Staff & shifts
The Staff page gives your team personal logins to the admin panel: everyone signs in with their own email and password and sees only the sections their role allows. The same page hosts the shift schedule and time tracking.
Open: Admin panel → Staff. The owner sees nine tabs: Employees · Roles and access · Shifts · Plan vs fact · Payroll · Labour cost · Requests · Processes · HR. Managers see My cabinet · Shifts · Plan vs fact · Requests · Processes · HR. Other employees get a personal cabinet with their shifts, requests, documents and employment details, without the shared tab bar.
Roles and access#
| Role | What they see and can do |
|---|---|
| Manager | Menu, orders, POS, inventory, locations and devices |
| Waiter | Orders and POS only |
| Cook | Orders and the kitchen screen (KDS) only |
| Courier | Delivery screen only: their orders, map and routes |
The owner keeps full access to everything, including finance, subscription and settings.
Three levels per section#
A section is not granted "all or nothing": every section allowed to a role has three levels — 👁 view, ✏️ edit data and ⚙️ section settings. You can, for example, let a stock keeper view and edit inventory but keep them out of its settings, and leave an accountant with read-only finance.
What the level changes on the employee's screen:
- 👁 view only — the section header shows a "View only" note explaining who grants the edit level, and the "add", "create", "delete" buttons are disabled (hovering explains why). Lists, search, filters, printing and exports keep working.
- ✏️ edit — normal work with the section. The server additionally issues a write grant for that section's data; without this level writing is physically impossible, even around the interface.
- ⚙️ settings — the "Section settings" gear in the window header. Without this level the gear is simply not there. In the general Settings hub such a role keeps only the personal tabs — "Interface" (how the admin panel looks for them) and "Personal SIP accounts"; account-wide parameters are hidden.
The levels are already honoured by Menu, Orders, Inventory, Staff, Customers, Appointments, Tables & bookings, POS, Finance and Settings; the "Section settings" gear is gated by the ⚙️ level in every section at once. The remaining sections still show a role everything they contain, without splitting view from edit — we are rolling them out one by one.
Adding an employee#
- Click "Add employee".
- Enter the email (used as the login), name and role.
- Set a password or click "Generate".
- Hand the credentials to the employee — the password is shown only once (there's a "Copy credentials" button).
At any time you can reset the password, add notes (schedule preferences, contacts, documents) or delete the employee — they immediately lose access.
Workspaces#
The admin sidebar has a Workspace switcher: Administration, Hall, Kitchen, Delivery, Marketing. It trims the menu to relevant sections — handy on a waiter's tablet (just Orders, POS, Kitchen, Floor Plan) or a kitchen device. A workspace is a filter on top of role permissions: access is defined by the role, the workspace just hides the clutter.
Shifts: plan vs fact#
The staff page includes a shift schedule:
- Plan — the manager lays out shifts per day (start and end time);
- Fact — the employee taps clock-in and clock-out; time is recorded server-side, so it can't be forged from a device. Clock-in can be restricted to the venue — by geofence or only from a venue terminal (a tablet with a PIN pad or a monitor with a QR code) — and forgotten shifts can be closed automatically, see Clock-in and clock-out;
- Plan vs fact — the summary highlights deviations: late arrivals, overtime, no-shows. Shifts are grouped by role.
Worked hours feed into Finance (the Staff tab) — labor costs are visible next to revenue.
Payroll#
The owner’s Payroll tab calculates monthly pay from closed shifts: hourly pay, salary, commission or a combination, overtime, tips, manual bonuses and deductions. Country packages provide the applicable tax calculation options; custom rates remain available where a package does not cover the case. Review the employer, tax profile, hours and adjustments before finalizing a calculation.
The calculation moves from draft to finalized to paid. Employees see their payslips in My cabinet after finalization. Payslips and timesheet/payroll exports are available; country-specific reporting files depend on the selected package. Labour cost compares staffing costs with sales and hours worked.
