Roles & permissions
Control who on your partner account can open each area of the Partner Portal — and who can change those rules.
What it does
Every user under your partner account has:
- A role — Founder, Manager, or Employee
- Permissions — checkboxes for portal areas (Dashboard, Outlets, Apps, …) and team capabilities
Founders always have full access. Managers and employees only see what you grant.
This is separate from Staff Management: staff records are for shifts and the till; Settings → Team is who can log in to the Partner Portal.
Who it's for
- Owners who invite managers and front-desk users
- Multi-outlet businesses that need different people to see different apps
- Anyone who wants to limit who can invite users or change roles
Roles at a glance
| Role | Typical use | Access |
|---|---|---|
| Founder | Account owner | Full portal access; can grant any permission, including Manage roles |
| Manager | Trusted lead | Only what the Founder (or a Manager with Manage roles) assigns |
| Employee | Day-to-day user | Only assigned portal areas and apps |
Two kinds of permissions
Portal access (objects)
Gates the main sidebar areas, for example:
- Dashboard
- Customer registry
- Outlets
- Connect
- Store
- Apps (launcher)
- API connectors
Apps
Gates individual products under Apps (Appointments, Billing Desk, Cashflow, Staff, Inventory, and so on). A user usually needs both Apps and the specific app grant.
Team capabilities
| Capability | Allows |
|---|---|
| Manage team | Invite users, edit profiles, reset passwords |
| Manage roles & permissions | Change someone’s role and permission checkboxes |
Only a Founder can grant Manage roles & permissions. Managers with that capability can still assign portal/app access to employees, within what they themselves have.
How to invite someone and set access
- Log in to the Partner Portal
- Open Settings → Team
- Click Add user
- Enter name, email, and password
- Choose a role (Founder, Manager, or Employee)
- Tick the permissions they should have
- Save
To change access later: open the member’s Edit action, update role and permissions, then save.
Nobody can change their own role or permissions. Ask another Founder (or a Manager who has Manage roles) to update you.
Default behaviour (before you set permissions)
If a Manager or Employee has never had an explicit permission set saved:
- Manager — can manage the team list (invite / edit / reset password) but does not get portal areas or apps until you grant them
- Employee — no portal areas until you grant them
Once you save permissions for that person (even an empty set), Oflync treats that as their explicit access list.
Rules that always apply
- You can only grant permissions you yourself have
- Managers cannot change Founder or other Manager roles/permissions
- Role and permission changes need Manage roles; inviting and password reset need Manage team
- Sidebar items and direct URLs are both gated — no permission means the area is hidden and blocked
Suggested setups
| Person | Role | Useful grants |
|---|---|---|
| Co-owner | Founder | (full access — no checklist needed) |
| Ops manager | Manager | Portal areas they run + Apps they use + Manage team; add Manage roles only if you trust them to assign access |
| Front desk | Employee | Dashboard, Outlets, Appointments, Billing Desk |
| Accountant | Employee | Cashflow, API connectors (if they manage keys), maybe Dashboard |
Common questions
Where do I open this?
Settings → Team in the Partner Portal.
Why can’t my manager see Cashflow?
Grant Apps and Cashflow (and any other areas they need), then save. Legacy managers do not get apps until you assign them.
Can two people be Founders?
Yes, if someone with Manage roles promotes them. Treat Founder carefully — they have full access.
Is this the same as Billing Desk PIN permissions?
No. Desk PINs and outlet locks are configured inside Billing Desk / desktop. Portal roles only control the Partner Portal login.
Related
- Account & login — signing in and sessions
- API connectors — keys for external cashflow posts (needs the API connectors permission)
- Staff Management — employee directory and shifts (not portal login)