System Roles & Permissions Structure
Complete breakdown of login-enabled staff roles, operational boundaries, and managerial override privileges.
Login-Enabled System Roles
OCTK Restaurant OS provisions structured, role-based access to safeguard financial records, inventory data, and sensitive staff credentials.
The system provides dedicated accounts for 7 distinct operational roles: Owner, Branch Manager, Host, Waiter, Chef, Inventory Staff, and Driver. Secondary kitchen staff without individual system accounts operate seamlessly through the touch-based Kitchen Kiosk interface.
Full System Access across All Branches
Manages multi-branch setup, audit logs, staff hours, open shifts, payroll, finance, analytics, and employee provisioning.
Assigned Branch Operational Control
Operates tables, menu availability, recipes, inventory stock & waste logging, periodic inventory audit, cash closing, daily reports, takeaway & delivery dispatch. Cannot access Staff Hours, Open Shifts, or Payroll (Owner only).
Front-of-House & Guest Reception
Manages walk-in waiting lists, table reservations, operational table actions, Delivery/Takeaway order Accept/Reject, bill and payment closing, invoice view/print/reprint, and Staff Meals & Purchases. Orders page is strictly read-only; cannot create dine-in orders.
Assigned Table POS & Dining Room Service
Creates table orders for assigned tables, dispatches additional items to kitchen stations, applies authorized coupons, uses Continue Order, and processes bill requests.
Kitchen Display & Station Routing
Views full orders, starts station preparation or full orders, marks dishes as Ready (triggering recipe deductions), remakes, and manages kitchen staff attendance.
Branch Stock & Logging Management
Adds stock (selecting item and quantity), logs inventory waste, monitors low stock alerts, and views ingredient movements. Cannot run Inventory Audits.
Delivery Dispatch App
Receives assigned delivery dispatches via the Android app, activates live route tracking upon pickup/out for delivery, updates status to Delivered, and can cancel with mandatory reason. Does not update cooking states, accept/reject orders, or collect cash.
Manager Override PIN Mechanics
The Manager Override PIN is created and configured exclusively by the Owner. It authorizes sensitive operational overrides such as emergency table status modifications. The PIN is not displayed after saving (only "Change PIN" is available afterward).
Host and Waiter roles do not hold override PIN authorization. The Chef account uses standard login credentials and does not require an override PIN for kitchen actions.
Audit Log Retention
Sensitive emergency/manual overrides are recorded in Audit Logs with the relevant operation details, including reason information where captured by the override flow.
Related Documentation Guides
Step-by-step guide to provisioning a staff account, assigning an operational role, and branch assignment.
Detailed authority matrix comparing Owner, Branch Manager, Waiter, Host, Chef, Inventory Staff, and Driver.
14-day immutable audit logs for administrative events, dynamic role filters, and export options.