Separate Payroll section#
A separate Payroll page (/payroll) handles calculations and materials for the accountant. Select an employer and month, then use Overview · Monthly calculation · Payouts · Government · Documents · Settings. Government has separate reports and deadline-calendar views. The owner grants section access through staff roles; access to payroll data is checked separately.
Start with employer settings and the monthly calculation. Payouts and budget payments currently show Not available yet and offer links to the calculation or calendar. The program prepares calculations and materials but does not transfer money or file reports itself; recording a payout does not make a bank transfer.
Personnel records and HR#
The HR tab is available to the owner and manager. It brings together staff turnover and tenure, discipline, training progress, personnel records, identity and tax details, contracts and employment dates. Country profiles provide a required-document register with valid, expiring, expired and missing states.
Upload scans to the personnel file or use Fill from scan, then review and save the recognized details. Reporting deadlines can be marked as submitted manually. An employee’s individual page also contains the manager’s private notes, issued equipment, documents and personnel records; outstanding equipment is flagged on departure.
Requests and HR processes#
Requests combines leave, employee-record and timesheet corrections, resignation and shift swaps. Employees submit requests in their cabinet and track their status. The owner or an authorized manager decides in the shared queue; the tab badge shows pending requests.
Processes organizes the steps before hiring, on the first day, when a document needs renewal and when an employee leaves. HR permissions determine who can access requests and processes.
Exporting payroll to 1C:ZUP#
Close the period and finalize payroll, then choose an export and map employees to their 1C codes. CSV packages and XML are supported; XML needs the employer’s name and tax ID. Download the files and the preparation report, which identifies unmapped employees and errors. Import the package into your own 1C database and check the result there.
Login codes and device QR codes#
Typing a login and password repeatedly is inconvenient on a shared tablet or kitchen display. Login codes are short unique identifiers that open the required workspace with its assigned permissions.
Two types of code#
Both types live in QR codes, alongside guest table codes, on separate tabs.
| Type | Where to create it | Intended use |
|---|---|---|
| Device code | Admin panel → QR codes → Devices | A waiter tablet, kitchen monitor or till: a particular workspace linked to a location |
| Staff QR code | Admin panel → QR codes → Admin login, owner only | An employee needing quick access on another or shared device |
The Devices tab also shows live devices per location and when each was last seen. It can bind a kiosk to a payment terminal connected through the bridge on that computer. Open this page on the kiosk computer itself, where the local bridge is visible.
Creating a device code#
- Open QR codes in the sidebar and select Devices.
- Click Create to generate a unique code.
- Name it, for example Hall till or Kitchen, select its start screen, such as Order monitor, Kitchen or Menu, and optionally restrict it to a location.
- Set a PIN if needed. Staff must enter it after scanning.
- Download the displayed QR code as SVG, print it and attach it to the tablet or counter.
Scanning the QR code opens the login screen and then the selected workspace with the code's permissions.
Creating a staff login QR code#
This code belongs to a person rather than a device. The employee can scan their personal QR code to open the admin panel on any device.
- Open QR codes → Admin login. Use the neighbouring Devices tab instead if you want a workspace with restricted access.
- Click Add and enter the employee's name.
- Set a PIN or password to protect the code.
- Print or send the QR code to the employee.
The employee scans it to open their workspace, entering the PIN once after scanning if one is set. You can deactivate or delete the code at any time to prevent further sign-ins through it.
Switching staff on a shared tablet. Each waiter keeps their own QR code on a card or phone and scans it when starting work. A different employee signs in with their own code.
Device-code permissions#
Configure what the device can access:
- Start screen — Order monitor, Kitchen (KDS) or Menu management.
- Locations — restrict orders to one or more locations.
- Additional permissions — view or manage orders, change item availability and prices, edit menus and locations, or manage the stoplist.
