We moved

kiosk.co.ke is now kiosk.ke — your shop has a new address. See what changed

Staff & branches

User roles & how to add users

Invite staff, pick the right role, assign branches and departments, and manage PINs and access — with screenshots of every screen.

Updated 2026-08-244 min read7 sections6 FAQ

Users are the people who can sign in to your workspace — at the dashboard, the till, or the grocery counter. A role decides what each person can see and do, and the branch narrows where they work. This guide walks through adding users, choosing roles, and managing access safely.

What is a role?

  • A role is a bundle of permissions — one choice in the invite drawer decides what the person can see across the whole workspace.
  • Owner sees and controls everything: users, roles, payment settings, billing, and branches.
  • Managers run the day-to-day shop: catalog, stock, suppliers, supplies, and reports.
  • Cashiers sell at the till. Branch-locked roles (cashier, stock manager, grocery clerk) can only work in their assigned branch.
  • Stock managers handle stock levels, supplies, and stock takes — with optional toggles in Business → Operations.
  • Grocery clerks get a kiosk-friendly counter and only the departments you assign to them.

Step 1 — Invite a user

  1. Step 01Open Users in the dashboard and tap Invite user.
  2. Step 02Enter the full name and a unique work email.
  3. Step 03Pick the Role — owner, manager, cashier, stock manager, grocery clerk, and more.
  4. Step 04Pick the Branch, or leave it blank for someone who works everywhere (owners and managers usually).
  5. Step 05Choose the sign-in method: Email invite sends them a secure link to set their own password, or PIN creates a 4–6 digit till code for cashier-style access.
  6. Step 06Tap Create user. Email-invited people show as Invited until they finish setup; PIN users are active right away.
Invite user drawer with full name Jane Doe, email, Cashier role, Main branch, and the sign-in method dropdown open showing Email invite and PIN options
The invite drawer: name, role, branch, and how they sign in — all in one step.

Step 2 — Manage the directory

The Users page is a live directory. Every row shows the person, their role, departments, branch, status, and the actions you can take — all without opening a separate page.

  • Filter by status (active, invited, suspended, locked), role, or branch to find anyone fast.
  • Edit a name, change a role, or move someone to another branch with the pencil icons on the row.
  • Grocery clerks show a Departments column — assign the sections they are allowed to see.
  • Actions cover credentials and access: set a password, set or view a PIN, sign the person out of every device, or deactivate them.
Users directory table with filters for status role and branch, rows for cashier stock manager grocery clerk owner and an invited user, status badges, and row actions
The directory — one row per person, with role, branch, status, and access actions.

Deactivate vs sign out — what is the difference?

  • Sign out of all devices revokes every live session but keeps their password and PIN working — they can sign straight back in. Use it when a phone or till was left unattended.
  • Deactivate is the strong move: the person loses access on every device until someone re-invites them. Use it when someone leaves or their access is being reviewed.

PIN login for the till

  1. Step 01Make sure the user has a branch assigned (PIN login is branch-scoped).
  2. Step 02Set a 4–6 digit PIN — either when inviting, or later from the row actions (the # icon).
  3. Step 03Cashiers unlock a shared till with their PIN instead of typing a long password.
  4. Step 04Forgot a PIN? An admin can view it from the row (👁 icon) or set a new one.

Departments for grocery clerks

Grocery clerks only see the departments you assign. Until an admin assigns at least one department, the clerk’s counter shows no items — assign departments right after creating the account, or when changing their role.

Security checklist

  • One login per person — never pass around shared credentials.
  • Assign the least privilege that works: cashiers sell, managers run, owners own.
  • Deactivate leavers the same day, and sign out devices that were left behind.
  • Keep PINs private; don’t write them on the till.
  • Review the directory monthly — role drift creeps in as the shop grows.

Frequently asked

Which role should a new cashier get?
Cashier — it is scoped to selling at the till in one branch. Promote to manager later if they also need catalog, stock, and supplier access.
Can I change someone's role later?
Yes. Tap the pencil next to their role in the directory, pick the new role, and save. The change applies on their next action — no re-invite needed.
A cashier forgot their PIN — what do I do?
From the row actions, the # icon lets you view their current PIN (it is stored viewable for recovery) or set a brand-new one.
What is the difference between deactivate and delete?
Deactivate blocks access until re-invited while keeping history attached to the person. Users are not deleted outright — history stays attributable to the right account.
My grocery clerk sees no products — why?
Grocery clerks only see assigned departments. Open their row, assign at least one department (e.g. Grocery, Produce), and save.
An invited user never got the email — can I resend?
Deactivate and re-invite, or set a password for them from the row actions and share the sign-in details securely. Confirm the email is spelled correctly first.

Related articles

Still stuck setting up?

Send a message with your business name and subdomain — we will help you get the till selling.