Cashier using a point-of-sale terminal during a supermarket sale
Back to blog
POS Controls

Cashier Permissions: What Staff Should and Should Not Be Able to Do

Trust matters, but so do clear limits. Decide who may void sales, refund payments, change stock, approve discounts or export reports as a shop grows from one trusted cashier to a larger team.

Published: 4 August 2026 Read: 11 min read Author: Maduuka Operations Team Reviewed: 4 August 2026

A cashier spots a mistake after payment while the customer and the queue are waiting. Can the cashier void the sale? Must a manager approve the refund? If the same login can also change stock, export reports, and alter user roles, a small correction can become an untraceable business problem.

Good permissions do not treat every employee as dishonest. They give staff enough authority to serve customers quickly, then place a clear checkpoint around actions that move money, rewrite completed history, change stock, or expose business-wide data.

A practical cashier permission matrix

Use this as a starting point, then adjust thresholds and roles to the size of the shop. The system should deny unassigned actions by default rather than relying on a verbal rule.

A practical cashier permission matrix
ActionCashierManagerOwner, finance, or admin
Create a sale, take payment, and issue a receipt Allow Allow Allow or view
Correct quantity before payment Allow with a reason where material Allow Review exceptions
Void a completed sale or process a refund Request or allow only within a written limit Approve within threshold Set policy and review high-risk cases
Apply a discount or override a price Published offers only Approve exceptions Set price and margin rules
Adjust, write off, or backdate stock No Request or approve by policy Authorise and review evidence
View own shift and till totals Allow at the right stage of cash-up View branch totals View consolidated totals
Export full sales, customer, or audit reports No Limited branch export if needed Restricted named roles only
Create users or change roles and permissions No Request Admin action with independent approval

Permissions protect honest staff as well as the owner

The Association of Certified Fraud Examiners' 2024 global study found that 32% of the occupational fraud cases in its dataset involved a lack of internal controls, while 19% involved an override of existing controls. That does not mean every shop has the same risk. It does show why an override must be visible and reviewable instead of becoming a shared password or a quiet favour at the till.

A clear role boundary also protects the cashier. When a refund carries the manager's approval and the original sale remains visible, responsibility does not depend on memory or accusation. The record shows who requested the action, who approved it, and what changed.

Manager and staff member reviewing a sensitive action together on a business computer

Give each person a login and only the access the job needs

Do not let a whole shift trade under one cashier account. Unique accounts make ordinary work attributable and allow access to be removed when a staff member changes role or leaves. Where cardholder data is in scope, PCI DSS bases access on job need and generally requires individual accountability, while documenting a narrow exception for certain POS accounts used for only one card transaction at a time. Its scope is payment-card security, not every retail action.

NIST describes least privilege in the same practical way: allow only the access needed for assigned tasks, review it, and remove or reassign rights that are no longer needed. For a cashier, that means selling is normal access. Editing permissions, changing system settings, or opening every company's report is not.

Cashier working at her own point-of-sale session

A void or refund must correct history, not erase it

Before payment, a cashier may need to remove a wrongly scanned line or correct quantity. After payment, the action has a different consequence: cash, mobile money, card settlement, tax records, customer balance, and stock may already have moved. Treat a completed-sale void or refund as a controlled correction linked to the original transaction.

Require a reason, the original receipt or sale reference, the amount, the person requesting the change, and the approver. Do not expose a normal Delete button for a completed sale. A manager override should approve the specific action; it should not give the cashier a reusable manager session.

Café cashier holding a payment terminal at the counter

Discounts and stock changes need different boundaries

A cashier can apply a promotion that the business has already approved. An improvised discount, manual price override, or sale below a margin rule needs a different permission. Set percentage or amount thresholds in the business policy, not in the article: a threshold suitable for a kiosk may be meaningless in a hardware shop or pharmacy.

Stock adjustments are more sensitive than correcting an open basket. A sale should reduce stock through the normal transaction flow. Damage, expiry, write-off, count variance, or backdated stock changes need a reason and evidence, then review by the role responsible for inventory. Otherwise, a user who can refund a sale and adjust stock can make both the cash and the product disappear from the story.

Reports, exports, and role changes are not cashier tools

A cashier may need an own-shift total during close, but not the full payroll, customer export, profit report, audit log, or consolidated branch performance. Report access should follow the same need-to-know rule as transaction access. Limit branch managers to the branches they manage and reserve broad exports for named owner, finance, audit, or data-administration roles.

