POS Permissions: What Your Waiters Should — and Shouldn't — Be Able to Do (2026)

Tabres Team
pos permissionsrestaurant pos user roleswaiter permissionsrestaurant staff access controlrestaurant managementpos security

Most money that walks out of a restaurant doesn't leave through the cash drawer. It leaves through a void, a comp, and a 20% discount that nobody had to approve.

Here's the short answer. Waiters should be able to do everything that serves a guest — open an order, add and change items before payment, move or merge tables, print the bill, take payment, add a tip. They should not be able to do anything that changes money after the fact or changes the business itself — refunds, comps, price edits, menu changes, sales reports, staff records. In between sits a small list of actions you allow with a reason and a manager's approval: removing a line, discounting, and reopening a settled order.

Get those three lists right and two things happen at once. Your floor gets faster, because nobody's waiting for a manager to tap something a waiter should own. And your losses get smaller, because the handful of actions that actually cost money now leave a name and a reason behind.

Let's build the lists.

What POS Permissions Actually Are

A POS permission is a single yes-or-no switch on one action. "Can apply a discount." "Can issue a refund." "Can view sales reports."

A role is a bundle of those switches — Waiter, Head Waiter, Cashier, Bartender, Branch Manager. You set the bundle once, then hire against it. A new waiter starts on day one with exactly the same access as every other waiter, and you never have to remember what you gave the last person.

Modern restaurant POS systems ship 50 to 70 of these switches across orders, discounts, payments, refunds, menu, tables, employees, inventory, and reporting. That sounds like a lot of admin. It isn't, because you'll only ever think hard about eight of them. The rest are obvious in both directions.

The rule that keeps this simple: give the least access that still lets someone finish their job without asking. Not the least access possible — that's how you end up with a manager being called to the till 40 times a night and eventually giving everyone their PIN, which is worse than having no permissions at all.

Why This Matters More Than It Sounds

Three reasons, and only one of them is theft.

Speed. Every action a waiter can't do is an interruption for someone else. If a waiter needs a manager to remove a mis-tapped drink, that's 90 seconds of two people's time, 15 times a shift. That's half an hour of your manager's night spent walking across the room to tap "confirm".

Mistakes. Permissions stop honest errors, not just dishonest ones. A tired waiter editing a product price at 11 p.m. can break tomorrow's menu for the whole restaurant. A waiter who can't reach that screen can't break it.

Loss. The National Restaurant Association has long put employee theft at a meaningful slice of restaurant losses, and industry estimates commonly land somewhere between 3% and 7% of sales. The exact number is unknowable — that's the nature of it. But the pattern is boringly consistent: it's rarely cash from the drawer. It's a bill settled as cash, then voided after the guest leaves. It's a comp for a friend. It's a "staff discount" applied to a table of six strangers.

None of that needs a criminal mastermind. It needs a permission that was switched on because switching it off felt like distrust.

The Green List: What Every Waiter Should Do Freely

These are the actions that serve guests. Block them and you're just making service worse.

  • Open a new order — dine-in, takeaway, or delivery.
  • Add items, variants, and add-ons to an order.
  • Change quantities before the order is sent to the kitchen.
  • Add order notes — allergies, no onions, sauce on the side.
  • Send items to the kitchen and to specific stations.
  • View their own open tables and orders.
  • Move an order to another table, and merge two tables when a party joins up.
  • Change the order type — a dine-in guest decides to take it away.
  • Print or share the bill.
  • Take payment — cash, card, and whatever else you accept.
  • Add a tip.
  • Split the bill, by item or by amount.
  • Attach a customer to a delivery or takeaway order.

That last group surprises people. Should a waiter really take payment and split bills? Yes. Splitting a bill six ways is service, not finance, and routing it through a manager creates a queue at exactly the moment guests want to leave. The controls that matter come after the money lands, not before. If splitting is a regular headache in your place, the practical mechanics are here: how to handle split bills.

One small thing worth being precise about while you're setting this up: a bill is what's owed, a receipt is proof it was paid. Two different documents, two different moments — the difference in plain terms.

