Skip to content
Retail Operations

Preventing Employee Theft at the Register: Controls That Don't Insult Your Staff

Retailer OSSeptember 18, 20269 min read
Preventing Employee Theft at the Register: Controls That Don't Insult Your Staff

Preventing employee theft at the register comes down to five controls: restrict who can void, refund, discount, or override a price; require a manager approval for the exceptions; keep an audit log of every change; watch for the patterns that flag trouble early; and reconcile cash against what the drawer should hold, not just what's in it. None of this requires treating your team like suspects — it just means the register enforces the same rules for everyone, including the owner.

What Actually Counts as Register Theft?

Register theft is inventory or cash loss caused by the person operating the point of sale, not by a customer or an outside party. It's rarely a cashier grabbing bills from the drawer — that's the easiest kind to catch. Most register theft moves through the transaction itself, where it looks like normal work until you check the pattern.

  • Sweethearting — ringing up a friend or family member for less than they owe, or skipping items entirely
  • Refund fraud — processing a fake return and pocketing the cash or store credit
  • Discount abuse — applying an employee or loyalty discount to a stranger's purchase
  • Voided sales after the customer leaves — ringing the real sale, voiding it once the customer is gone, and keeping the cash
  • Under-ringing — entering a lower quantity or a cheaper item code than what was actually sold
  • Till skimming — pocketing cash from a sale that was never entered into the register at all

Why Do Void, Refund, and Discount Permissions Matter Most?

Every method above depends on one thing: a cashier having the power to change a transaction after the fact without anyone else looking at it. That's why the highest-leverage control isn't a camera or a policy memo — it's simply not giving every cashier the ability to void a completed sale, issue a refund, or apply a discount on their own. We covered the mechanics of this in detail in POS user roles and permissions, but the short version for loss prevention is this: separate the permission to *sell* from the permission to *undo a sale*.

  • Void a completed sale — reserved for shift leads and above, not open cashiers
  • Process a refund or exchange — requires a manager role, especially for cash refunds
  • Apply a discount beyond a set limit — a cashier can apply a small posted discount; anything larger needs approval
  • Override a price at the register — logged and limited to specific roles
  • Open or close a register — tracked separately, since this is where cash variances start

This isn't about distrust — it's the same reason a bank teller can't approve their own loan. Separating who rings the sale from who can reverse it removes the opportunity, which removes most of the temptation.

How Should Manager Overrides Work Without Slowing Down the Line?

The fastest way to make loss-prevention controls fail is to make them annoying. If a manager override takes five minutes to track down, cashiers will find workarounds, and honest employees will resent the friction more than the thieves do. The fix isn't fewer controls — it's faster ones. A manager override should be a single approval step at the register (a PIN, a badge tap, or a manager login) that takes seconds, not a walk to the back office. The point isn't to interrogate every discount; it's to make sure a second person's judgment — and name — is attached to every exception before it happens, not after.

What Should an Audit Log Actually Show You?

Permissions stop most theft before it happens. An audit log catches what gets through, and it's what turns a suspicion into a conversation backed by facts instead of a guess. A useful audit log needs three things: what changed, who changed it, and when. Without all three, you're back to asking the whole team who did it.

  • A record of every price override, discount, void, and refund tied to the employee who performed it
  • A timestamp precise enough to match against the shift schedule and the security footage
  • The ability to filter by date range, employee, or register so a manager can spot a pattern instead of scrolling a full transaction history

The value of an audit log isn't catching one bad actor. It's that everyone knows the log exists, which is often enough on its own to stop the behavior before it starts.

What Loss-Prevention Alerts Catch Theft Early?

Most register theft isn't a single big incident — it's a small pattern repeated over weeks. The employees involved usually aren't your worst performers on paper; they're often high-volume cashiers whose numbers look fine at a glance. The patterns worth watching for: an unusual rate of voids or refunds tied to one register or one employee, discounts clustered around a specific shift, and drawer variances that keep landing on the same person's closes. None of these prove theft by themselves. They tell you where to look first, which is the entire point of an alert — it turns a monthly report nobody reads into something a manager sees the next morning.

How Does Cash Reconciliation Close the Loop?

Permissions and audit logs control the transaction. Cash reconciliation controls what's left in the drawer at the end of the shift, and it's the step most stores get wrong by making it a blind count. If a cashier counts the drawer without knowing what it's supposed to hold, a shortfall just looks like a counting mistake — theirs or the system's. Show the expected amount (starting float plus cash sales minus cash refunds, drops, and payouts) before the count, then have the employee count and enter the actual total. The system records the variance automatically, with a note for anything off. We go through the full close-out process, including over/short thresholds worth acting on, in how to close out a cash register and cash handling procedures for retail stores.

A reasonable starting policy: any variance over a small fixed dollar amount, or a percentage of the day's cash sales, gets a manager follow-up before the next shift starts. A single small variance is a counting error. The same employee posting variances on a recurring schedule is a pattern.

How Do You Roll This Out Without Insulting Honest Staff?

The framing matters as much as the controls. Tell your team the truth: these limits protect them as much as the business. A cashier who can't independently void a sale also can't be wrongly blamed for one they didn't touch. A manager who has to approve every large discount is also on record when a customer complains about a price. Roll it out as a standard applied evenly — owner included — not as a response to a specific person. And keep the controls proportional: a $5 loyalty discount doesn't need the same approval as a $200 refund. Over-controlling the small stuff is what actually feels insulting; controlling the exceptions that matter doesn't.

How Retailer OS Handles Register Controls

Retailer OS builds these controls into the register itself rather than leaving them as a policy staff have to remember. Voids, refunds, discounts, price overrides, and opening or closing a register are each separate permissions, assigned through built-in roles (owner, admin, manager, cashier, viewer) or a custom role built for your store, with access scoped to specific locations for multi-location teams. See how the roles fit together in store consistency and retail operations management.

  • Cash management with expected-vs-counted: the close screen shows what the drawer should hold before the employee counts, and records the variance with a note — counts aren't blind
  • A register that closes with a difference surfaces in notifications, so a manager sees it the next morning instead of finding it in a monthly report
  • An audit log records permission-gated changes with who made them and when, filterable by date range
  • Role-based permissions separate who can ring a sale from who can void, refund, discount, or override a price, with location-scoped access for multi-location teams
  • Card reconciliation matches register card payments against the store's own Stripe charges, so card-side variances surface alongside cash ones
  • Two-factor sign-in with an authenticator app adds a second check on who's actually logged into a manager account
  • Dashboards, saved views, and scheduled email digests so shrink-relevant numbers reach an owner without a manual pull — see retail analytics

Because point of sale and inventory run on one system, a variance at the register and a variance in stock on hand show up in the same place, which makes it faster to tell an inventory-shrink problem from a cash-handling one. For the inventory side of shrink — cycle counts, variance thresholds, and what to do when stock and sales don't match — see reducing inventory shrinkage.

Loss prevention works best when it's built into the register, not bolted on as a separate policy. See how Retailer OS handles roles, permissions, and the audit log, or check pricing — plans start at $99.99/month per store plus $9.99/month per user seat.

#loss prevention#cash handling#POS permissions#retail operations

Last updated September 18, 2026

Run every store from one system.

Point of sale, inventory, and your team in one place. Start a 14-day free trial with no card required, or book a walkthrough with our team.