Getting started

Roles and what each sees

Five roles, fourteen permissions. What each person can do, why the defaults are drawn where they are, and what changes on screen from one role to the next.

Every person holds one or more roles, and a role is a set of permissions. The server checks the permission on every action, and the screens show only what the signed-in person may do. Nobody is shown a door that is locked.

The five roles

RoleWhoWhat they do
Owner / AdminThe licence holder or the person who runs the shopEverything, including users and roles.
Licensed PractitionerThe registered OTCMS practitioner on the premisesRuns the shop's operations: sells, voids, receives, disposes, manages compliance. Cannot manage users.
Sales ClerkServes at the counterSells and looks at the shelf. Cannot void a sale.
Inventory ClerkReceives and counts stockReceives deliveries, adjusts and quarantines. Cannot sell or dispose.
AuditorAn inspector, an accountant, the owner's adviserReads everything, exports anything, changes nothing.

The permissions

PermissionOwnerPractitionerSales clerkInventory clerkAuditor
Manage users
Manage roles
Manage products
Receive stock
View stock
Adjust stock
Quarantine stock
Dispose of stock
Make a sale
Void a sale
View reports
Manage compliance
View the audit trail
Export reports

Why the lines are drawn there

  • A sales clerk cannot void. A void returns stock and erases revenue, which makes it the easiest way to take cash from a till. Voids need a practitioner or the owner, and every void carries a reason.
  • An inventory clerk cannot sell or dispose. Receiving and counting are one job. Disposing of medicine is a regulated act that the licence holder answers for, so it stays with the practitioner and the owner.
  • The auditor changes nothing. An auditor who can also adjust stock is not an auditor.
  • Only the owner manages users and roles. The practitioner runs the shop's operations; the owner runs the shop.

What changes on screen

The sidebar has four groups: Sell, Stock, Comply and Manage. A group appears only when the person may open at least one screen in it, and a screen appears only when they may use it.

Signed in asSellStockComplyManage
OwnerTill, Sales by dayProducts, Expiry and quarantine, PurchasesCompliance, Reports, Audit trailUsers
PractitionerTill, Sales by dayProducts, Expiry and quarantine, PurchasesCompliance, Reports, Audit trail
Sales clerkTill, Sales by dayProducts, Expiry and quarantine
Inventory clerkProducts, Expiry and quarantine, Purchases
AuditorSales by dayProducts, Expiry and quarantine, PurchasesCompliance, Reports, Audit trail

The dashboard follows the same rule. Each of its panels belongs to a permission, so a sales clerk sees today's till and the shelf, and an auditor sees the figures without the Close the day button.

Inside a screen, buttons the person may not use are absent rather than greyed out. A sales clerk opening a sale sees the receipt and Print, not Void.

Custom roles

The five system roles cannot be deleted, but anyone with manage roles can change what they hold or add a role of their own, say a Shop manager who does everything the practitioner does plus users. See Users and roles.