User Accounts & Roles

GSK POS Documentation | User Management
Last Updated: November 23, 2025 | Applies to: GSK POS Cloud System (gskpos.com) | Status: ✅ Code Verified | Chapter: Security & Access Control

Overview

User Accounts are the foundation of security in GSK POS. Each person who accesses your system needs their own account with an appropriate role that defines what they can do.

What you'll learn:

  • Using the modern user card interface
  • Creating and managing user accounts
  • Activating and deactivating users
  • Understanding roles and permissions
  • Editing and deleting users
  • Best practices for user management

Why it matters:

  • Security - Control who accesses your business data
  • Accountability - Know who did what
  • Efficiency - Give staff appropriate access
  • Audit Trail - Track all user actions

The User Management Interface

GSK POS features a modern split-view interface for managing users:

Left Panel - Add New User

Form to create new user accounts

  • Email field
  • Password field
  • Role selection
  • Phone (optional)

Right Panel - User Cards

List of all users as cards

  • Avatar icon
  • Email/Username
  • Role badge
  • Status badge
  • Action buttons

Status Badges

  • ✅ Active (green) - User can log in and use the system
  • 🚫 Inactive (red) - User cannot log in (account suspended)
  • 🛡️ Protected - Admin account - cannot be modified

Statistics Header

At the top of the user list, you'll see:

  • Total Users - Count of all accounts
  • Active Users - Count of users who can log in

What Are User Accounts?

A user account represents an individual person who can log into GSK POS. Each account consists of:

Required Information:

  • Username - Unique login identifier (e.g., "john", "mary", "cashier1")
  • Password - Secure authentication credential
  • Role - Defines permissions and access level

Optional Information:

  • Email - For notifications and password resets
  • Phone - Contact information

What Are Roles?

A role defines what a user can do in the system. Think of roles as job titles with specific permissions attached.

**Common Roles**

Admin 👑

  • Full system access
  • Can manage users and permissions
  • Access all features and reports
  • Use for: Business owner, IT manager

Manager 👔

  • Most business operations
  • Process sales and purchases
  • View reports
  • Manage customers and suppliers
  • Cannot manage users or change critical settings
  • Use for: Shop managers, supervisors

Cashier 💰

  • Sales processing only
  • Add customers
  • View stock levels
  • Cannot access reports or settings
  • Use for: Front desk staff, sales clerks

Stock Clerk 📦

  • Inventory management
  • Process purchases
  • Adjust stock
  • Manage suppliers
  • Cannot process sales
  • Use for: Warehouse staff, inventory managers

Accountant 📊

  • Read-only access to reports
  • View financial data
  • Export reports
  • Cannot modify transactions
  • Use for: Accountants, auditors

Creating a New User

**Prerequisites**

  • ✅ You must be Admin or have "User Management" permission
  • ✅ Decide username, temporary password, and appropriate role

**Step-by-Step Process**

Step 1: Access User Management

  1. Log into GSK POS
  2. Click "User Accounts" in the sidebar menu
  3. User registration form appears

Step 2: Enter User Information

Username (Required)

  • Any name you prefer
  • Must be unique in your system
  • No special format required
  • Examples: john, mary_smith, cashier1, manager_kampala
  • Tips:
  • Use first names for small teams
  • Add numbers for multiple people with same name
  • Use role-based names for generic accounts

Password (Required)

  • Any length accepted (8+ characters recommended)
  • User should change after first login
  • Make it memorable but secure
  • Examples: Welcome123, TempPass2024
  • Tips:
  • Don't use the same password for everyone
  • Include numbers and symbols
  • Avoid common words

Role (Required)

  • Select from dropdown menu
  • Choose based on job responsibilities
  • Available roles:
  • Admin (full access)
  • Manager (most features)
  • Cashier (sales only)
  • Stock Clerk (inventory only)
  • Accountant (reports only)
  • Custom roles (if configured)

Email (Optional)

  • Valid email format required if provided
  • User receives welcome email with login details
  • Example: john@example.com
  • Benefits:
  • Automatic welcome email
  • Password reset capability
  • System notifications

Phone (Optional)

  • Any format accepted
  • For contact purposes only
  • Examples: +256700123456, 0700123456

Step 3: Create Account

  1. Review all information
  2. Click "Create User" button
  3. System validates:
  • Username doesn't already exist
  • Email format is correct (if provided)
  • All required fields completed
  1. Success message appears
  2. If email provided, welcome email sent automatically

Step 4: Welcome Email Sent

The new user receives an email with:

  • Welcome message
  • Their username
  • Their temporary password
  • Link to login at gskpos.com
  • Instructions to change password
  • Link to video tutorials

Step 5: Inform the User

  • Give them username and password (if no email)
  • Tell them to change password on first login
  • Show them how to access the system
  • Explain their role and what they can do
  • Provide link to documentation

