both manager-approval permission and the permission for the underlying action set to allowed. A managerial job title alone is not enough. During a demo, test both a properly authorized approver and a supervisor who lacks the underlying permission.

Approval granularity varies. Ask whether restrictions are simple allow-or-deny choices, whether particular actions can require approval, and whether the system supports any amount or percentage thresholds you need. Do not infer dollar-based refund limits merely because manager approval exists.

Also test what happens after the manager approves. Does access return to the cashier’s normal limits, or is a broader session left active? Can the employee repeat or change the action without another approval? The answer should come from the proposed product’s actual behavior.

Eight demo scenarios that reveal meaningful differences

  1. Routine return: Start from a valid receipt and show the cashier’s allowed workflow.
  2. Exception return: Try an out-of-policy or unverified return and observe the approval requirement.
  3. Discount change: Apply a custom discount, then distinguish it from an authorized promotion code.
  4. Cash action: Open the drawer outside a sale and attempt a cash adjustment using the cashier role.
  5. Customer information: Look up a customer, then attempt to view or export information beyond the role’s need.
  6. Location change: Use the same staff identity in another location with the quoted plan configuration.
  7. Role change: Remove a permission while the employee is already signed in and check when the change takes effect.
  8. Audit review: Find the attempted and completed actions, their staff attribution, and approval details where recorded.

Use test accounts and demonstration transactions agreed with the vendor. Record what is supported, unsupported, or still unverified. Do not treat an undocumented behavior as an acceptance criterion the supplier has already agreed to meet.

Pros and cons of tighter controls

Preset roles

Pros: Quick to understand and easier to administer when the business has few distinct jobs. Cons: The available bundles may be too broad or too restrictive. A store can end up promoting staff to a powerful role just to unlock one routine task.

Custom roles

Pros: Duties can be separated more deliberately, and one role change can apply consistently to a group. Cons: Someone must maintain the design as the store changes. Poorly named roles and undocumented exceptions can make the setup hard to review.

Approval-based exceptions

Pros: Staff can request specific actions without receiving permanent unrestricted access. Cons: Excessive approval prompts can slow service and encourage workarounds. Track which legitimate requests repeatedly need approval and adjust the policy deliberately, rather than letting the workaround become standard practice.

Buy useful records, not just more restrictions

A control decides whether an action can occur. A log helps explain what occurred. Ask which events are recorded, whether attempts and approvals appear, how long records remain accessible, and whether they can be exported. An entry that says “refund” without a transaction reference may not answer the question you need to investigate.

Shopify’s permissions documentation directs merchants to its POS activity log for attribution of high-risk register actions. Treat that as a starting point for review, not evidence that every possible field or event you want is present. Have the demonstrator retrieve the actions from your test and show the actual detail.

Review exceptions in context. A high refund count may reflect legitimate customer-service duties rather than misconduct. Compare the underlying transactions, reasons, and approvals before drawing conclusions. The purpose of a useful record is to support a fair investigation and better operating decisions.

Pair access controls with a clear retail POS returns process. Permissions cannot resolve an unclear return policy, and a clear policy is difficult to apply consistently if the software gives staff the wrong tools.

Include training, coverage, and lifecycle costs

Request line items for the required software tier, every covered location, staff-management add-ons, setup, training, and support. Ask who will configure the initial permission matrix and who verifies it after migration. A paid feature is not a finished control until it has been configured and checked.

For illustration, an incremental $70 monthly subscription at three locations adds $2,520 per year before onboarding, tax, and staff time. That is not a vendor price or a prediction of savings. Compare the cost against your actual needs, including how often supervisors must interrupt other work to approve ordinary requests.

Set a joiner, role-change, and departure process. Test deactivation on an already signed-in register, not just on the employee list. Ask how cached or offline access behaves and how restrictions resume after reconnection. The offline POS buying guide helps frame those continuity questions without assuming offline transactions behave like online ones.

Before signing, require a completed permission matrix, a demonstrated approval path for each shift, and readable records from the test scenarios. Compare proposals on those outcomes. The lowest-priced plan is not a bargain if your required controls exist only in a different subscription.

Frequently asked questions

What is the difference between a POS role and a permission?

A permission controls access to an action or area. A role groups permissions around a job, such as cashier or supervisor, so the same access definition can be assigned to multiple people.

Does Shopify offer POS roles on every location plan?

The cited Shopify documentation states that POS roles are available only at locations on the POS Pro subscription. Confirm the exact plan and behavior at every location in your proposed deployment.

Does manager approval automatically include dollar limits?

No. Approval requirements and amount-based limits are different capabilities. Ask the provider to demonstrate any refund or discount threshold you need instead of assuming it is included.

What should happen when an employee leaves?

Follow a documented access-removal process and verify its effect on signed-in devices and connected applications. Ask the vendor how deactivation behaves during offline operation and after reconnection.

Ready to find your perfect POS system?

Answer 3 quick questions and get free quotes from top providers.

Get Free Quotes →

Leave a Reply

Your email address will not be published. Required fields are marked *