The Amber List: Allow, But With a Reason

These four actions cost real money, and they're all legitimate parts of a normal shift. Don't block them. Log them.

1. Removing a Line After It's Been Sent

A waiter taps the wrong burger. The kitchen already has it. It has to come off.

Let waiters do this — but make a reason mandatory, from a short fixed list: wrong item, guest changed mind, kitchen error, out of stock, quality issue. Free-text boxes get filled with "." at 9 p.m. A dropdown doesn't.

Now you have data. Ten "kitchen error" removals in one week is a kitchen conversation. Ten "wrong item" removals from one waiter is a training conversation. The permission didn't stop anything — the reason code found the pattern.

2. Discounts

This is the big one, and the answer is a cap, not a block.

Give waiters a small discretionary limit — a free coffee, 10% off one dish, something in the $5 to $15 range. Anything above that needs a manager. The cap should be a number you'd happily let a waiter spend to save an unhappy table, because that's exactly what it's for.

Set the limit three ways, and use whichever your POS supports:

  • A percentage cap per line (say 15%).
  • A cash cap per order (say $15).
  • A whole-order discount locked to managers only.

That last one matters. Line discounts fix a specific problem. Whole-order discounts are where the leakage lives, because "25% off everything" hides inside a normal-looking bill.

3. Reopening or Editing a Settled Order

Once money has landed, the order should be effectively frozen for floor staff. Adding a late coffee is fine. Changing what was already paid for is not.

If your POS allows a settled order to be edited without a trace, that's the single most dangerous switch on your system. Find it and turn it off for everyone except a manager.

4. Changing a Price by Hand

Off-menu specials and market-price fish make this necessary sometimes. Keep it rare and keep it named.

Better still, build the exceptions into the menu instead: an "open food" product for genuine one-offs, and real products for anything you sell more than twice a week. Hand-typed prices are impossible to report on later. There's a fuller version of that argument here: how to handle off-menu orders.

The Red List: What Waiters Should Never Have

Nine switches. Managers and owners only, every time.

Permission Why it's off-limits
Refunds Money moves back out. Highest-abuse action in any POS
Comps / write-offs A free meal with no money trail at all
Edit or delete the menu One tired tap breaks tomorrow's service
Edit product prices permanently Different from a one-off override — this changes everything
View sales reports Nobody on the floor needs your gross sales, and it travels to competitors
View or edit employees Wages, PINs, and personal data
Change tax settings An accounting problem you'll find months later
Change branch settings Hours, fees, service charge, legal receipt details
Delete orders entirely An order should be cancelled with a reason, never erased

Refunds deserve their own line. The classic trick is old and still works: settle a bill in cash, wait for the guest to leave, refund it, pocket the cash. The order looks refunded, the drawer balances, and nothing looks odd unless someone's counting refunds per person. Keep refunds with managers, always require a reason, and read the list weekly. Full playbook: how to handle restaurant refunds.

Comps are the quieter cousin. A comp and a refund look identical to the guest and completely different in your books, which is exactly why a comp permission on a waiter account is a bad idea. Free food should always be a decision someone signed for.

A Permission Matrix by Role

Here's a starting point that works in most independent restaurants. Copy it, then argue with it — the arguing is where you learn what your place actually needs.

Action Waiter Head Waiter Cashier Bartender Runner Shift Manager Owner
Create and edit orders
Send to kitchen
Move / merge tables
Remove a sent line (with reason)
Line discount up to the cap
Whole-order discount
Take payment
Split the bill
Refunds
Comps
Mark a product unavailable (86)
Edit the menu
View sales reports
Manage employees
Branch and tax settings

Two rows are worth explaining.

86'ing a product — marking it sold out — belongs with head waiters and bartenders, not every waiter. It stops the whole restaurant selling something, so it needs a bit of seniority. But keeping it away from the floor entirely means the last three portions of sea bass get sold twice while someone hunts for a manager.

Runners get less than you'd think. A runner carries food. Giving a runner payment access is how a terminal ends up logged in as someone who isn't there.

Managers Approving Things Without Slowing the Floor

The whole system collapses at one specific point: when getting approval is harder than working around it.

