Skip to content

Employees, permissions and time clock — Paloma POS 2

This article is about Paloma POS 2 — the new Paloma point-of-sale app for a tablet, POS terminal or Windows device. It explains how employees and their permissions work: the employee list, the role and access-rights constructor (simple and advanced mode), how permissions affect order visibility and access to actions, switching operators by PIN, and clocking in and out (time clock). If you are not sure which product you have, start with «How to tell you have Paloma POS 2». For signing in by PIN and opening a shift, see «Sign-in, employee PIN and opening a shift».

Overview

  • Employees. The employee list is every operator who signs in to the POS by PIN. Open it from the side menu with «Employees». Here you add, edit, delete and restore employees.
  • Roles and permissions. Each employee has one or more roles (positions). A role is a set of permissions: which POS sections are visible and which actions are allowed. Roles are configured in «Access types».
  • Permission constructor. The constructor has two modes: «Simple» — by plain-language capabilities and ready-made positions, and «Advanced» — an exact matrix of rights per operation (view, edit, add, delete, print).
  • How permissions affect work. If an employee lacks a right, the button or section is hidden, and an attempt to act shows a refusal. Some actions can be allowed once with a manager authorization.
  • Switching operators by PIN. The operator at the register changes via «Sign out» and re-entering a PIN — no full account sign-out.
  • Time clock. An employee clocks in and out in «Clock Time»; work hours are calculated from these punches.

The employee list

Open the side menu and tap «Employees» — the «Employees» screen opens with the list of operators.

  1. At the top is a search field with the hint «Search by name, username, phone or email». Start typing to filter.
  2. To add an employee, open the «Add employee» form. Fill in «Full name», set a «PIN», and optionally «Phone», «Username» and «Details».
  3. Under «Roles» assign one or more roles — they define the permissions. Under «Workplaces» choose where the employee may sign in, or turn on «All workplaces».
  4. Save with «Save changes».

The list shows only real operators who sign in by PIN. Service and empty back-office rows are not shown, so no blank-name row with a "?" avatar appears.

A deleted employee can be brought back: from the screen menu choose «Restore deleted» — the «Restore Employees» screen opens with the deleted operators.

Roles and permissions: «Access types»

Open the side menu and tap «Access types» — the «Access Types» screen opens with the list of roles. The section is available to employees with the roles right; if there are no roles yet, the POS shows a hint to refresh from the cloud.

To create a role, tap «Add role» and enter a name in «Role name». An existing role can be renamed, cloned («Clone role») or deleted.

Rights are grouped into sections:

  • «Interfaces & sections» — what is visible on the home screen (quick order, order list, tables, delivery, KDS, reports, analytics, settings, time clock and others). The reports right opens the whole reports section, including the «Rentals report» — see «Time-based tariffs (tarificator)».
  • «Order operations» — what is allowed with an order (discounts, custom price, removing items, refunds, changing the employee, access to other employees' orders and others).
  • «Shift, cash & receipts» — working with the shift, the cash drawer, cash in and out, unlocking a bill.
  • «Other» — the remaining rights.

The constructor: simple and advanced mode

At the top of the role constructor is a «Simple» / «Advanced» toggle.

Simple mode

Simple mode is the default and speaks in capabilities rather than technical rights:

  1. Under «Position» you can pick a ready-made base — for example «Server», «Cashier», «Admin», «Kitchen», «Delivery» or «Full access».
  2. Below, plain-language capabilities are toggled by group: «Sales», «Floor», «Orders & reports», «Catalog», «Management» — for example «Accept orders & payment», «Give discounts», «Refunds & cancels», «Work with tables», «View reports», «Staff & roles».
  3. On the right, the «What the employee will see» block previews which sections will be available with the current set. Changed items are marked «changed».

Simple mode fits most cases: pick a position, tick the capabilities, and the role is ready.

Advanced mode

Advanced mode shows the full rights matrix. For each right there are operations: «View», «Edit», «Add», «Delete», «Print» (the set depends on the right). Each rights section has an «Allow all» checkbox that grants every right in the section at once. There is search by role («Search roles») and by right («Find permission»). While a permission search is active, the «Allow all» checkbox applies only to the rows visible in the search results, and its checked state is computed from the visible rows too — so you can grant one right precisely: find it with «Find permission» and turn on «Allow all», and only what was found is granted. Some operations are managed in the back office and only shown on the POS — those are marked «managed in back office».

After changes, save the role — the POS shows «Role saved».

