Skip to main content
The current navigation and authorization do not fully agree. A Staff user can encounter a Staff link, but the employee list and administration APIs require Owner or Manager. Documentation follows the enforced API permission.

Who can do this?

Frontmatter roles list everyone affected by the flow. Administration is server-limited to Owners and Managers; Staff may perform only the explicitly described joining or access flow.

Where to do it

Use Staff in the Management web app for lists, profiles, and administration. Invitations take new users into the staff signup flow. The Management mobile app has corresponding team, detail, invite, and join screens.

Steps

  1. If your role is Staff, do not use the Staff page to manage team records. Use only operational pages authorized for Staff.
  2. If the Staff link is visible, selecting it does not grant access. A forbidden or failed data load is expected when the API checks the Staff role.
  3. Ask an Owner or Manager to view profiles, invite people, edit details, change roles, reassign memberships, or remove members.
  4. If you believe your role is wrong, ask an authorized administrator to inspect your membership in the selected store.
  5. After a legitimate role change to Manager or Owner, refresh or sign in again and confirm the selected store before reopening Staff.

Platform notes

Roles are store-specific and checked by the API. Web and mobile share the same memberships; a visible control does not replace permission. After a change, refreshing or signing in again may be needed for locally held navigation and store context to catch up.

Market notes

The same roles and flows apply in GB and Germany. Language and contact formatting are localized, but the Owner → Manager → Staff hierarchy and safeguards do not change by market. This guide reflects the product on 17 July 2026. When navigation and the server response disagree, the API rule is authoritative; it prevents a visible surface from creating extra permission.

Troubleshooting

  • Do not repeatedly retry a forbidden request or assume the employee service is down. First verify the role returned for the selected store.
  • This mismatch should be treated as a product navigation issue, not as permission to bypass the API. Support should record the visible-link context while preserving the enforced role boundary.