You'll know it's happening when you see the classic symptoms. Everyone knows the manager's PIN. One account stays logged in all night. Or the manager just does the void from across the room while the waiter holds the tablet.

Three things prevent it.

Make the ask fast. Approval should be a 4 to 6 digit PIN typed on the same screen, in a few seconds. If it involves walking to an office or an app on someone's phone, it will be bypassed by Friday.

Log the approver, not just the actor. The record needs both names: who asked, and who approved. One name is a guess. Two names is an audit trail.

Give people their own login. POS terminals usually work one of two ways. Some ask for a manager PIN in the moment. Others use a device-unlock model, where a manager opens the terminal once and staff PIN in and out of their own sessions on top of it — with a "lock" button to hand the terminal to the next person. Either is fine. Shared accounts are not. If four people use one login, every permission you set is decorative.

And say the quiet part to your team: this isn't about trusting them. It's about being able to prove nothing went wrong when a number looks strange. Staff accept that far more easily than a lecture about honesty — and if your team is thin on people who can approve anything, that's a staffing problem, not a permissions one: hiring shift managers.

The Weekly Report That Catches Everything

Permissions without review are theatre. The review takes about ten minutes a week.

Pull these five numbers, per employee:

  1. Voids and removed lines — count and total value
  2. Discounts given — count, total value, and average percentage
  3. Comps — every single one, with the reason
  4. Refunds — every single one, with the reason and the original tender
  5. Cash-settled orders that were later changed — should be almost zero

Now do the only thing that matters: compare people to each other, not to zero. Voids are normal. Everyone has them. What's not normal is one waiter having four times the void rate of everyone else on the same section, same shifts, same guests.

A rough sense of typical ranges in table service:

  • Voids: roughly 1–3% of order lines
  • Discounts: roughly 1–4% of gross sales, mostly small
  • Comps: under 1% of sales
  • Refunds: well under 1% of sales

Your numbers will differ. That's fine — the point is knowing yours, so an outlier is visible. Bolt this onto the review you already do: restaurant KPIs to check every Monday morning. And if the reports themselves are unfamiliar territory, start here: how to read a restaurant sales report.

One caution before you accuse anyone. A high void rate usually means bad training, a confusing product grid, or a menu with three items that look identical on screen. Check the boring explanation first. You'll be right most of the time, and you'll keep a good waiter you'd otherwise have lost.

Running Permissions Across More Than One Branch

Two extra rules once you have a second site.

Scope people to a branch. A waiter at the Riverside branch should not see, edit, or take payment on Downtown's orders. Most systems handle this with a branch assignment on each employee — set it, and check it, because a manager who transfers sites often keeps both.

Keep the role names identical everywhere. If "supervisor" means one thing at one branch and something else at another, cover shifts turn into a mess and nobody can be moved without a briefing. Same role names, same switches, same discount caps, every site. It's the same trap that hits menus and reporting across locations: multi-location POS problems.

The one exception worth allowing: discount caps can differ by site if the price points genuinely differ. A $15 cap in a café is generous. In a steakhouse it barely covers a side.

Rolling This Out in One Shift

You don't need a project. You need about 40 minutes and one pre-shift meeting.

  1. List your roles. Most places need five or six: waiter, head waiter, cashier, bartender, manager, owner. Not fifteen.
  2. Open your POS employee settings and read the permission list once, top to bottom. Ten minutes. You'll be surprised what's already switched on.
  3. Turn off the red list for floor roles. Refunds, comps, menu editing, reports, employees, taxes, branch settings.
  4. Set a discount cap and make reasons mandatory on voids and discounts.
  5. Give everyone their own PIN. No shared logins, no exceptions, and change the PIN when someone leaves.
  6. Tell the team what changed and why — in pre-shift, in one minute, without drama. "Everything you need is still there. The money stuff needs a name on it now."
  7. Run one week. Pull the five numbers. Adjust.

Expect one thing to be wrong. There's always a single permission you turned off that a waiter genuinely needs 20 times a shift. Find it in week one and switch it back on — that's the system working, not failing. Rolling this out lands much better when it's framed as part of normal training rather than a crackdown: how to train restaurant staff.