Viewing All Users

**Access User List**

Method 1: View All Users Button

  1. Go to User Accounts menu
  2. Click "View All Users" button
  3. Complete user list displays

Method 2: After Creating User

  • List automatically shows after user creation
  • Refresh to see latest changes

**Information Displayed**

The user list shows:

ColumnDescription
UsernameLogin identifier
EmailContact email (or "N/A" if not provided)
PhoneContact number (or "N/A" if not provided)
RoleCurrent role with dropdown to change
ActionsEdit and Delete buttons

Special Cases:

  • "admin" user - Cannot be edited or deleted (system protection)
  • Your own account - Cannot delete yourself
  • Inactive users - Show normally (no separate inactive status)

Editing an Existing User

**What Can Be Changed**

  • ✅ Email address - Update contact information
  • ✅ Phone number - Update contact information
  • ✅ Role - Change user's permissions
  • ❌ Username - Cannot change (permanent identifier)
  • ❌ Password - Users change their own passwords

**How to Edit**

Step 1: Open User List

  1. Go to User Accounts
  2. Click "View All Users"
  3. Locate user to edit

Step 2: Make Changes

Edit Email:

  1. Click in email field
  2. Type new email address
  3. Press Enter or click outside field
  4. Changes save automatically

Edit Phone:

  1. Click in phone field
  2. Type new phone number
  3. Press Enter or click outside field
  4. Changes save automatically

Change Role:

  1. Click role dropdown
  2. Select new role
  3. Changes apply immediately
  4. User's permissions update automatically

Step 3: Finalize

  1. Click "Edit" button to save all changes
  2. Or changes save automatically on field exit
  3. Confirmation message appears
  4. User list updates

**Role Change Impacts**

⚠️ Consider before changing roles:

Promoting (More Access):

  • Cashier → Manager
  • Gains: Report access, settings, more features
  • Can now see financial data
  • Stock Clerk → Manager
  • Gains: Sales processing, reports
  • Can now interact with customers
  • Any → Admin
  • Gains: Full system access
  • Very powerful - be careful!

Demoting (Less Access):

  • Manager → Cashier
  • Loses: Reports, settings, some features
  • May lose access to current work
  • Admin → Manager
  • Loses: User management, critical settings
  • Consider implications carefully
  • Manager → Stock Clerk
  • Loses: Sales, reports
  • Limited to inventory only

Best Practice: Inform user before changing their role so they understand what changes.

Activating & Deactivating Users

Instead of deleting users, you can deactivate them temporarily. This is useful when:

  • Employee is on leave
  • Temporary suspension needed
  • Want to keep their history but prevent access

How to Toggle User Status

To Deactivate (Active → Inactive)

  1. Find user card (green "Active" badge)
  2. Click Toggle button (circle icon)
  3. Confirm the action
  4. Badge changes to red "Inactive"
  5. User can no longer log in

To Reactivate (Inactive → Active)

  1. Find user card (red "Inactive" badge)
  2. Click Toggle button (check icon)
  3. Confirm the action
  4. Badge changes to green "Active"
  5. User can log in again
Benefits Over Deleting:
  • Can be undone - Reactivate anytime
  • History preserved - All records remain
  • Quick to reactivate - No need to recreate account
  • Safer choice - Use for temporary changes

Deleting a User Account

**When to Delete**

  • ✅ Delete when:
  • Employee permanently leaves company
  • Account created by mistake
  • Temporary account no longer needed
  • Security breach requires recreation
  • ❌ Don't delete if:
  • Employee on temporary leave (consider disabling instead)
  • You need historical activity records
  • Unsure - ask first!

**Important Warnings**

  • 🚨 Deletion is permanent and cannot be undone!

What happens when you delete:

  • User immediately cannot log in
  • Account removed from user list
  • Historical activity logs remain (for audit)
  • Username can be reused for new account
  • All past transactions still show their username

What doesn't happen:

  • Past sales/purchases are NOT deleted
  • Reports still show their name
  • Activity logs remain intact

System Protections:

  • Cannot delete "admin" account
  • Cannot delete your own account
  • Must have proper permissions to delete

**How to Delete**

Step 1: Confirm Decision

  • Are you sure?
  • Have you informed management?
  • Is there a better alternative?

