Skip to content
All guides

User roles and permissions

How the 157-permission model works, what the audit trail records, and how to plan roles for your staff before we configure them with you.

Polaris has 157 distinct permissions, bundled into 7 roles you can start from. Each permission covers a specific action in a specific part of the product. Staff sign in with their own accounts, and what each person can see and do follows from their role. Roles can be created and adjusted per shop — you decide the bundles. On a cashier, refunds, void, price override and ledger access are off until you grant them.

Every action is logged. The audit trail records who did what and when, from which IP address, with before-and-after values, so “who changed this price?” has an answer instead of an argument. Balance corrections carry extra detail: one of 9 root-cause categories and how long the correction took.

Accounts can carry TOTP-based two-factor authentication, with 10 backup codes for the day the phone is lost. 5 failed sign-ins lock the account for 30 minutes.

What to have ready

  • A list of everyone who will use Polaris.
  • For each person, two honest answers: what do they need to see, and what do they need to change.
  • A bias toward less. Permissions are easier to loosen later than to claw back.

What Polaris handles, and what we do with you

The permission system is in the product; deciding your roles is the part that takes thought, and we do it with you. A shop usually needs only a few roles, decided once. 157 permissions is a lot to read alone, and you should not have to.

Set it up with us

Message us on WhatsApp with your staff list and what each person does at the shop, and we configure the roles together during onboarding.

Message us on WhatsApp

+92 335 070 6014 — the same number support runs on.