Mistakes That Break POS Permission Systems

  • One shared login for the whole floor. Every other control on this page becomes useless.
  • The manager PIN everyone knows. Change it, and stop announcing it across the pass.
  • Blocking so much that managers get called constantly. Bypass follows, guaranteed.
  • Free-text reason boxes. You'll collect a thousand entries that say "ok".
  • Permissions set once and never reviewed. Roles drift. People get promoted and keep old access.
  • Leaving accounts active after someone quits. Do it the same day, along with the door code.
  • Reviewing totals but not per-person numbers. The restaurant-wide void figure hides every outlier inside it.
  • Treating a high void rate as guilt. Usually it's a badly built product grid.
  • No approval trail. If the record doesn't say who approved it, the action might as well have been anonymous.

FAQ

What POS permissions should a waiter have? Everything that serves a guest: creating and editing orders, adding items and add-ons, order notes, sending to the kitchen, moving and merging tables, printing or sharing the bill, taking payment, splitting bills, and adding tips. Waiters should not have refunds, comps, menu editing, sales reports, employee records, or tax and branch settings.

Should waiters be able to void items? Yes, but with a mandatory reason from a fixed list, and only before or shortly after the item is sent. Blocking voids entirely just means a manager gets called 15 times a shift. The control that works isn't blocking it — it's the reason code plus a weekly review of voids per employee.

Should waiters be able to give discounts? Give them a small cap — usually $5 to $15, or 10–15% on a single line — so they can fix a problem at the table without hunting for a manager. Whole-order discounts and anything above the cap should need manager approval, because that's where losses hide.

Can waiters issue refunds on a POS? They shouldn't. Refunds move money back out and are the most commonly abused POS action. Keep them with managers and owners, always attach a reason, and review every refund weekly against the original payment method.

What's the difference between a void, a comp, and a refund? A void removes an item before payment. A comp gives it away for free and writes it off. A refund sends money back after a payment has already gone through. To the guest they can look the same. In your books they're three completely different things, and only one of them should be available to floor staff.

How many POS permissions does a restaurant actually need? Most systems offer 50 to 70 switches, but you'll only make real decisions about eight to ten of them: voids, discounts, whole-order discounts, refunds, comps, price overrides, reports, menu editing, employee management, and settings. The rest are obvious either way.

How do I stop staff sharing POS logins? Give every employee their own PIN, add a "lock" button that's faster than staying logged in, and make sure switching users takes seconds rather than a full sign-out. If switching is slow, sharing will happen no matter what you say in pre-shift.

How often should I review POS permissions? Look at the void, discount, comp, and refund reports weekly — it takes about ten minutes. Review the permission settings themselves every few months, and always when someone is promoted, changes branch, or leaves.

Should a bartender have different permissions from a waiter? Mostly the same, with two differences. Bartenders usually need to mark products unavailable, since they run out of things constantly. They usually don't need table moves and merges, because they aren't running the floor plan.

Does a small café need POS permissions at all? Even with three staff, yes — but only the simple version. Separate logins for everyone, refunds and comps kept with the owner, and a discount cap. That takes 15 minutes to set up and removes the single most common source of unexplained gaps.

Can staff see how much the restaurant made today? Only if you let them, and most owners shouldn't. Sales figures aren't floor information, they move quickly between venues in a small town, and knowing tonight's takings changes nobody's service. Keep reports with managers and above.


POS permissions get framed as a trust problem. They're really a clarity problem. Every switch you set is just you deciding, in advance and while calm, who owns which decision — instead of deciding it at 9 p.m. with a guest waiting and a queue at the till.

Do one thing this week. Open your POS employee settings and read the permission list for a waiter, top to bottom. Ten minutes, one coffee. Almost everyone finds at least one switch turned on that shouldn't be — and that single discovery is usually worth more than anything else you'll change this month.

Still paying for restaurant software?

Switch for Free

Stop paying monthly fees. Tabres gives you all the tools you need to run your business - 100% free.