Step 2: Access User List

  1. Go to User Accounts
  2. Click "View All Users"
  3. Find user to delete

Step 3: Delete User

  1. Click "Delete" button next to username
  2. Confirmation dialog appears:
  • "Are you sure you want to delete [username]?"
  • "This action cannot be undone"
  1. Click "Yes, Delete" to proceed
  2. Click "Cancel" to abort

Step 4: Verify Deletion

  • Success message: "User deleted successfully"
  • User disappears from list immediately
  • They cannot log in anymore
  • Refresh page to confirm

Step 5: Post-Deletion Tasks

  • Inform relevant staff
  • Update contact lists
  • Reassign responsibilities
  • Document reason for deletion (for records)

Best Practices

**Security Best Practices**

  • 🔐 One Account Per Person
  • Never share accounts
  • Each person needs unique username
  • Enables accountability
  • Required for audit trail
  • 🔐 Appropriate Roles
  • Match role to job function
  • Don't make everyone admin
  • Use least privilege principle
  • Review roles quarterly
  • 🔐 Immediate Offboarding
  • Delete account on employee's last day
  • Don't wait "just in case"
  • Change shared passwords if they had access
  • Review their recent activity
  • 🔐 Strong Passwords
  • Enforce minimum 8 characters
  • Require mix of letters/numbers
  • Change every 90 days
  • Never reuse old passwords
  • 🔐 Limited Admin Accounts
  • Only 2-3 admins maximum
  • Business owner should be one
  • IT/tech manager can be another
  • Review admin list monthly

**Operational Best Practices**

  • ✅ Consistent Naming
  • Use standard username format
  • Examples:
  • First name: john, mary
  • Role + number: cashier1, cashier2
  • Location: kampala_john, jinja_mary
  • Easier to manage as you grow
  • ✅ Onboarding Process
  1. Create account day before start
  2. Send welcome email
  3. Personal walkthrough on first day
  4. Show password change process
  5. Explain role and permissions
  6. Provide documentation link
  7. Check in after one week
  • ✅ Regular Audits
  • Monthly: Review user list
  • Remove departed employees
  • Check roles still appropriate
  • Look for unused accounts
  • Document any changes
  • ✅ Documentation
  • Keep list of all users
  • Document role assignments
  • Note why each role chosen
  • Record changes and dates
  • Maintain offboarding records

**Training Best Practices**

  • 📚 Initial Training
  • Show them their accessible features
  • Explain what they can/cannot do
  • Demonstrate password change
  • Provide documentation
  • Assign mentor for questions
  • 📚 Ongoing Support
  • Regular check-ins
  • Additional training as needed
  • Update on system changes
  • Encourage questions
  • Share tips and tricks
  • 📚 Role-Specific Training
  • Cashiers: Focus on POS
  • Stock clerks: Focus on inventory
  • Managers: Comprehensive overview
  • Admins: Full system training

Troubleshooting

**Cannot Create User - Username Exists**

Error: "Username already exists. Please choose a different one."

Cause: Another user (current or past) already has that username

Solutions:

  • Add number: john → john2
  • Add location: john → john_kampala
  • Use different format: john → j.smith
  • Try variations until unique found

**Cannot Create User - Email Exists**

Error: "Email already exists"

Cause: That email is registered to another account

Solutions:

  • Use different email
  • Leave email blank (optional field)
  • Check if person has multiple accounts
  • Remove email from old account first

**User Cannot Login After Creation**

Possible Causes:

Wrong Password

  • User typing incorrectly
  • Caps lock enabled
  • Password contains special characters they're missing

Wrong Username

  • Username may be case-sensitive
  • Extra spaces
  • Typo

Account Not Created

  • Check user list to verify
  • Try creating again

Browser Issues

  • Clear cache
  • Try different browser
  • Use incognito mode

**Cannot Delete User**

"admin" User

  • Protected system account
  • Cannot be deleted
  • This is intentional

Your Own Account

  • Cannot delete yourself
  • Another admin must do it
  • Security feature

No Permission

  • You need admin or user management permission
  • Ask admin to delete

**Role Change Not Working**

User Can't See New Features

  • User needs to log out and back in
  • Or refresh page
  • Permissions update on new session

Changes Don't Save

  • Check internet connection
  • Try again
  • Contact support if persists

Wrong Role Selected

  • Verify correct role in dropdown
  • Check role has expected permissions
  • Role configuration may need adjustment

Summary

User Accounts & Roles are the foundation of GSK POS security:

  • ✅ Create accounts - One per person, appropriate role
  • ✅ Manage carefully - Edit when needed, delete when necessary
  • ✅ Follow best practices - Security first, accountability always
  • ✅ Regular audits - Monthly reviews keep system clean

Key Takeaways:

  • Every person needs their own account
  • Roles define what users can do
  • Admin role is most powerful - limit carefully
  • Delete departed employees immediately
  • Document everything for audit trail

What's Next?

Continue learning about user management:

  • Permissions System - Understanding how access control works
  • Change Password - Keeping accounts secure
  • User Activity Tracking - Monitoring system usage

Next: Permissions System

Learn how access control and permissions work in GSK POS.

Next: Permissions System →

Next: Sales & Purchase Reports

Learn how to generate detailed and summary reports for all your sales and purchase transactions.

Next: Sales & Purchase Reports →

Next: Purchases & Stock In

Learn how to record purchases from suppliers and increase your stock levels.

Next: Purchases & Stock In →