## 🛡️ Manage Employee Roles and Permissions

Create custom roles and control which screens and POS actions each staff role can use.

### 📝 Steps
1. In the left sidebar, tap **MANAGEMENT**, then open the **System Setup** tab. Under **Basic Setup**, tap **Role Management**. You need **Setup Page** access — a **Cashier** cannot open this screen.
2. Review the list: **Role Name**, **Type** (**System** or **Custom**), **Permissions** (how many are granted), and **Action**. Built-in roles **Cashier**, **Manager**, and **Admin** are marked **System**.
3. Tap **Add New Role**. Enter a unique **Role Name**. A duplicate name is rejected with **A role with this name already exists**.
4. Grant access in the four groups (each is a multi-select; placeholder **Select permissions**):
   - **Route Permissions** — **POS**, **CRM**, **Management**, **Settings**, **Reporting**, **Analytics**, **Booking**.
   - **Function Permissions** — **Switch Table**, **Last Bill**, **Print Last Kitchen Slip**, **Print Last Order Docket**, **Print Full Order Docket**, **Note**, **Delete Bill**, **Percent Discount**, **Flat Discount**, **QR Code**, **Pay In**, **Pay Out**, **Open Drawer**, **Void**, **Void and Duplicate**, **Receipt**, **Reprint**, **Add Customer**, **Change Payment**, **Check**, **Pay at Counter**, **Merge Table**, **Add Salesperson**, **Stock Adjust**, **Stock History**, **CRM Add Customer**, **CRM Edit Customer**, **CRM Delete Customer**.
   - **Item Editor Permissions** — **Table Editor**, **Flat Discount**, **Percent Discount**, **Delete**, **Note**, **Duplicate**, **Takeaway**, **Transfer**, **Sales Person**, **Change Price**.
   - **Page Permissions** (MANAGEMENT tabs) — **Report Page**, **Inventory Page**, **Invoices Page**, **Product Page**, **Employee Page**, **Setup Page**.
5. Tap the green check to save. You should see **Role saved successfully**.
6. To change a role, tap the blue pencil (**Edit Role**). System role names cannot be renamed. The **Admin** role cannot be saved — its green check is disabled.
7. To remove a **Custom** role, tap the red trash and confirm. **Cashier**, **Manager**, and **Admin** cannot be deleted. If anyone still has that role, delete is blocked: **Cannot delete: This role is assigned to {count} employee(s): {names}** — reassign those staff on **MANAGEMENT** → **Employee** first.

Built-in defaults (do not try to permanently rewrite them):
- **Cashier** (default role): no **Void**, **Void and Duplicate**, **Change Payment**, **Flat Discount**, **Percent Discount**, **Open Drawer**, or **CRM Delete Customer**; no **Employee Page** or **Setup Page**; no **Settings**, **Reporting**, or **Analytics** routes.
- **Manager**: no **CRM Delete Customer**, no **Employee Page**, no **Settings**.
- **Admin**: all permissions; name and permissions stay locked.

> **💡 Tip:** System role permissions reset to the defaults above when staff sign in. To give a cashier extra access (for example **Void** or **Setup Page**), create a **Custom** role instead of editing **Cashier**. If someone hits a locked action, they see **Permission denied. Please switch to another account with the permission.** and **Switch Account** opens.

---

## 🎬 Video Guide

[Watch Demo Video](https://support.agenteehq.com/rails/active_storage/blobs/redirect/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBdTBDIiwiZXhwIjpudWxsLCJwdXIiOiJibG9iX2lkIn19--ad8bb02dcaf4bb1ee732f911c839f1b9b6f3b314/manage-employee-roles-and-permissions-EN.mp4)