Mobile apps for staff#
Native Android apps are available for waiters, cooks, couriers and floor managers. Open the app and scan a device code to sign in. See Mobile apps.
What you need to get started#
- Owner permissions — employees are created by the account owner; the "Employees", "Roles and access", "Payroll" and "Labour cost" views are available to them only, while the schedule and HR views are also open to a manager.
- The employee's email and a chosen role — with those the person signs into the admin panel as themselves.
- A shift schedule — for plan vs. fact and for distributing tips into a pool.
- Pay rates — for payroll and labour cost calculations.
- Login codes and device QR codes — to put the POS, kitchen display or kiosk on a tablet (QR codes and devices).
Limitations#
- Invitations may need to be handed over manually. On AWS the system attempts email delivery; if it fails, or on the Russian cloud, it shows the owner the sign-in address, login and temporary password to pass to the employee.
- Access levels are enforced in the interface. Writing a section's data to storage is already refused by the server for an employee without the "edit" level, but individual API operations are so far limited by the interface only — the server-side check of levels is still being written.
- HR permissions have their own scope: the whole account, direct reports, selected locations or the employee themselves. The server checks it for the relevant HR actions; this does not imply identical permissions across every module.
- Russian HR records are written only on the Russian contour (a personal-data residency requirement); for Kazakhstan the HR module is unavailable anywhere — the system says so honestly and shows an article.
- My documents shows the employee’s own documents. They can open them and acknowledge reading; an empty list and a loading failure are shown separately.
- Employee self-service is available: leave requests, shift swaps, timesheet corrections and clock-in. Geofencing and terminal-only rules may restrict clock-in from a phone. Shift reminders support 0–24 hours; 0 disables them, and the default is 2 hours.
- 1C:ZUP export is available for the Russian cloud or accounts with Russian locations. It requires a closed period and finalized or paid payroll; XML also requires employer details. This is a downloadable package, not continuous synchronization.
- The target labour-cost percentage is stored in the browser — on another device you will have to set it again.
- The "Roles and access", "Payroll" and "HR records" screens are complex — our internal clarity review gives them 2 out of 5; they were written for an HR specialist, not for an owner.
Troubleshooting#
The employee did not receive an invitation. If manual delivery is offered, copy the displayed sign-in address, login and temporary password and pass them to the employee. Creating access does not prove that an email was delivered.
The employee sees the wrong sections. Check the role: the set of sections is defined by it, and the "workspace" only narrows the interface visually. On the POS the real permission layer is role plus PIN.
The employee cannot open My documents. Check that the document is linked to that employee and the appropriate location. Retry a failed load; an empty list means no accessible documents were found.
The HR section is blocked. This is the personal-data residency gate: Russian HR records are kept only on the Russian brand.
Payroll was not calculated. Pay rates are missing, or there are no closed shifts in the period.
Related#
- Clock-in and clock-out — venue terminal, QR from a monitor, auto clock-out
- POS — the waiter's work screen
- Kitchen (KDS) — the cook's work screen
- Own delivery — the courier's work screen
- Floor plan — assigning waiters to tables
- Finance — staff reports
FAQ#
How many employees can I add?#
Up to 30 hired employees per account; the owner's row does not count towards the limit. The system tells you when the limit is reached.
Can a waiter see finance or settings?#
No. The waiter role sees orders and the POS. Role permissions apply throughout the admin panel.
How is a waiter assigned to an order?#
Automatically: an order the waiter creates at the POS is assigned to them, as are orders from their assigned tables in the floor plan's Waiters mode. The assignment is visible on the order card.
Can I schedule shifts without using admin roles daily?#
Yes. Shift scheduling works for employees regardless of how often they use the admin panel.
What happens if an employee loses a QR code?#
Delete it on the relevant QR codes tab to stop further access through it. Create and share a replacement.
Can a code be limited to one location?#
Yes. Select the allowed locations when creating the device code; staff using it see only those locations' orders and data.