Cashiers should be able to ring sales and accept tenders, but they generally should not be able to void a completed sale, issue a refund, or apply a discount without a manager's approval — those three actions are the most common paths for internal shrinkage and belong to shift leads and above. The right setup gives every role exactly the permissions its job needs, scopes access to the locations someone actually works, and logs every sensitive action with a name and timestamp attached.
What Are POS Roles and Permissions, Exactly?
POS permissions are the individual settings that control which actions a staff member can perform at the register — such as voiding a sale, issuing a refund, applying a discount, overriding a price, or opening and closing a drawer — and a role is simply a named bundle of those permissions assigned to a person. Instead of deciding case by case whether an employee can do something, you assign them a role, and the role decides for you.
Most stores don't need a custom permission scheme for every employee. They need four or five clear tiers, applied consistently, so a new hire's access is obvious on day one and a departing employee's access disappears cleanly. The mistake we see most often isn't too little structure — it's every register logged in as "Manager" because it was easier to set up that way. That erases the entire point of having roles.
Who Should Be Able to Void a Sale?
A void cancels a transaction before it's finalized, and it's one of the two or three actions most closely tied to internal theft — a cashier can ring a sale, hand over the merchandise, then void the transaction so it never appears in the day's totals. That's why void permission should stop at the cashier level.
- Cashier: can start and complete a sale; cannot void a completed transaction.
- Shift lead / key holder: can void a sale during their own shift, typically with a reason code required.
- Store manager: can void any sale at their location, at any time, without restriction.
- Owner / admin: can void across every location and see every void in reporting.
If your current setup lets every cashier void freely, start there. It's the single highest-leverage permission change most stores can make, and it costs nothing to implement — it's a setting, not a purchase.
Who Should Be Able to Issue a Refund?
Refunds return money to a customer, which makes them a favorite target for fraud — a fake return, a refund to the wrong tender, or a refund with no matching original sale. The safest pattern ties refund permission to management, and ties the refund itself to the original transaction wherever possible.
- Cashier: can look up a past sale but cannot complete the refund.
- Shift lead: can process a refund against a receipt on file, up to a set dollar amount.
- Store manager: can process any refund, including no-receipt returns and exchanges, and can issue store credit or gift card refunds.
- Owner / admin: can review refund activity across every location and adjust the shift lead's dollar limit.
For a full walkthrough of what should show up on the daily report — including refund totals against sales — see how to close out a cash register at end of day.
Who Should Be Able to Apply a Discount or Price Override?
Discounts and price overrides are different actions with the same risk: an employee sells merchandise below its real price, sometimes to a friend, sometimes to themselves through a second party. The fix isn't banning discounts — it's tiering how much discount authority each role holds.
- Cashier: can apply a published promotion or loyalty reward automatically; cannot type in a manual discount.
- Shift lead: can apply a manual discount up to a set percentage (many stores use 10-15%) without approval.
- Store manager: can apply any discount or price override, and can approve a shift lead's discount above their limit.
- Owner / admin: sets the discount ceilings for every other role and can see every manual discount in the audit log.
This is also where customer price tiers matter. A wholesale or contract customer shouldn't need a manual discount typed in at all — their price should already be correct at the register based on who they are. That removes an entire category of manual discount from the equation. We cover the buyer side of this in how to sell wholesale online and show buyers their own prices.
What About Staff Who Only Need to Check Prices or Do Repairs?
Not every employee fits neatly into cashier, lead, or manager. A part-timer who only helps with intake for repairs, a stockroom hire who only receives purchase orders, or a floor associate who only needs to look up stock and price for a customer doesn't need register access at all — and giving it to them anyway is how permission sprawl happens.
- Build a task role scoped to exactly what the job requires: inventory lookup and item detail, but no sell screen, no drawer access, no discount authority.
- For repair or serial-tracked items (jewelry, electronics), scope the role to intake and status updates only — not pricing or payments.
- For receiving-only stockroom staff, scope the role to purchase orders and transfers, without checkout access.
- Review task roles the same way you review cashier and manager roles — quarterly, not once at hiring.
A narrow, purpose-built role is safer than a broad role with a mental note not to use most of it. People forget mental notes; permission settings don't.
Should Permissions Change Across Locations?
Yes, and this is where a lot of multi-location stores get exposed. An employee who works the flagship store shouldn't automatically have access to a second location's register, inventory, or reports just because they're in the same system. Access should be scoped to the locations a person actually works, with a smaller group — usually owners and a regional manager — given visibility across all locations.
This matters just as much for reporting lines as it does for register access. A shift lead at Store B shouldn't see Store A's margins, payroll-adjacent time clock data, or customer list unless their role explicitly includes it. For the broader case on why one shared count and scoped access beats running separate spreadsheets per site, see multi-location retail management.
How Do You Know Who Did What?
Roles decide what someone can do. An audit trail tells you what they actually did. Without one, a permission structure is just a policy — it's unenforced until something goes wrong and you have no record to check. A usable audit trail should answer three questions for any void, refund, or discount: who did it, when, and at which register or location.
- Every sensitive action (void, refund, discount, price override, drawer open/close) should be attributed to the logged-in user, not the register.
- The log should be filterable by date range and by action type, so a manager can review a week's discounts in minutes, not by scrolling receipts.
- Cash drawer closes should show counted cash against what the drawer was expected to hold, with a note explaining any difference — not a blind guess.
How Retailer OS Handles Roles, Permissions, and the Audit Trail
Retailer OS ships built-in roles — owner, admin, manager, cashier, and viewer — and lets you build custom roles for anything that doesn't fit, like a repair-intake or receiving-only position. Discounts, price overrides, voids, refunds, returns, and opening or closing a register are each separate permissions, not bundled together, so you can hand a shift lead void authority without also handing them refund authority. Some stores start from presets like Shift Lead or General Manager and adjust from there rather than building every role from scratch.
Access is scoped by location: each user can be limited to the stores they actually work, while selected people (usually owners) get all-locations visibility, and reporting lines are set in Setup → Team so it's clear who a store manager reports to. Every register runs from the same catalog, so a customer's price tier, active promotions, and loyalty rewards apply automatically at checkout — cutting down how often a manual discount is even needed. Retailer OS also keeps an audit log of changes, filterable by date range, so you can see who voided a sale, who applied a discount, or who changed a price, and when. For sign-in security, users can turn on two-factor authentication with an authenticator app. In-store card payments run through the merchant's own Stripe Terminal hardware, reconciling against the same register activity the audit log tracks.
None of this requires a separate purchase — roles, permissions, location scoping, and the audit log are part of running Retailer OS at $99.99/month per store plus $9.99/month per user seat. See the full breakdown on pricing, or read more on what a well-run register should support in what a modern POS should do for independent retailers.
Start with four roles — cashier, shift lead, manager, owner — set their void, refund, and discount limits, and run the audit log for one week. It will show you exactly where your current setup is too loose. See how role-based access and the audit trail work in store consistency or retail workforce operations.
Last updated September 15, 2026