Permissions System

GSK POS Documentation | User Management
Last Updated: November 23, 2025 | Applies to: GSK POS Cloud System (gskpos.com) | Status: ✅ Code Verified | Chapter: Security & Access Control

Overview

The Permissions System controls what each user can do in GSK POS. It's the security layer that prevents unauthorized access and ensures users only perform actions appropriate for their role.

Key Concepts:

  • Permissions = Specific actions users can perform
  • Roles = Collections of permissions
  • Access Control = System checking permissions before allowing actions

How Permissions Work

**Permission Flow**

Every action in GSK POS follows this flow:

`

  1. User attempts action (e.g., "Delete Sale")

↓

  1. System checks: Does user have required permission?

↓

  1. Check user's role for permission

↓

  1. If YES → Allow action ✅
  2. If NO → Show "Permission Denied" ❌

`

**Admin Bypass**

Admins bypass all permission checks:

  • Admin role has automatic access to everything
  • No need to assign individual permissions
  • Ultimate power - use carefully

Regular users:

  • Must have explicit permission for each action
  • Permissions inherited from their role
  • Cannot bypass security checks

Common Permissions

**User Management**

userManagement - Manage user accounts

  • Create new users
  • Edit existing users
  • Delete users
  • View user list
  • Who needs: Admin, HR Manager

manage_permissions - Configure permissions

  • Assign permissions to roles
  • Create custom roles
  • Modify role access
  • Who needs: Admin only (very powerful)

**Sales Operations**

Create Sales - Process sales

  • Access POS interface
  • Add items to cart
  • Complete transactions
  • Print receipts
  • Who needs: Cashiers, Managers

View Sales - View sales data

  • Access sales reports
  • View transaction history
  • Export sales data
  • Who needs: Managers, Accountants

Delete Sales - Remove transactions

  • Void completed sales
  • Undo transactions
  • Very sensitive permission
  • Who needs: Managers only (not cashiers)

**Purchase Operations**

Create Purchases - Record stock received

  • Add purchase transactions
  • Update inventory from purchases
  • Record supplier invoices
  • Who needs: Stock Clerks, Managers

View Purchases - View purchase data

  • Access purchase reports
  • View supplier transactions
  • Who needs: Managers, Accountants

**Inventory Management**

Manage Stock - Edit inventory

  • Add new products
  • Edit product details
  • Update pricing
  • Who needs: Stock Clerks, Managers

Stock Adjustments - Manual corrections

  • Adjust stock quantities
  • Record discrepancies
  • Very sensitive (can hide theft)
  • Who needs: Managers only

View Stock - View inventory

  • Check stock levels
  • View product list
  • Who needs: Everyone (usually)

**Customer & Supplier Management**

Manage Customers - Customer operations

  • Add/edit customers
  • View customer history
  • Manage customer debt
  • Who needs: Cashiers, Managers

Manage Suppliers - Supplier operations

  • Add/edit suppliers
  • View supplier history
  • Who needs: Stock Clerks, Managers

**Reporting**

View Reports - Access reports

  • Open reports menu
  • Generate reports
  • View analytics
  • Who needs: Managers, Accountants

Export Data - Download reports

  • Export to PDF/Excel
  • Download data
  • Who needs: Managers, Accountants

**System Settings**

Edit Settings - Change configuration

  • Modify system settings
  • Update business profile
  • Configure printing
  • Very sensitive
  • Who needs: Admin only

Permission Denied Errors

**What It Means**

"Permission denied" appears when you try to do something your role doesn't allow.

Example:

  • Cashier tries to view reports
  • System checks: Does Cashier role have "View Reports"?
  • Answer: No
  • Result: "Permission denied" message

This is not a bug - it's security working correctly.

**What to Do**

Step 1: Determine if you need access

  • Is this action required for your job?
  • Can someone else do it?
  • Is there an alternative approach?

