# Users & Roles

**Admin → Users** is where you invite staff and set what they can reach. Only **Owners** (and ForkLine superusers) can manage users.

For counter staff who share a till, see [Register Accounts](/register-accounts) instead — that's a different and usually better answer.

## The roles

| Role | Can do |
|---|---|
| **Owner** | Everything: billing, settings, menu, AI phone, orders |
| **Manager** | Operations, menu, settings, AI phone, orders — no billing |
| **Staff** | View and update orders |
| **Kitchen** | Kitchen display only; move orders through prep |
| **Cashier** | Register, card readers, kitchen display, counter orders |

There's also **Pending**, meaning someone signed in but hasn't been granted access yet.

### Choosing a role

**Owner** — you, and a business partner. Owners can change billing and delete things.

**Manager** — a general manager or shift lead who runs the place day to day. Everything operational, nothing financial.

**Staff** — front-of-house who handle orders but shouldn't change your menu or prices.

**Kitchen** — cooks. They get the [kitchen display](/kitchen-display) and nothing else: no menu, no settings, no revenue, no customer contact details. This is the right role for a screen mounted on a wall, because a tablet left signed in on the line is physically accessible to anyone in the building.

**Cashier** — counter staff. The register, readers, and kitchen display. This is what the shared till device signs in as.

## Inviting someone

1. Go to **Admin → Users**.
2. Choose to invite a user.
3. Enter their **email address**.
4. Choose their **role**.
5. Send.

They get an email, sign in with Google or Apple, and land in the access you granted.

**Use the email they'll actually sign in with.** If they sign in with a Google account on a different address, ForkLine sees a different person.

## Changing a role or removing access

Open the user and change their role, or remove their access. Changes take effect immediately.

**Remove access the day someone leaves.** Not the day you get around to it — a former employee with register access is a real risk.

## Multiple locations

Access is per restaurant. Someone can have access to one location or several, with a different role at each — a manager at one store and staff at another.

If you have access to more than one, the restaurant picker in the admin header switches between them.

## Least access, always

Give each person the least access that lets them do their job:

- Cooks don't need customer contact details or revenue figures.
- Counter staff don't need to edit prices.
- Only Owners should touch billing.

This isn't about distrust — it's about limiting damage from a mistake or a device left unlocked.

## Where to go next

- [Register Accounts](/register-accounts) — passcodes for shared tills
- [Activity Log](/activity-log) — who did what
- [Kitchen Display](/kitchen-display) — kitchen-only accounts
