Hiding a menu
is not a
permission.
Plenty of software greys out a button and calls it security. A hidden link is still reachable by typing the address into the bar. Ours refuses: every screen checks the capability twice — once when the menu is registered, and again when the page renders.
Twenty-six,
in four groups.
Each one is separate. That is the whole point — a cashier who can refund without being able to discount is a normal thing to want, and it should not require editing code.
Suite · 4 capabilities
Point of sale · 12 capabilities
Inventory · 8 capabilities
Membership · 2 capabilities
Names shown exactly as they read on the roles screen.
Four to start
from.
Use them as they are, or take them apart. They are ordinary WordPress roles carrying the suite's capabilities, not a parallel user system.
Cashier
Sells and opens a shift. Cannot close the drawer, discount, override or refund.
Shift Manager
Everything a cashier does, plus closing the shift, discounts, voids, refunds, cash movements and POS reports.
Stock Manager
The supply side — suppliers, purchase orders, receiving, costing, stock takes, transfers. Reports, but no till.
Outlet Manager
All twelve till capabilities and the inventory group. The role you give the person who runs the shop.
403, not a
missing link.
A cashier who types the reports address straight into the bar gets a refusal naming the capability they do not have. Not a blank screen, not a redirect to the dashboard, and certainly not the page.
The home page has this running as a working sketch — pick a role and watch it type the address.
Checked at the menu · checked again at the page
About Members.
Is this a paid-memberships plugin?
What does "checked twice" mean?
Can I lock an administrator out?
Can I build my own roles?
Free on WordPress.org.
Like the rest of it.
Members works on its own, and it is the permission layer the till and the stockroom check against.