Access (groups & policies)
Control who can do what, and at which locations.
GreenSails lets you decide who can do what, and often at which locations. It sits on top of member base roles: roles set the baseline, while policies and groups add the details.
Access management lives under Settings → Organization → Access and
requires iam:view to browse and iam:manage to create or edit groups and
policies. To attach access to a person, open Settings → Organization →
Members and choose Manage access (also requires iam:view).
The building blocks
Policy
A reusable document of allow/deny statements over actions, optionally scoped to locations.
Group
A named bundle of policies. Add members to a group and they inherit every policy attached to it.
Member access
Attach groups or individual policies directly to one member from the Members list.
The Access page has two tabs, Groups (default) and Policies. Create policies first, attach them to groups, then add members to those groups. For one-off grants, skip the group and attach policies directly to the member.
Base roles first
Before groups and policies, each member has a base role:
| Role | Baseline access |
|---|---|
| Owner | Implicit superuser, all permissions, cannot be restricted by deny policies. |
| Admin | Nearly full back-office access; excludes org:delete and org:manage-billing. |
| Member | No baseline permissions. A newly invited member can do nothing until you grant groups or policies. |
| Service | Fixed operational baseline for service accounts (catalog read, orders, stock counts, menu availability, KDS). Not used for human dashboard users. |
Use Member as the default invite role, then grant Inventory Managers, Cashiers, or custom policies. Admins already inherit broad access; groups are most useful for Members and for narrowing Admin access at specific locations.
How policies work
A policy contains one or more statements. Each statement has:
- Effect: Allow or Deny
- Actions: Specific permissions (e.g.
orders:view,menu-boards:manage) or*for every action - Locations: For location-scoped actions, which venues the statement applies to (
All locationsor a picked subset). Ignored for org-wide actions.
When you edit a policy, the statement editor groups actions the same way as the product UI (Organization, Members, Inventory Items, Stock Taking, Orders, and so on).
Deny always wins. If any applicable statement denies an action, the user is blocked, even when another policy allows it. Use deny statements sparingly to carve exceptions out of broad allows.
Location scoping
Only certain permissions can be limited to specific locations. For everything else, location picks in a statement are ignored and the grant applies organization-wide.
Location-scoped (you can restrict to selected venues):
| Area | Permissions |
|---|---|
| Local stock | stock-counts:view, stock-counts:upsert, stock-counts:delete |
| Snapshots & counts | stock-snapshots:view, stock-snapshots:create, count-sessions:view, count-sessions:create, count-sessions:close |
| Purchasing | purchase-orders:view, purchase-orders:create, purchase-orders:update, purchase-orders:receive, purchase-orders:cancel |
| Transfers | transfers:view, transfers:create, transfers:ship, transfers:receive, transfers:cancel |
| Orders | orders:view, orders:create, orders:settle, orders:split |
| Locations | locations:view, locations:update, locations:delete |
| Menu boards | menu-boards:view, menu-boards:set-availability |
| Kitchen display | kds:view, kds:manage |
| Analytics | analytics:view |
Organization-wide (location scope has no effect):
- Catalog: items, item categories, modifier groups, location categories,
locations:create - Stock taking & intelligence:
stock-taking:*,inventory-alerts:*,inventory-reports:view - Billing: all
invoices:*andcontracts:*actions - Administration: members, service accounts, settings, audit logs, access control, org settings
- Other:
menu-boards:manage,shifts:view,uploads:create
Example: a regional supervisor might get orders:view and menu-boards:set-availability at three stores only. An invoice clerk gets invoices:* org-wide with no location picker.
Permission reference
The tables below mirror the action picker in the policy editor. Grant the minimum set each role needs.
Organization & administration
| Actions | Typical use |
|---|---|
org:update, org:delete, org:manage-billing | Organization profile, billing account, and Tax & compliance (regime, inclusive prices, service charge, TCC policy) |
members:view, members:invite, members:remove, members:update-role | Members & invitations |
service-accounts:view, service-accounts:create, service-accounts:update, service-accounts:delete | Service accounts |
settings:view, settings:update | Invoice template, payment reminders, contract templates, terminals, KDS stations, operators, tags |
tags:view, tags:manage | Browse tag vocabulary, filters, and hub; create or edit tags |
audit-logs:view | Settings → Organization → Audit logs: see Audit Logs |
iam:view, iam:manage | View or edit groups and policies |
uploads:create | Logo and image uploads (catalog, invoices, locations) |
Catalog
| Actions | Typical use |
|---|---|
items:*, item-categories:* | Catalog → Items |
modifier-groups:* | Catalog → Modifier templates |
locations:*, location-categories:* | Catalog → Locations and categories |
stock-counts:view, stock-counts:upsert, stock-counts:delete | Per-location stock sheets (Catalog → Locations or inventory flows) |
Inventory operations
| Actions | Typical use |
|---|---|
stock-taking:view, stock-taking:configure | Count policies, schedules, variance rules (Inventory → Stock taking) |
stock-snapshots:*, count-sessions:* | Snapshots and count sessions |
purchase-orders:view | Vendors list, purchase order list and detail |
purchase-orders:create, purchase-orders:update | Create/edit purchase orders and vendors; create linked PO or vendor bill paperwork (with invoices:create) |
purchase-orders:receive | Check in stock against an ordered purchase order |
purchase-orders:cancel | Cancel draft or ordered purchase orders |
transfers:view | Transfer list and detail |
transfers:create | Create and edit draft transfers |
transfers:ship | Ship stock out of the source location |
transfers:receive | Check in stock at the destination location |
transfers:cancel | Cancel draft transfers |
inventory-alerts:view, inventory-alerts:acknowledge | Inventory → Alerts |
inventory-reports:view | Inventory → Reports |
See Inventory Overview, Vendors, Purchase orders, and Transfers for how these map to the sidebar.
