In a system where every employee can do every action, mistakes and misuse both become easy. The answer is to define clearly who can do what.
Role-based permissions
Adisyon Merkezi has three roles: owner, manager and waiter. A waiter sees only the order and payment screens; reports and settings belong to the authorised roles.
Where does PIN approval come in?
Sensitive actions such as discounts and cancellations can require an authorised person's PIN. That way a waiter can't complete the action alone; a manager or the owner approves it.
Practical tips
- Keep the PIN limited to authorised people and change it regularly.
- Explain to waiters their roles and limits clearly.
- Put the discount and complimentary policy in writing.
- Review the audit log regularly.
The audit log
Important actions are recorded with who did them and when. When something doesn't add up, you can look back and investigate.
The aim isn't to restrict employees but to protect both the business and the employee: when every action is traceable, arguments go down.