Step 2: Request access (if needed)

  1. Talk to your manager
  2. Explain what you're trying to do
  3. Explain why you need access
  4. Manager contacts admin
  5. Admin evaluates request
  6. If approved, your role is updated
  7. Log out and back in to get new permissions

Step 3: If denied

  • Manager/admin had good reason
  • Accept decision
  • Find alternative solution
  • Escalate to owner if critical

Security Through Permissions

**Why Permissions Matter**

Prevent Mistakes:

  • New users can't accidentally delete data
  • Limited access reduces errors
  • Safer training environment

Prevent Theft:

  • Can't steal what you can't access
  • Clear audit trail
  • Accountability discourages dishonesty

Regulatory Compliance:

  • Access controls required by law
  • Auditors need proper permissions
  • Protect customer data

Business Continuity:

  • One compromised account can't destroy everything
  • Easier recovery from security incidents
  • Protected business operations

**Real-World Examples**

Scenario: Helpful Cashier

  • Cashier wants to help with inventory
  • Could accidentally delete products
  • Solution: Keep cashier limited to sales

Scenario: Stolen Manager Account

  • Manager password compromised
  • Thief can't access user management (admin only)
  • Solution: Limited damage, easier to recover

Scenario: Shared Password

  • Multiple people using one account
  • Can't tell who did what
  • Solution: Every person gets own account

Best Practices

**Principle of Least Privilege**

Give minimum permissions needed for job.

  • ✅ Right:
  • Cashier gets sales only
  • Stock clerk gets inventory only
  • Manager gets most features
  • Only owner/IT is admin
  • ❌ Wrong:
  • Making everyone admin "to be safe"
  • Giving unnecessary permissions
  • Sharing high-privilege accounts

**Regular Audits**

Monthly checklist:

  • Review all user roles
  • Remove unnecessary permissions
  • Add needed permissions
  • Delete departed employee accounts
  • Document changes

**Permission Matrix**

Create a table showing what each role can do:

| Role | Sales | Reports | Users | Settings | Stock |

|------|-------|---------|-------|----------|-------|

| Admin | ✅ | ✅ | ✅ | ✅ | ✅ |

| Manager | ✅ | ✅ | ❌ | ❌ | ✅ |

| Cashier | ✅ | ❌ | ❌ | ❌ | View |

| Stock Clerk | ❌ | ❌ | ❌ | ❌ | ✅ |

Benefits:

  • Clear expectations
  • Consistent access
  • Easy training
  • Clear escalation path

**Change Process**

Formal process for permission changes:

  1. Request: User/manager requests
  2. Justification: Explain why
  3. Approval: Manager/owner approves
  4. Implementation: Admin makes change
  5. Documentation: Record what/when/why
  6. Review: Check in 30 days - still needed?

Troubleshooting

**Permission Not Working After Role Change**

Solution: User must log out and back in for changes to take effect.

**Need Permission But Manager Says No**

Solution: Accept decision or escalate to business owner with strong justification.

**Permission Seems Wrong for Role**

Solution: Contact admin to review role configuration - may need adjustment.

Summary

Permissions are the keys to GSK POS features:

  • Control what users can do
  • Protect sensitive data
  • Enable accountability
  • Support compliance

Remember:

  • Admins bypass all checks
  • Regular users need explicit permissions
  • "Permission denied" is security, not error
  • Request access through proper channels

What's Next?

Continue learning about user management:

  • Change Password - Keeping accounts secure
  • User Activity Tracking - Monitoring system usage

Next: Change Password

Continue your learning journey.

Next: Change Password →

Next: Permissions System

Learn how access control and permissions work in GSK POS.

Next: Permissions System →

Next: Sales & Purchase Reports

Learn how to generate detailed and summary reports for all your sales and purchase transactions.

Next: Sales & Purchase Reports →

Next: Purchases & Stock In

Learn how to record purchases from suppliers and increase your stock levels.

Next: Purchases & Stock In →