Skip to main content
Tapp assigns a role for each store membership. The same person can therefore have different access in different stores. The API—not a visible menu item—is the final authority for every protected action.

Who can do this?

Frontmatter roles list everyone affected by the flow. Administration is server-limited to Owners and Managers; Staff may perform only the explicitly described joining or access flow.

Where to do it

Use Staff in the Management web app for lists, profiles, and administration. Invitations take new users into the staff signup flow. The Management mobile app has corresponding team, detail, invite, and join screens.

Steps

  1. Treat Owner as the highest store role. Owners can manage staff at every level, including inviting or changing Owners, subject to the final-owner safeguards.
  2. Treat Manager as the operational administration role. Managers can manage Managers and Staff, but cannot invite, modify, remove, reassign, or promote anyone as an Owner.
  3. Treat Staff as the day-to-day operations role. Staff can use authorized operational flows such as bookings, live floor, POS orders, and POS promotion redemption, but cannot administer Promotions, Guests, or Staff records.
  4. Check the role for the currently selected store before diagnosing access. Switching stores can also switch the user’s role.
  5. After a role change, have the affected person refresh or sign in again if the interface still reflects old access.

Platform notes

Roles are store-specific and checked by the API. Web and mobile share the same memberships; a visible control does not replace permission. After a change, refreshing or signing in again may be needed for locally held navigation and store context to catch up.

Market notes

The same roles and flows apply in GB and Germany. Language and contact formatting are localized, but the Owner → Manager → Staff hierarchy and safeguards do not change by market. This guide reflects the product on 17 July 2026. When navigation and the server response disagree, the API rule is authoritative; it prevents a visible surface from creating extra permission.

Troubleshooting

  • A sidebar link can be present even when its data request is forbidden. Promotion, Staff, and Guest administration endpoints require Owner or Manager, so link visibility never proves access.
  • Do not solve a permission error by sharing an Owner account. Ask an authorized Owner or Manager to perform the action or make an evidenced role change.