POS employee management software
Run the team from one permission-aware employee record.
Keep identity, access, work, and lifecycle context attached to the person who does the work—with invitation, self-onboarding, and protected records available when the tenant rollout is configured for them.Keep role, permission, onboarding, clock, and lifecycle context attached to one employee record.
Operating thread · real Employees screen
Read the roster before evaluating the policy.
The employee surface keeps roles, locations, and clock status visible so an operator can open the exact record behind a staffing decision.
Swipe the product frame horizontally to inspect details, or open the full-resolution screen.
- 01
Open Employees in a seeded store.
- 02
Compare role and location context across the roster.
- 03
Inspect the current clock status on an employee record.
- 04
Move through schedule, time, and performance context.
- 05
Review the archive and reactivation controls.
One employee record, bounded at every operating edge
- IdentityProfile, contact, location, employment context
- AccessRole, permissions, BCrypt-protected POS PIN
- OnboardingConfigured invite, self-onboarding, consent record
- Protected recordConfigured encryption and permission-gated documents
- Work contextClock, schedule, timesheet, performance
- LifecycleArchive and reactivate without deleting history
Roster · access
Make the permission boundary visible at the employee record.
The Employees view can list active or archived people with location, role, contact, and current clock status. Open a record to inspect the profile, shifts, timesheet, labor, and sales-performance context available to the authorized operator.
Roles and permissions bound sensitive work at the server. Hourly, tipped, and salary wage types can describe employment context without turning the employee record into a separate workforce system.
PIN · invite · onboarding
Start access deliberately, then let the employee finish their record.
Create the employee, issue an invitation, reset contact details when needed, and reset the POS PIN through authorized controls. A POS PIN must be four to six digits; LiftedPOS stores only its BCrypt-protected value and does not return the plaintext PIN.
When the tenant encryption key, invitation delivery channel, permissions, and onboarding rollout are configured, an invited employee can complete self-onboarding with profile details, emergency contact, consent metadata, and protected document submission. The invitation and onboarding path remain connected to the employee identity an operator later manages.
Protected record
Keep sensitive documents encrypted and permission-gated.
When the tenant encryption key and document workflow are configured, employee documents are stored behind permission-gated submission and retrieval paths. The application boundary protects the document record while the merchant remains responsible for defining access, reviewing the information, and following its own records process.
Work · performance context
Move from clock status into the work record without losing the person.
Manager clock controls can sit beside the employee profile and current clock status. Schedule, timesheet, labor, and performance views preserve the employee, location, and period context an operator needs for review.
Scheduling owns planned shifts and worked-time review; reporting owns the broader employee and location comparison. This page keeps the identity and access record that connects those operating surfaces.
For register accountability, inspect cash drawer management and the separate offline cash acceptance boundary.
Swipe the product frame horizontally to inspect details, or open the full-resolution screen.
Archive · reactivate
Change operating state without erasing the record.
Authorized users can archive an employee who should no longer appear in the active roster, filter for archived records, and reactivate the same person when the operating relationship resumes. The lifecycle action preserves history rather than creating a disconnected duplicate.
Permission and records responsibility
LiftedPOS protects the product boundary. The merchant defines the people policy.
Roles, server-enforced permissions, and BCrypt-protected POS PINs describe the core access record. Invitation delivery, self-onboarding, protected-document submission, and encrypted retrieval require the tenant encryption key, configured delivery channel, relevant permissions, and rollout setup. The merchant remains responsible for assigning access, reviewing employee information, and deciding how its internal records process is used.
Employee management FAQ
Exact answers for an access review.
How does employee access work in LiftedPOS?
Each employee record can carry role, permission, location, and employment context. Sensitive actions remain bounded by server-enforced permissions.
How are employee POS PINs protected?
LiftedPOS validates a four-to-six-digit POS PIN and stores only a BCrypt-protected value. The plaintext PIN is not returned from the employee record.
Can employees complete their own onboarding?
When tenant encryption, invitation delivery, permissions, and rollout setup are configured, an invited employee can complete self-onboarding with profile, emergency-contact, consent, and protected-document information.
How are employee documents handled?
When the tenant encryption key and document workflow are configured, employee documents use encrypted storage and permission-gated retrieval. The merchant controls who receives the relevant employee-record permissions.
Can an employee record be restored after archive?
Yes. Authorized users can archive and reactivate an employee record while retaining its operating history.

