Who can do this?
Owners and Managers and Staff can use the parts described here. Store-wide management of other devices remains limited to Owners and Managers; self-service for the current device and read-only list access have different scopes. API authorization is authoritative.Where
Owners and Managers use Devices in web Admin or Store devices in native Settings. Staff do not see those management links and receive a restricted message if they reach the web route. Staff-facing operational flows can still query POS-device targets where needed.Steps
- Treat the API rule as the authorization truth: Staff store membership permits list reads.
- Treat the UI rule as the supported product experience: Staff are not offered general device management.
- Staff may update or delete their own registered device through self-service endpoints, but cannot use manager operations on arbitrary team devices.
- Owners and Managers can list, mark POS state, and remove store devices through the management UI.
- Document or report the navigation/API mismatch rather than promising Staff a hidden management page.