An important part of your Kobas setup is creating Staff User Permission Levels to ensure your business and information is secure, but staff can operationally function.
Last updated 13 Aug 2024
Jump to:
Introduction
Every staff member is assigned to a User Permission Level group. This defines what areas staff members can see within Kobas, and the actions that they can take. This is essential to configure as required to keep your data and people's privacy secure. Please also read our information in relation to GDPR here.
You can view, create and edit user levels and define the default permission set for each level by navigating to Administration > Staff User Permission Levels. Here you can create a new user level, change an existing one, or duplicate a current permission level as a start for a new level.
Some definitions used in this settings page:
- *Own Venue(s) - It is possible for a user to have more than one venue that is considered their own venue, and would come from:
- The user's home venue in their staff profile
- A venue of which the user is the venue manager (Administration > Venue Settings > Settings)
- A venue in an area of which the user is a territory manager
- A venue in a region of which the user is a territory manager
- Manage – view and make all available changes.
- View / Create / Edit / Delete – all of the available components of “Manage”.
- Preparation refers to Printers and KDS (Kobas Display Screens).
Seniority Level
Each user level is assigned a "seniority level", with 1 being the highest for Administrators. This defines your company hierarchy helping to protect data. Staff cannot access data or take actions relating to other staff on the same, or a higher, seniority level. You can have more than one user level on the same seniority level.
Warning: It is important to only give Administrator access to those who genuinely should have full and unfettered access to your business.
Administrators will be able to see and edit all personal and commercially sensitive information, make irreversible changes to your account, and make financial and data-erasure authorisations to Kobas in relation to the account.
Top Tip: We recommend duplicating the Administrator level and rename it, even with all the permissions ticked, this will still remove some of the more destructive rights of the users and removes their ability to authorise additional costs to Kobas.
This article gives more detail as to the effect of each permission element.
There are some permissions that are inherent only to the Administrator permission level, and cannot be delegated to lower user groups:
- The ability to roll back closing tasks.
- Access to the cloud Audit Log.
Administration
Permission name |
Users with this permission will be able to… |
|
Hardware Management |
Manage |
Manage all Tills, PDQs, and Preparation (Printer/KDS) across all venues. (The “Venues – Manage” permission below is required in conjunction with this). This also allows EPOS Simulator access. |
KDS States |
Manager |
This allows you to edit and manage the KDS Stats in the Administration section. |
Multi-Factor Authentication |
Require |
Setting this setting to active will require all users in this level to activate and use MFA. |
Operations |
Manage |
Access all the menus within Administration in the cloud that relate to the Stock and Rota System. Note for the “Pricing Administration” page, permission “Operations – Ingredients/Batches – Manage” is also required. |
System and Financial Settings |
Manage |
Access menus within Administration such as Kobas System Preferences, Kobas Billing, and Integration Settings. Within Venue Settings you will also need this permission to access the Financial settings tab and the Stripe settings for online ordering. This also allows exporting data to Sage and Xero. |
Territories |
Manage |
Access menus within Administration such as Venue Territories and Franchises. |
User Management |
Manage |
Access “Staff User Permission Levels” menus within Administration. |
Venues |
Manage |
Access to all venue pages, particularly the Venue Settings page, and pages relating to Daily Tasks within Administration |
Collaboration
Collaboration is the file-sharing “pinboard” section within Kobas cloud.
Permission name |
Users with this permission will be able to… |
|
Documents |
View |
View any documents uploaded here. |
Create / Edit / Delete |
View, upload, edit and delete docs to the board. |
Daily Tasks
Daily tasks refer to the Opening, Closing & In-Shift tasks within Cloud.
