Appearance
Who can do what (permissions)
Use this page when you want to know which role can use each part of Lyt-ning — or when you need to grant the right permissions to a new employee.
Goal
You need to know which role can do what in Lyt-ning so you can assign the right role when onboarding a new employee — and so you can tell why a sidebar item is or isn't visible to you.
Where this happens
Permissions are configured in the Core App at Finance & Admin → HR Management → Employee Security. A user only sees the sidebar items and menu items their role has access to.
- In the back office (Core App): sign in as franchise admin and open Finance & Admin → HR Management → Employee Security to grant or change permissions for any user.
- At the till: sign in with your PIN. The till shows you the screens your role can use; nothing more.
- In Lytning Analytics: opens from the Core App with single-sign-on and respects the same role permissions.
Prerequisites
Franchise-admin login to the Core App — needed only if you want to change permissions. Read this page to understand the role model even without admin access.
Steps — the roles in plain language
1. Cashier
Sign in to the till with a PIN · ring sales · take refunds (if permission granted) · close their shift on the till (End User Shift) · raise a support ticket · view their own till shift history. Cashiers cannot open the Core App.
2. Supervisor
Everything a cashier can do, plus: open the Core App (back office) · manage staff schedule and PINs within their store · approve refunds and voids above the approval threshold the franchise admin has set · record stock adjustments and GRVs · run cashup · view the dashboard KPIs · open Reports & Analytics. Supervisors work within their own store only.
3. Franchise admin
Everything a supervisor can do, across all stores in the franchise: create stores · grant employees permissions · set up devices · manage stock templates · enable or disable integrations (Smart Invoice, SAGE, SAP, Kazang, Lyt-Accounting, Online Store, Cash.co.zm, Loyalty Setup) · set currency · view P&L across stores. Franchise admins cannot see other franchises' data.
4. Other roles your franchise may use (accountant, regional manager, auditor)
Some franchises use additional read-only roles — accountant, regional manager, or external auditor. These depend on your franchise's security-group setup. Ask your franchise admin which roles exist in your business; the Wiki cannot list every variant.
Edit Employee (when and how to use it)
Use Finance & Admin → HR Management → Edit Employee when an existing employee's record changes — name, role, store, contact, security group, or PIN.
- Open Finance & Admin → HR Management → Edit Employee.
- Search for the employee by name or employee number.
- Open their record.
- Change the field you need (name, role, store, contact, security group, or PIN).
- Save.
PIN changes: set a temporary PIN and tell the employee in person — never put a PIN in a ticket, chat, or email. The employee signs in with the temporary PIN and changes it on their first shift.
Role / security-group changes: changing the security group changes what the employee can see and do. Confirm with the franchise admin before changing a supervisor or franchise-admin role.
Notes:
- Editing a security group does not retroactively change historic actions — only future ones.
- If the employee is signed in on a till when you save, the change applies on their next sign-in or refresh.
- See Onboarding for the full new-employee setup flow.
5. Integration permissions
Integration access is not a separate role — it is granted per integration. Only the franchise admin can enable or disable Smart Invoice, SAGE, SAP, Kazang, Lyt-Accounting, Online Store, Cash.co.zm, or Loyalty Setup. Each integration is granted access per store. Supervisors and cashiers cannot see or change integration settings.
Steps — who can configure what
Use this quick table to decide who to ask when something is locked or missing.
- Set a new employee's PIN → supervisor or franchise admin (Finance & Admin → HR Management → Employee Security).
- Add a new store → franchise admin only (System & Settings → System Configuration → Franchise Management — the exact path is configured at the franchise level).
- Approve a void above the approval threshold → supervisor (or whoever holds the threshold permission for that store).
- Issue a Smart Invoice → system-driven (no user action).
- Connect SAGE → franchise admin only (Add-ons & Integrations — SAGE appears there when the add-on is enabled for your franchise).
- Connect Smart Invoice or Kazang → franchise admin only (System & Settings → Till & Payments — Smart Invoicing and Kazang Settings).
- View all stores' P&L → franchise admin.
- View one store's P&L → supervisor of that store.
- Reset a locked PIN → franchise admin (Finance & Admin → HR Management → Employee Security).
- See audit log entries → franchise admin (ask your supervisor for the exact path on your store).
- Edit an existing employee → supervisor or franchise admin (Finance & Admin → HR Management → Edit Employee).
- Maintain the Asset Register → franchise admin (Finance & Admin → Asset Management → Asset Register) — see the Asset Register section below.
Asset Register (franchise admin only)
The Asset Register is the back-office list of every fixed asset the franchise owns — fridges, scales, printers, tills, vehicles, and any other long-life equipment. It sits under Finance & Admin → Asset Management → Asset Register.
Use it when you need to:
- Record a new asset the franchise has bought.
- Track an asset's purchase date, cost, location, and depreciation.
- Find which store an asset is in.
- Disposal of an asset at end of life.
- Open Finance & Admin → Asset Management → Asset Register.
- The list shows every asset with its category, store, purchase date, and current value.
- To add a new asset, click Create and fill in the category, description, store, purchase date, and cost.
- To move an asset between stores, open the asset and update its store.
- To dispose of an asset, open the asset, set the disposal date, and pick the reason (sold, scrapped, lost).
Notes:
- The Asset Register is for franchise-admin use only — supervisors see the list but cannot add or dispose.
- Asset categories are configured at the franchise level — ask your supervisor if you need a new category.
- Depreciation rules depend on the franchise's accounting policy — ask your accountant or finance lead for the rules your franchise uses.
Related (Asset Register)
Expected result
- You know which role to assign when onboarding a new employee.
- You know who to ask when a sidebar item is missing or a PIN is locked.
Edge cases
- The employee can see a sidebar item but can't open it — the role doesn't have permission for that action. Ask your supervisor or franchise admin.
- Your PIN keeps getting locked — the role has been suspended. Ask your franchise admin to reactivate it.
- A new cashier needs refund permission — grant it under Finance & Admin → HR Management → Employee Security with the right threshold.
- Two supervisors disagree on who can approve a void — the franchise admin sets the threshold once per store; everyone follows the same rule.