How permissions affect order visibility and actions

Permissions work on the POS like this:

  • Hidden sections. If a role lacks a section right, its tile does not appear on the home screen. Without the order-list right, for example, a cashier will not see that tile.
  • Visibility of other employees' orders. The right to access other employees' orders determines whether an operator sees only their own orders or all of them. Without it, an employee sees only their own orders in the order list; an employee with it sees all orders at the point.
  • Blocked actions. If an action is not allowed, the POS shows «Not allowed for your role» with «Ask a manager to authorize this action.» Some of these can be done once: the POS opens «Manager authorization required», where a manager enters their PIN or a function password.

For removing items, voiding and refunds, see «Removing items, voiding a check and refunds».

Switching operators by PIN

At the register, the operator changes without a full sign-out: in the side menu tap «Sign out» — the POS returns to the PIN screen while keeping the workplace signed in, and the next employee signs in with their PIN. Each person's sales are recorded to whoever is signed in. This flow and opening a shift are described in «Sign-in, employee PIN and opening a shift».

Time clock (clock in and out)

Open the side menu and tap «Clock Time» — the «Time Clock» screen opens.

  1. The employee starts work with «Clock In». The status then changes to «On shift» and the last punch is shown.
  2. Ending work is marked with «Clock Out».
  3. A manager can open the team screen via «Manage team» and see who is on shift. Past punches are corrected via «Edit time cards» (the «Edit Time Card» screen) if the employee has the right to edit the time clock.
  4. Totals for hours worked are in «Work Hours»: total hours, number of shifts, first in and last out, PDF export and print.

Open obligations block clocking out: with unpaid orders the POS shows «Unpaid orders», and with unfinished tips «Pending tips». In that case pay the orders, finish the tips or get a manager authorization.

The time clock (clock in / out) is not the same as the cash shift: the shift belongs to the workplace and is opened with «Open shift», while clock in / out are the employee's personal punches. For closing the cash shift and reconciliation, see «Closing a shift».

Common problems

  • "Не удалось найти этого сотрудника — возможно, он удалён на другом устройстве" — the card was deleted or has not arrived; open "Restore" in the panel menu.
  • "Не удалось загрузить удалённых сотрудников", "Не удалось загрузить роли: {error}" — the lists did not load; retry.
  • "Не удалось сохранить — попробуйте ещё раз." — the card edit did not save.
  • «Not allowed for your role» and «Ask a manager to authorize this action.» — the current role lacks the needed right. Set the right in «Access types» or ask a manager to authorize the action.
  • «Not allowed for your role — ask a manager to authorize.» — the same as a short notice when you attempt the action.
  • «Manager authorization required» — the action needs elevated permission. A manager enters their PIN («Employee PIN») or a «Function password» to allow it once.
  • «Incorrect — access denied» — during manager authorization the PIN or function password was wrong. Try again.
  • «No roles configured yet.» — the POS has no role catalog. Refresh from the cloud («Sync») to pull roles from the back office.
  • «Couldn't save changes. Try again.» — the role did not save. Check the connection and retry; while the shift is closed, changes apply after sync.
  • «Enter a role name.» — you are saving a role without a name. Fill in «Role name».
  • «Couldn't load the list. Pull to refresh from the cloud.» — the employee list didn't load. Pull the screen down to refresh.
  • «That PIN is already in use.» — the PIN you set belongs to another employee. Choose a different PIN.
  • «Please clock in to continue.» — the employee has not clocked in. Tap «Clock In» in «Clock Time».
  • «Unpaid orders» / «Pending tips» — you cannot clock out while there are unpaid orders or unfinished tips. Close the orders, finish the tips or get a manager authorization.

FAQ

What is the difference between a role and permissions?

A role is a position with a ready-made set of permissions (for example «Server» or «Cashier»). Permissions are the specific rights inside a role. An employee is assigned a role under «Roles», and the role itself is configured in «Access types».

A server sees only their own orders. How do I show them all?

Visibility of other employees' orders is a separate right. Turn it on for the server role in «Access types» (the «Order operations» group, the access-to-other-employees'-orders right) — after that the order list shows all orders at the point.

Simple or advanced mode?

Simple mode is enough for most cases: pick a position and tick capabilities. Advanced mode is needed when you must fine-tune individual rights per operation — view, edit, add, delete, print.

How do I change an employee's PIN?

Open the employee in the «Employees» list and set a new PIN in «New PIN (leave blank to keep)». Leave the field blank if the PIN should not change.

An employee left. How do I remove them from the POS?

Delete the employee in the «Employees» list — they can no longer sign in by PIN. If you deleted them by mistake, bring them back with «Restore deleted».

Is the time clock the same as the cash shift?

No. Clock in / out in «Clock Time» are the employee's personal punches for calculating work hours. The cash shift belongs to the workplace and is opened separately with «Open shift». See «Sign-in, employee PIN and opening a shift» and «Closing a shift».