Roles and permissions
Esta página aún no está disponible en tu idioma.
Clockout keeps two separate things on a person, and it helps to name them apart:
- Access level — what they can see and change in the app. This is what this article is about.
- Job role — the job they do, such as Server or Line Cook. It is a label used for tagging shifts and deciding who may claim a role-tagged open shift. It grants no permissions.
The access levels
Section titled “The access levels”Owner. Full access across every store in the business, including payroll and business settings.
Co-Owner. The same reach as an owner for day-to-day purposes, including submitting payroll.
Manager. Full operational access at the stores they are assigned to: build and publish schedules, edit and approve timecards, set pay rates, add and terminate employees. Managers do not see other stores.
Employee. Their own timecards and their own pay statements, plus the store’s schedule — they can see when their coworkers are on, which is the point of a schedule. What they cannot see is anyone else’s wages or personal details.
Three rules worth knowing:
- Payroll is submitted by owners and co-owners. Managers can do everything up to that point.
- Pay rates can be set by managers and above — this is not owner-only.
- A flagged timecard needs an owner or co-owner to approve or edit; a manager cannot clear the flag themselves.
You can only grant an access level below your own, so a manager cannot make someone else a manager.
Permissions are per store, not global
Section titled “Permissions are per store, not global”This is the part that surprises people. Access is granted store by store, so the same person can be a manager at one location and an hourly employee at another. Their access level is whatever their membership at that store says — there is no single account-wide rank.
The practical consequence: if a manager says they cannot see a schedule or approve a timecard, the answer is almost always that they do not have manager access at that store, not that something is broken. See Manage store access.
What the app shows is not the boundary
Section titled “What the app shows is not the boundary”Clockout hides what you cannot use, but the real check happens on the server for every action. Hiding a button is a convenience; the server is what actually refuses. You cannot get to someone else’s pay statement by guessing a URL.
Changing someone’s access level
Section titled “Changing someone’s access level”Change it on their profile. The change takes effect immediately; it does not alter anything they did under the previous level — past approvals and edits keep the identity that made them. To take access away entirely, terminate them at that store rather than deleting, so their timecards and pay history survive — see Manage store access.