Permission name |
Users with this permission will be able to… |
|
All |
Override Time Lock Restrictions |
Make changes to Cash Logs after the set number of days in Kobas System Preferences (Operations) when the log locks down. |
Cash Bags
|
View all venues |
View Cash Bags in all venues |
Edit |
Edit Cash Bags in all venues |
|
Mark Banked |
Mark all Cash Bags as Banked (respecting the View All / Own venue permission) |
|
Mark in Account |
Mark all Cash Bags as in Account (respecting the View All / Own venue permission). This permission is required to edit Cash Bags. |
|
View own venue / venues |
View Cash Bags in own venue / venues* |
|
Cash Logs |
View own venue / venues |
View own venue / venues* Cash Logs |
View All Venues |
View All Venues Cash Logs |
|
Edit / Delete All Venues |
Edit / Delete All Venues Cash Logs |
|
Edit / Delete Home Venues |
Edit / Delete Home Venues Cash Logs |
|
Closing Tasks
|
All Venues |
Complete and view closing tasks for all venues. |
Own Venue / Venues |
Complete and view closing tasks for own venue / venues*. |
|
End of Trade Logs |
Edit Logged Amounts |
Edit the figures in the cash log after closing tasks have been declared. |
Opening Tasks
|
All Venues |
Complete and view opening tasks and in-shift tasks for all venues. |
Own Venue / Venues |
Complete and view opening tasks and in-shift tasks for own venue / venues*. |
|
Safe Logs
|
View Own Venue / Venues |
View own venue / venues* safe logs |
View All Venues |
View all venue safe logs |
|
Edit / Delete All Venues |
Edit / Delete all venues safe logs |
|
Edit / Delete Home Venues |
Edit / Delete home venues safe logs |
|
Till Float Logs
|
View Own Venue / Venues |
View own venue / venues* till float logs |
View All Venues |
View all venue till float logs |
|
Edit / Delete All Venues |
Edit / Delete all venues till float logs |
|
Edit / Delete Home Venues |
Edit / Delete home venues till float logs |
EPoS Local
This section refers to user permissions on the actual EPoS till / iPad units.
Permission name |
Users with this permission will be able to… |
|
Admin
|
Access Admin Menu |
Open the Admin menu on EPOS. This permission is required to access any other “admin” permissions on EPOS Local. |
View Session Data |
View “session data” including total sales value on EPOS. |
|
Download Data |
Perform the “download data” function on EPOS. |
|
Access training mode and other available venues |
Change the till screen between “Live”, “Training” and any other available venue. |
|
Special Save - Waste |
Mark items as “Waste” (ie, deplete stock, add to Waste in finance reporting). |
|
Special Save – Refund |
Log items as a “Refund” against Cash/Card / Other. |
|
Special Save – Comp |
Mark items as “Comp” (ie, deplete stock, add to Comp in finance reporting). |
|
Special Save – Director |
Mark items as “Director” (ie, deplete stock, add to Director in finance reporting). |
|
Special Save – Void |
Mark items as “Void” (ie. Remove from tab/basket and don’t record sale, don't deplete stock) |
|
Create / Edit Reservations |
Create and edit reservations for the same day. |
|
Set Sold Out |
Mark items as “sold out” or add “counts” onto EPOS items. |
|
Close Session |
Perform X- and Z-Reads on the current till session (necessary for closing tasks). This permission is also required to manage user Dallas key allocation. |
|
Manage Tabs |
Open the tab screen and settle etc the tabs. Without this permission, a user can only open, take payments and close tabs that they created, not having the ability to work on others that are not theirs. |
|
Price and Discount Availability Override |
Adjust the price of an item at any point, and apply any discount at any time, regardless of the discount's inherent time restrictions. |
|
Manage Automated Orders |
This allows a user to see pending/rejected orders, accept or reject them, and be notified when online orders are made that require to accept/reject on the till itself. |
|
Manage Order Tracking |
Opens the "Order Management" tab in the Admin menu on EPOS. Allowing to track online orders, view, mark as read, etc. |
|
Manage Framework
|
Allow taking orders |
Add items to the basket and to tabs, as well as settle them. |
Allow No Sale |
Perform a no sale (ie. Open the cash draw where there’s no sale). Access to the Admin menu is required. |
|
Allow Clock in/out |
Clock in and out and start/stop breaks. |
|
Allow Order Discounting |
Apply the pre-defined discounts within the active time frames identified. |
|
Allow Service Charge Management |
Change the definitions and applications of service charges. |
|
Redeem Deposits and Other Payment Types |
Redeem deposits and other payment types against an order or a tab. |
EPoS Administration
This section relates to managing EPoS within the cloud.
