See which counter actions each role should be able to perform. Use it as the starting point for setting up employee access in your billing system.
ActionAccess for Cashier
Create a sale
Search products and build a cart.
Full
Apply discount within limit
Discounts at or below the role threshold.
Limited
Approve above-limit discount
Recorded decision for out-of-policy discounts.
None
Refund a sale
Issue a refund referencing the original invoice.
None
Cancel / void a bill
Cancel a sale without deleting history.
Limited
Manage products and prices
Create, edit, or reprice products.
None
Manage employee accounts
Create staff logins and change roles.
None
Adjust inventory
Record counts, adjustments, and damage.
None
Transfer stock between locations
Move stock between stores.
None
Close the day / approve variance
Close shifts and approve day-end records.
None
View employee-wise reports
See who billed, approved, or cancelled.
None
Export data / access audit log
Export records and review the audit trail.
None
Illustrative role matrix for planning. The actual permission surface depends on the deployed product configuration, and sensitive actions should always be auditable.
Design permissions around the work
Give each role only the permissions the work requires. Routine sales stay fast, exceptions route for approval, and sensitive actions stay auditable. This is the difference between a controlled counter and an uncontrolled one.