User Roles & Permissions
SSP Manager implements a flexible role-based access control (RBAC) system that allows you to manage user permissions at both the organization and location level.
Overview
The permission system operates on two levels:
- Collection Level: Permissions for managing groups of locations
- Location Level: Permissions for individual restaurant locations
Default Roles
Super Admin
Full access to all features across all locations and collections.
Permissions:
- ✅ Manage users and invitations
- ✅ Create and delete locations
- ✅ Configure payment settings
- ✅ Manage all menus and items
- ✅ View all reports and analytics
- ✅ Configure integrations
- ✅ Manage printer settings
- ✅ Configure tax rules
- ✅ Access audit logs
- ✅ Manage employee time & attendance
Location Manager
Manages day-to-day operations for assigned locations.
Permissions:
- ✅ Manage location users (invite, edit)
- ✅ Edit menus and menu items
- ✅ View sales reports
- ✅ Manage tables and floor plans
- ✅ Configure printers
- ✅ Process orders
- ❌ Delete locations
- ❌ Configure payment settings
- ❌ Access organization settings
Kitchen Manager
Focused on kitchen operations and inventory.
Permissions:
- ✅ View and manage orders
- ✅ Update menu item availability
- ✅ Manage inventory
- ✅ View kitchen reports
- ❌ Edit prices
- ❌ Manage users
- ❌ Configure settings
Server/Cashier
Front-of-house staff with limited access.
Permissions:
- ✅ Process orders
- ✅ View assigned tables
- ✅ Print checks
- ✅ Clock in/out
- ❌ Edit menus
- ❌ View reports
- ❌ Manage settings
- ❌ Manage other users
Accountant/Bookkeeper
Financial reporting and analysis.
Permissions:
- ✅ View all financial reports
- ✅ Export reports
- ✅ View audit logs
- ✅ Manage tax settings
- ❌ Process orders
- ❌ Edit menus
- ❌ Manage users
Permission Matrix
| Feature | Super Admin | Location Manager | Kitchen Manager | Server | Accountant |
|---|---|---|---|---|---|
| Dashboard Access | ✅ | ✅ | ✅ | ✅ | ✅ |
| Menu Management | ✅ | ✅ | 📝 View Only | ❌ | ❌ |
| User Management | ✅ | ✅ | ❌ | ❌ | ❌ |
| Order Processing | ✅ | ✅ | ✅ | ✅ | ❌ |
| Reports & Analytics | ✅ | ✅ | 📝 Limited | ❌ | ✅ |
| Payment Settings | ✅ | ❌ | ❌ | ❌ | ❌ |
| Tax Configuration | ✅ | ✅ | ❌ | ❌ | ✅ |
| Printer Setup | ✅ | ✅ | ✅ | ❌ | ❌ |
| Integrations | ✅ | ❌ | ❌ | ❌ | ❌ |
| Audit Logs | ✅ | ❌ | ❌ | ❌ | ✅ |
| Time & Attendance | ✅ | ✅ | ❌ | 📝 Own Only | ✅ |
Kitchen abilities
The Kitchen Display and the kitchen pages in SSP Manager are gated by these abilities:
| Ability | Unlocks |
|---|---|
update_item_list_status | On the KDS: start, claim, plate, serve, hold, resume and recall lines |
submit_orders | Submitting an order; firing and releasing courses (KDS Expo screen and SSP Waiter) |
manage_kitchen_stations | The Stations tab: stations, roles, KDS settings |
manage_kitchen_routing | Routing classes and the routing of menu items |
eighty_six_menu_items | The 86 control in the KDS item sheet |
eighty_six_menu_itemsThis ability is not part of any built-in role yet. Grant it per user (Manage Users → Edit Permissions) from an account that already holds it — an organisation administrator — or add it to a custom role.
Creating Custom Roles
- Principle of Least Privilege: Grant only the minimum permissions needed
- Regular Audits: Review permissions quarterly
- Role Documentation: Document what each custom role can do
- Testing: Test new roles carefully before assigning to users
Location vs Collection Permissions
Collection-Level Permissions
Apply to all locations within a collection:
- Menu synchronization across locations
- User management across multiple locations
- Centralized reporting
Location-Level Permissions
Apply only to specific locations:
- Location-specific settings
- Local user access
- Individual location reports
Managing User Permissions
Inviting a New User
- Navigate to Locations → [Location Name] → Manage Users
- Click Invite User
- Enter email address
- Select role from dropdown
- Click Send Invitation
Editing User Permissions
- Navigate to Manage Users
- Click on user's name
- Select Edit Permissions
- Modify role or individual permissions
- Click Save Changes
Revoking Access
- Navigate to Manage Users
- Click on user's name
- Select Remove User
- Confirm action
Permission Inheritance
Permissions can be inherited in a hierarchical structure:
Organization
├── Collection A
│ ├── Location 1
│ └── Location 2
└── Collection B
├── Location 3
└── Location 4
- Organization-level permissions apply to all collections and locations
- Collection-level permissions apply to all locations in that collection
- Location-level permissions apply only to that specific location
Security Considerations
Permission Checks
- UI elements are hidden based on user permissions
- All actions are validated against user permissions
- Both client and server-side checks are enforced for security
Session Management
- Sessions expire after 24 hours of inactivity
- Permissions are refreshed on login
- Users must re-authenticate after session expiration
Troubleshooting
User Can't Access Feature
- Verify user's assigned role
- Check if location/collection access is granted
- Ensure user session is not expired
- Review audit logs for access attempts
Permission Changes Not Reflecting
- Have user log out and log back in
- Check if permission update was saved successfully
- Verify no conflicting permissions exist