Permission name |
Users with this permission will be able to… |
|
EPoS Items |
View EPoS Items |
View all EPoS Items for all venues. |
EPoS Items |
Manage All Venues |
Create/edit/delete EPoS items ‘available in’ “All Venues” |
EPoS Items |
Manage Own Venue/Venues |
Create/edit/delete EPoS items ‘available in’ own venues. |
KDS Builds |
Manager |
Edit KDS Builds for all EPoS Items they have access to |
Menu |
Manage Own Venue / Venues |
Edit menu layout, assign menu Venue Manager for own venues. |
Menu |
Manage All Venues |
Edit menu layout, assign menu Venue Manager for all venues. |
Other |
Manage All Venues |
Manage discounts, Menu page creation, Modifiers, Price Bands & Customer Facing Screens in all venues. |
Operations
Within Kobas, the term Operations refers to the stock management system.
Permission name |
Users with this permission will be able to… |
|
Audit Log |
View |
Access the user audit log here https://login.kobas.co.uk/reports/audit/ |
Deliveries
|
Edit |
Edit a delivery that has already been saved. |
Override Stock Delivery Editing Time Restriction |
Make the above edits even after the number of days when a delivery is locked down to most users (click to change setting in preferences) |
|
Deliveries / Transfers / Orders
|
View Own Venue / Venues |
View all deliveries, transfers, and orders relating to own venue / venues*. |
Receive Own Venue / Venue |
Log deliveries and transfers as received in the own venue / venues*. |
|
Manage All Venues |
Undertake all actions across all venues in relation to deliveries, transfers, and orders. |
|
Ingredients / Batches
|
View |
View all ingredients and batches in the account. |
Manage |
Edit and delete all ingredients and batches in the account. |
|
Bulk Upload |
Use the spreadsheet bulk uploader for ingredients. |
|
Restrict Own Venue |
Restrict ingredients so that they are shown or hidden to home venues. |
|
Orders |
Create / Edit / Delete Own Venue / Venue |
Create, edit and delete all orders relating to own venue / venues*. |
Stock Checks
|
View All Venues |
View all stock checks in all venues. |
Create / Edit / Delete |
Create, edit and delete stock checks in all venues. |
|
Override Stock Check Editing Time Restriction |
Make the above edits even after the number of days when a stock check is locked down to most users (click to change setting in preferences) |
|
View Own Venue / Venue |
View all stock checks in own venue / venues*. |
|
Transfers |
Create / Delete / Fulfilment Own Venue / Venue |
Create, delete and fulfill transfers relating to own venue / venues*. |
Usage
|
View All Venues |
View all stock usage logs across all venues. |
View Own Venue / Venue |
View all stock usage logs in the own venue / venues*. |
|
Create / Edit / Delete All Venues |
Create, Edit, and Delete stock usage in all venues. |
|
Create / Edit / Delete Own Vewnue / Venues |
Create, Edit, and Delete stock usage in own venue / venues*. |
Reports
Some reports contain personally and commercially sensitive information. These reports ascribe to a two-step permission level as follows:
- The Report permission gives access to the reports
- Then the associated permission dictates whether the user can see for all venues or their “own venues”. This is in brackets in the table below.
Permission name |
Users with this permission will be able to access these reports... |
|
Customer Analysis
|
Loyalty |
Loyalty Scheme |
Reservations |
Reservations Report | |
Labour Analysis For most: (Staff > General > View All or Own) There is also a KSP setting that dictates whether additional permissions are required for Labour Costings.