User creation and permission changes need their own control. An administrator may configure accounts, but should not silently grant themselves authority to approve refunds or financial corrections. Review role assignments when somebody joins, changes job, leaves, or temporarily covers another branch.

A manager override should be narrow, named, and reviewable

The safe override is a moment, not a password handover. The cashier starts the restricted action, the manager authenticates, sees the sale and reason, approves or rejects that one request, and the cashier returns to ordinary access. Maduuka supports supervisor PIN verification for this kind of step-up action and records both users in the audit trail.

Review overrides as an exception report. Repeated voids by one user, refunds just below a threshold, frequent manual discounts, cash-drawer openings without a sale, and stock adjustments after close all deserve a manager's attention. The report is a prompt to investigate, not automatic proof of wrongdoing.

Process: Set up permissions without slowing the till

1

List real shop tasks

Write down what staff do during sale, payment, correction, refund, cash-up, stock handling, reporting, and user administration.

2

Group tasks into roles

Start with cashier, supervisor or manager, inventory, finance or owner, and administrator. Avoid creating a different role for every person.

3

Mark sensitive actions

Flag actions that move money, change completed records, alter stock, expose broad data, or grant new access.

4

Set approval rules

Choose which actions are blocked, requested, allowed within a written threshold, or approved by a second person.

5

Test the exception path

Run a wrong scan, refund, discount, stock variance, report export, and manager override before staff use the setup with customers.

6

Review access regularly

Check permissions after role changes and departures, then review override and exception reports at a cadence the owner can sustain.

Controls: Cashier permissions checklist

  • Every staff member uses a unique account; shared cashier passwords are not accepted.
  • Cashiers can complete ordinary sales, payments, receipts, and their own till session.
  • Completed-sale voids and refunds link to the original sale and retain a reason.
  • Discounts and price overrides follow written rules and approval thresholds.
  • Stock adjustments, write-offs, and backdating require a separate inventory control.
  • Cash-drawer openings, cash variances, and session reopens are logged and reviewed.
  • Cashiers see only the reports needed for their work; broad exports are restricted.
  • Managers approve one action without sharing a password or leaving an elevated session open.
  • User and role changes are limited to administration and independently reviewed where they grant financial power.
  • Audit records show the actor, approver, time, original transaction, reason, and before-and-after effect.
  • Departed or transferred staff lose old access promptly.
  • Exception reports guide investigation; they are not treated as automatic proof of misconduct.

Common questions

A cashier can request a refund and may process one within a documented low-risk limit if the business chooses. The refund should still link to the original sale, retain a reason, and enter the manager's review queue.
No. The manager should enter the PIN privately for the specific approval. Sharing it turns future cashier actions into apparently authorised manager actions and weakens the audit trail.
Yes. Keep daily cashier access separate from owner-level configuration. If a second person cannot approve each exception, use compensating controls: owner review of voids and refunds, an independent cash count, periodic stock checks, and prompt access removal when duties change.
They may need their own till or shift total during cash-up. Consolidated profit, all-branch performance, customer exports, payroll, and audit reports usually belong to manager, owner, finance, or audit roles.
For a sensitive action, retain the user, role, date and time, device or session where useful, original transaction, reason, before-and-after values, approving user, and result.

Sources and institutions worth crediting

  • ACFE - Occupational Fraud 2024: A Report to the Nations: Global case-study evidence on control weaknesses; the 32% lack-of-controls and 19% control-override figures describe the report's dataset, not a forecast for a particular shop.
  • NIST SP 800-53 Release 5.2.0 - AC-5 and AC-6: Current primary standards catalogue for separation of duties, least privilege, periodic access review, and logging privileged functions.
  • PCI Security Standards Council - PCI DSS v4.x: Primary payment-card standard for job-based access, least privilege, approved access, and individual accountability where cardholder data is in scope; it is not a universal cashier-rule source and includes a narrow POS-account exception.
  • COSO - Internal Control Integrated Framework: Executive Summary: Professional framework supporting approvals, reconciliations, reviews, segregation of duties, and compensating controls when a small entity cannot fully separate tasks.
  • Maduuka - How Maduuka Protects Your Business Data: First-party product basis for granular POS permissions, supervisor PIN verification, and audit logging; it is product evidence, not independent control research.
  • Chwezi Accounting & Finance Doctrine - Internal controls: Local implementation doctrine used for maker-checker, refunds, stock adjustments, administrator boundaries, audit evidence, and no deletion of posted history.

Give every staff member the right level of access

Maduuka lets growing retailers separate ordinary cashier work from refunds, discounts, stock changes, reports, and manager approvals without turning the till into a paperwork exercise.