Employee permissions and operation passwords on the POS — Paloma365 Classic (Windows POS)
This article covers Paloma365 Classic, the Windows POS application. Access to sensitive operations (refunds, discounts, reports, deleting order lines, etc.) is controlled by two mechanisms: the employee's personal permissions and the point of sale's operation passwords. This article explains where each is configured, in what order they are checked, and why the POS says "Permission denied!" or asks for a password.
Overview
- Employee permissions are configured in the dashboard, in the employee card — a separate checkbox for each operation (refund, discount, stop list, reports, and so on).
- Operation passwords are configured per point of sale: dashboard → "Point of sales" → select the point → the "Passwords" tab. These are the point's passwords, not the employee's.
The order of checks on the POS:
- If the employee's permission is granted, the operation runs immediately — no password is asked.
- If the permission is explicitly denied, the POS shows "Permission denied!" and stops. The password is not offered: a point password cannot override a denial set in the employee's permissions.
- If the employee's permissions were never configured, the POS falls back to the point password: an on-screen keyboard window opens with the prompt "Enter the password to …" (red text, input masked with asterisks). Correct password — the operation runs; wrong password — "Wrong password!".
- If the operation's password is not set (empty) on the point, most operations are allowed without any prompt. The exception is six operations for which an empty password means denial (see the tables): the POS shows a message like "To … you need to set the password!" with a hint on where to set it.
Tables: operation → permission → password → empty password
"Permission" is the checkbox in the employee card in the dashboard; "Password" is the field on the point's "Passwords" tab; the last column shows what happens when the employee's permissions are not configured and the point password is empty.
POS reports
| Operation | Employee permission | Point password | Empty password |
|---|---|---|---|
| Final report | yes | final report password | allowed |
| Sales report (act) | yes | sales report password | allowed |
| X-report and Z-report | yes (shared for X/Z) | X-report password (shared for X/Z) | allowed |
| Products in stock | yes | stock report password | denied: "To view the report for items in stock, you need to set the password!" |
| Material sheet | yes | material sheet password | denied: "To view the report "Material sheet", you need to set the password!" |
| Marks report | stock report permission | stock report password | denied (same as stock) |
| Return / salon / refusal reports | yes | — | permission only |
| Cash report (money operations) | yes | — | permission only |
Working with orders
| Operation | Employee permission | Point password | Empty password |
|---|---|---|---|
| Refund | yes | refund password | denied: "To refund you need to set the password!" |
| Change the payment type | refund permission | refund password | denied (same as refund) |
| Unlock the order | yes | unlock password | denied: "To unlock the order you need to set the password!" |
| Split the bill | yes | split password | allowed |
| Stop list | yes | stop-list password | allowed |
| Change the order's employee | yes | — | permission only |
| Dish transfer | yes | — | permission only |
| Change the table in a bill | — | table change password | allowed |
| Receipt copy | — | receipt copy password | allowed |
| "All" / "Paid" tabs on the cash screen | final report permission | cash tab password | allowed |
| Closing an open order (leaving with an unpaid bill) | line deletion permission | line deletion password | allowed |
Lines, prices, discounts
| Operation | Employee permission | Point password | Empty password |
|---|---|---|---|
| Discount | yes | discount password | denied: "To use discounts you need to set the password!" |
| Refusing a line | yes | refusal password | denied: "To process the refusal you need to set the password!" |
| Deleting a line from an order | yes | deletion password | allowed |
| Price change | yes | price change password | allowed |
| Quantity change | yes | — | permission only |
| Manual service percent | yes | service password | allowed |
| Changing the note | yes | — | permission only |
Clients, money and other
| Operation | Employee permission | Point password | Empty password |
|---|---|---|---|
| Viewing / choosing a customer | yes | customer password | allowed |
| Adding a customer from the POS | yes | customer addition password | allowed |
| Deposit top-up / withdrawal | yes (two permissions) | customer password | allowed |
| Adding / taking / moving money, bank expense | yes (separate permissions) | — | permissions only |
| Table placement map | yes | — | permission only |
| Label printing | yes | — | permission only |
| Exiting the program | — | exit password | allowed |
Special case: for discounts and the service percent there is an extra shortcut — even when the point password is set, it is not asked if the employee's matching permission is granted.
Where things are configured
- Permissions — dashboard → the employee card. If an employee was never given any permissions, the POS relies on the point passwords (see the order of checks above).
- Passwords — dashboard → "Point of sales" → the point → the "Passwords" tab. The POS itself shows this path in the help attached to the message: sign in to your account, open the "Point of sales" catalog, select the point, go to the "Passwords" tab and set the password.
After changing permissions or passwords the POS must synchronize with the dashboard — see Synchronization troubleshooting.
Common problems
- "Permission denied!" — the operation is explicitly forbidden in the employee card. The POS will not offer a password: ask the administrator to grant the permission in the dashboard and wait for synchronization.
- "Wrong password!" — the wrong password was entered. Enter the point of sale's password for this operation (the "Passwords" tab), not the employee's personal code.
- "To … you need to set the password!" — the operation belongs to the strict list (refund, discount, refusal, unlocking, stock, material sheet) and no password is set on the point. Set the password in the dashboard — without it the operation is unavailable.
- The POS asks one employee for a password but not another — the second employee has the permission granted in their card (then no password is asked), or the first one had the permission explicitly revoked.
- The POS stopped asking for a password — most likely the employee was granted the permission, or the operation's password was cleared (for most operations an empty password means free access).
FAQ
Why doesn't the POS ask the administrator for a refund password?
Because the "refund" permission is granted in their employee card. The password is only asked of employees whose permissions were never configured.
Can a point password allow an operation to an employee whose permission is denied?
No. An explicitly denied permission is stronger than the password: the POS shows "Permission denied!" and does not offer password entry.
Whose password goes into the "Enter the password to …" window?
The point of sale's password set for this specific operation on the "Passwords" tab (usually known to the administrator or manager). It is not the employee's sign-in code.
Why are "Products in stock" and "Material sheet" unavailable even though no password was ever asked?
For these reports (and for refund, discount, refusal and order unlocking) an empty password means denial, not free access. Set a password on the point's "Passwords" tab or grant the employee the matching permission.