Skip to main content
Staff access is intentionally limited by the backend even though the current main navigation does not hide every Overview or Analytics entry point.

Who is affected?

This applies to users whose role for the selected shop is Staff. Owners and Managers are authorized for the advanced analytics endpoints.

Where to see it

In management web, the mismatch can appear from the main Overview link or a directly opened /analytics route. Check the selected shop and your role there before diagnosing the response.

What Staff can expect

  1. The side menu may display Overview because the main product-navigation list is not role-filtered item by item.
  2. Selecting it can cause the page to request summary data protected for Owners and Managers.
  3. Opening an /analytics route does not change the Staff role.
  4. The API checks the role stored for the selected shop and rejects analytics requests that are not from an Owner or Manager.
A visible link, a bookmarked URL or direct navigation therefore does not grant access. Do not interpret an authorization failure as missing sales data.

What to do instead

Use the operational pages available to your role, such as POS and authorized order-history functions. If your work genuinely requires business-wide analytics, ask an Owner to review your responsibilities and role. Do not share another person’s credentials. Some staff-performance API views elsewhere in the product scope Staff data to the authenticated person, but that does not make the separate advanced Analytics API available to Staff. That distinction protects store-wide aggregates. An endpoint that explicitly allows Staff can force its employee filter to the authenticated user; advanced Analytics instead checks for Owner or Manager before returning a domain report. Report misleading link visibility as a product issue rather than treating it as an access workaround.

Platform and market notes

The mismatch documented here is in management web navigation. API enforcement is the same for GB and Germany and remains the source of truth. Management mobile can arrange navigation differently, but it cannot override backend authorization.

Troubleshooting

If Staff receives an analytics authorization error, verify the selected shop and role. Retrying the same protected URL, changing the reporting period or switching interface language cannot grant access; an Owner must review whether a role change is appropriate.