Scopes: where each user works

3 min read ·Updated

A permission says what an employee can do; a scope says on which branch, warehouse and cashbox they do it. Two shops or two cashboxes? This article is for you.

On this page
  1. The idea in one sentence
  2. The five scopes
  3. 1. Branch scope
  4. 2. Warehouse scope
  5. 3. Cash accounts and banks scope
  6. 4. Payment amount limit
  7. 5. Item groups they sell from
  8. Allowed IP addresses
  9. Practical examples

The idea in one sentence

A permission answers "what", a scope answers "where". A treasurer has permission to create a receipt, and their scope says they collect on the east branch cashbox only. Scopes live in the Role and permissions tab of the user form, and every one of them means empty = all.

Scopes are enforced on the server when the operation runs, not only in the interface. Even if a request comes from the app or an old device, anything outside the scope is refused. The super admin (owner) is never restricted.

The five scopes

1. Branch scope

Documents the user creates must be on a branch from this list. A document on another branch is refused with "Branch outside your scope" (ERR_SCOPE_BRANCH). See Branches.

2. Warehouse scope

Sales, purchases, transfers, adjustments and stocktakes need a warehouse from the list, otherwise "Warehouse outside your scope" (ERR_SCOPE_WAREHOUSE). When choosing the POS warehouse in the Point of sale tab, only warehouses in this scope are offered.

3. Cash accounts and banks scope

Receipts and payments are posted to a cashbox from the list, otherwise "This cashbox is outside your scope" (ERR_SCOPE_CASHBOX). The one exception: a user holding the Other cashbox permission on vouchers bypasses this scope. The cashier's POS cash account must also be in the list, or saving the user itself is refused (ERR_CASHBOX_OUT_OF_SCOPE).

4. Payment amount limit

An amount in the base currency. A payment voucher above it is not posted directly; it becomes an approval request shown under Home, then Approvals, to whoever holds the Approve permission on payments. Suitable for a treasurer who pays small expenses and needs your signature above a certain amount.

5. Item groups they sell from

This scope is in the Point of sale tab and applies to cashiers only: their device receives only items from these groups including all sub-groups. Two points of sale in the same shop (a café corner inside a supermarket, for example) each sell from their own groups. See Item groups.

Allowed IP addresses

One address per line. When filled, the user can sign in to the control panel only from these addresses. Useful for an accountant who works from one office with a fixed address. Leave it empty for anyone who works from a phone.

Practical examples

EmployeeSuggested setup
Cashier at the west branchBranch scope: West. Warehouse scope: West shop. Cash scope: West cashier 1. POS cash account: the same.
Head treasurerCash scope: main cashbox and company bank. Payment amount limit: 1000. The Other cashbox permission is not granted.
Purchasing officerWarehouse scope: main warehouse only, so goods are not received straight into the shop warehouse.
Café corner cashierItem groups: Drinks and Pastries. Grocery items never reach their device.

Tip

Start with empty scopes on day one, then narrow them once you see how each employee actually works. A scope that is too tight stops a sale with an error in front of the customer.

Warning

Narrowing the cash scope of a POS user clears the POS cash account field if it falls outside the new scope, and it is refilled from the company default within the scope. Check it after every change.

Frequently asked questions

Does a scope hide data or only block operations?

It blocks operations and limits the choices in forms. Reports follow permissions; whoever can view balances sees every warehouse in the report.

What happens to a payment above the amount limit?

It is saved and becomes an approval request under Approvals. When someone with the Approve permission approves it, it is posted.

Does the item group scope apply to the web panel?

No, it is a scope for the cashier device only: it limits which items and groups are downloaded to the app.

Was this article helpful?