|
Attendance |
Holiday Status, Holidays Taken, Punctuality & Sickness |
Cost Breakdown (All / Own Venues) |
Labour Costs, Labour Per Person, Time Comparisons
|
|
Payroll |
Hours Export, Labour Exchange, Tips Per Employee By Date |
|
Retention |
Length of Service, Staff Turnover |
|
Operations Analysis (Operations > Deliveries/ Transfers/ Orders All or Own) |
Daily Actions |
Incidents Report, Petty Cash |
Stock Financials |
Stock Audit Trail Transactions, Stock Transfers |
|
Stock Levels |
Stock Current Position, Stock Ingredient Averages, Stock Usage Comparison |
|
Overall Analysis |
Finances |
Operational Profitability |
Revenue Analysis (Daily Tasks > Cash Logs > View All or Own)
|
Comparisons |
Week on Week Sales, Year on Year Sales |
Headlines |
Cash Log |
|
Item Sales |
Item Sales (All) By Date, Item Sales (Single) By Date |
|
Sales Figures |
Daily Sales By Interval, Daily Sales By Order, Discounts, Group Sales Breakdown |
|
Sales Mix |
Sales Mix By Lead Type, Sales Week Breakdown |
Rotas
Permission name |
Users with this permission will be able to… |
|
Holidays
|
Request |
Request days off and holidays for themselves. |
Request for Others |
Request days off and holidays on behalf of other staff in their venue/company. |
|
View / Accept / Reject All Venues |
View, accept, and reject holiday/day off requests across all venues. |
|
View / Accept / Reject Own Venue / Venues |
View, accept and reject holiday/day off requests across own venue / venues*. |
|
Hours Export |
Approve Export |
Approve the export of hours worked as various CSV reports. Exports cannot be made until all hours have been approved. |
Hours Worked |
Approve Hours |
Mark Hours Worked on Rotas with permission to see as "Hours Approved", and to add shifts that weren't clocked in or added in Closing Tasks. This permission is required to add additional shifts in Hours Worked. |
Rotas
|
View Own Venue / Venues |
View rotas for all own venue / venues*. |
Manage All Rotas |
View, edit and delete rotas across all venues. |
|
Manage Own Venue / Venues Rotas |
View, edit and delete rotas across own venue / venues*. |
|
Change Shift Charged To |
Edit the venue an individual shift is charged to after the fact, in the Hours Worked screen. |
|
View All Venues |
View all venue rotas. |
|
Approve All / Own Venue Rotas |
Approve or reject rotas. |
|
Templates
|
Create / Edit / Delete All Venues |
Create, edit and delete rota templates for all venues. |
Create / Edit / Delete Own Venue / Venues |
Create, edit and delete rota templates for own venue / venues*. |
Staff
Manage staff HR profiles within Kobas.
Permission name |
Users with this permission will be able to… |
|
Current Staff
|
Reset Access Levels |
Edit the User Access Level for someone below their seniority level. |
Edit All Pay Details |
Edit pay information for all staff. This is required to see the Financial Module of the Rota Creator (for all venues). |
|
Edit Own Venue / Venues Pay Details |
Edit pay information for own venue / venues* staff. This is required to see the Financial Module of the Rota Creator (for own venues). |
|
Details (The permission General > View All or Own dictates whose details can be edited) |
View / Create / Edit / Delete* |
View, create, edit and delete full staff profiles (including HR sections in conjunction with last three staff permissions) of staff who have a lower seniority level, as defined in the "Staff User Permission Level" menu. Staff will also not be able to see their own full profile except Administrators who can. With this permission, staff can Reset the EPOS PIN of those on the same/higher seniority level. Staff with this permission level will also be able to reset Cloud passwords for lower level staff. |
General
|
View All Staff |
View the staff list (ie. venue, name, picture and phone number) for all venues. |
View Own Venue / Venues Staff |
View the staff list (ie. venue, name, picture and phone number) for own venue / venues*. |
|
Edit Staff Permissions |
|
|
View All Pay Details |
View pay details of all staff (not edit). |
|
View Own Venue / Venues Pay Details |
View pay details of all own venue / venues* staff (not edit). |
|
Onboarding |
View / Create / Edit / Delete |
Full access to the onboarding process for new starters, and view access to the HR sections of the staff profile. |
Performance (The permission General > View All or Own dictates whose details can be edited) |
View / Create / Edit / Delete |
Full access to the performance management section of the staff profile. |
Recruitment |
View / Create / Edit / Delete |
Full access to the recruitment platform job adverts. |
Your Customers
Settings that manage access to your customer database within the cloud.
Permission name |
Users with this permission will be able to… |
|
Customers
|
View |
View the customer database. |
Create / Edit / Delete |
Make edits in the customer database. |
|
Gift Cards |
Manage |
Allows access to the cloud menu: EPoS > Gift Card Manager. |
Loyalty Campaigns |
Manage |
Manage the creation, amendment, deletion of loyalty campaigns and the codes. |
Reservations
|
All (View) |
View all reservations across all venues. |
All (Create / Edit / Delete) |
Create, edit and delete all reservations across all venues. |
|
Own Venue / Venues (View) |
View all reservations across own venue / venues*. |
|
Own Venue / Venues (Create / Edit / Delete) |
Create, edit and delete all reservations across own venue / venues*. |
Return to Training for Administrators.