1Ownership — the business account
glider.garden@gmail.com+ password — signs into the dashboard only- OWNS the venues (Venues page, add/remove) · full owner authority · bookkeeping
- Survives all staff changes; password reset by email; created by FillTables, never self-signup
2Staff — PINs, per venue
| ID | Name | Role | Opens |
|---|---|---|---|
m1 | Justin | OWNER | everything, incl. approving own voids |
o1 | Alice | OWNER | everything, incl. approving own voids |
k1 | Alex | MANAGER | + voids/refunds (as 2nd person), menu, reports, settings |
w1 | Linda | WAITER | orders + payments on the POS (dashboard bounces her to POS) |
3Money rules — the second PIN
- Every void/refund records TWO names: the operator + the authoriser who PINs in
- Managers can never approve their own · Owners can (flagged in the audit log)
- The POS socket can never author money events — PIN-checked paths only
4Devices — the allowlist
- Every signed-in device registers; visible on the Network map
- “Require device approval” toggle (Settings → Devices) — currently off; flip on at cutover after approving the café iPads (a manager sign-in auto-approves that device)
5Customers — your guests (storefront only)
- Full: email + password → order history, saved details, loyalty
- Light: mobile number only → loyalty stamps, nothing private (server strips all personal fields)
- Stamps carry over if a light guest later creates a full account · customers can never reach staff screens
6Sessions — being upgraded now
- Today: sessions expire + POS/dashboard sign in separately
- Coming: sign in once, stays until sign-out, survives updates, one login flows POS ↔ dashboard, header shows 👤 name · Sign out
One sentence: the email owns the business, PINs work the shifts, a second PIN moves money, devices are the doors, customers live in their own world — and sessions tie it together.