Sell & kitchen
| Actions | Typical use |
|---|---|
orders:view, orders:create, orders:settle, orders:split | Sell → Orders and POS sync |
shifts:view | Sell → Shifts (org-wide) |
kds:view, kds:manage | Kitchen tickets and KDS station config |
menu-boards:view, menu-boards:manage, menu-boards:set-availability | Menu boards, templates, and on-the-fly availability |
Workforce
Workforce permissions split manager tools in the dashboard from self-service tools in the staff portal:
| Actions | Typical use |
|---|---|
workforce:view | Workforce section: schedule, employees, time cards, requests (read-only; hourly rates hidden) |
workforce:manage-employees | Create roster entries, enable portal access, view hourly rates, and edit overtime and punch policy |
workforce:manage-schedule | Build and publish shifts on the calendar |
workforce:manage-timecards | Review time cards, manager clock-in (with override reason), adjust breaks, and view hourly rates |
workforce:approve-requests | Approve or deny requests, and create time off or shift trades on behalf of staff |
workforce:view-self, workforce:clock-self, workforce:request-self | Staff portal: schedule, calendar sync, clock in, breaks, and submit requests |
See Workforce Overview and Staff Portal.
Billing & money
Invoice and contract actions are organization-wide:
| Actions | Typical use |
|---|---|
invoices:view | Invoices, quotes, receipts, credit notes, vendor bills, customers, recurring, batch, GCT-01 helper, Service charge pool |
invoices:create | New documents, generate-from-order, and create PO / vendor bill paperwork from Inventory |
invoices:update | Edit drafts, record payments (including on draft vendor bills), templates, reminders |
invoices:delete | Remove drafts or documents |
invoices:send | Email parties and manage portal access |
contracts:view, contracts:create, contracts:update, contracts:delete, contracts:send | Money → Contracts and e-signature |
Grant send separately from update when staff may prepare documents but only managers may deliver them.
Analytics
| Actions | Typical use |
|---|---|
analytics:view | Analytics dashboards and AI briefings (can be location-scoped) |
Groups: manage access at scale
A group bundles policies under a name like "Store Managers" or "Menu Editors." Assign members to the group and they inherit every attached policy. When responsibilities change, edit the group once instead of each member.
Create policies
On the Policies tab, define reusable allow/deny documents. Start from a system preset or build your own.
Build a group
On the Groups tab, create a group and attach the policies it should include.
Add members
Open the group detail dialog and add members, or assign the group from a member's Manage access dialog.
Per-member access
For one-off needs, open Settings → Organization → Members, click Manage access on a row, and attach groups or individual policies without creating a dedicated group.
Prefer groups over direct member policies for anything recurring. Groups keep access auditable and make onboarding a single assignment.
System presets
Every new organization is seeded with built-in system policies and groups. System policies show a System badge, are read-only, and cannot be deleted, duplicate their intent in a custom policy if you need changes.
System policies
| Policy | Purpose |
|---|---|
| ReadOnlyAccess | Read-only across catalog, orders, billing, settings, analytics, audit logs, KDS, and tags |
| FullAccess | Allow every action (*) |
| InventoryManager | Full catalog and stock-count management plus analytics and tag read |
| Cashier | Take and settle orders; read catalog, stock, and tags at assigned locations |
| KitchenDisplay | Operate KDS screens (kds:view, kds:manage) |
| InvoiceManager | Full invoices and contracts plus related catalog, order, and tag read |
| MemberManager | Invite, remove, and change member roles; manage access control |
| StaffPortal | Staff portal self-service (workforce:view-self, workforce:clock-self, workforce:request-self) |
System groups
| Group | Attached policies |
|---|---|
| Administrators | FullAccess |
| Inventory Managers | InventoryManager |
| Cashiers | Cashier |
| Invoice Managers | InvoiceManager |
| Read Only | ReadOnlyAccess |
| Staff | StaffPortal |
Attach KitchenDisplay, MemberManager, or StaffPortal policies directly to members or add them to custom groups when needed. There is no preset group for kitchen display operators.
How access is evaluated
When a member attempts an action, GreenSails combines:
- Their base role baseline (Admin/Member/Service additions; Owner bypasses checks)
- All policies on groups they belong to
- Policies attached directly to the member
The engine merges allows and denies, applies deny-overrides-allow, and checks location scope for location-bound permissions. Changes to roles, groups, or policies bump a permissions version so dashboard sessions and terminals pick up new access promptly.
What's next
Members & Invitations
Invite teammates and assign base roles before layering policies.
Teams
Location-scoped crews with shared access and leads.
Hardware Service Accounts
Machine identities with the Service role baseline.
Tags
Shared labels across invoices, contracts, customers, orders, and items.
Invoices & Documents
Grant billing permissions to finance and operations staff.
Audit Logs
Review organization activity by event, actor, and time.
Inventory Overview
Stock taking, snapshots, sessions, alerts, and reports.