Skip to main content

Terminal Settings & Permissions

Terminal Settings & Permissions controls who can do what at the point-of-sale terminal. It lets you protect sensitive operations, customize how your store operates, and give team members the right level of access.

Written by Help

Terminal Settings & Permissions

How Terminal Security Works

Terminal Security gives you control over who can do what at the register, in three ways:

  • PIN-gated actions. For each sensitive action, you decide whether it's freely allowed, blocked, or requires an employee PIN first. When a PIN is required, the employee's role also has to be allowed — this is how you let cashiers ring up sales but require a manager to approve a refund.

  • Inactivity auto-lock. After a set idle time (15 minutes by default), the terminal returns to the PIN screen so the next person has to identify themselves.

  • Audit trail. Every gated action is reported back to Back Office with who performed it, who authorized it, and when, so you can review activity in reporting.


Where to Access Each Feature

To…

Go to

Set employee PINs and roles

Users

Choose which actions need a PIN and set the inactivity timeout

Settings → Devices → Permissions

Review who did what

Analytics → Employees


Editing Terminal Permissions

Step 1

This guide will show you how to set up your terminal settings and permissions. Please note, you will first need to set up all your users with a role of either Manager or Cashier under Settings then Users for these permissions to apply properly.

Configuring Terminal Permissions within Device Settings in Scotch POS video fallback

Step 2

To start, navigate to Settings within Scotch POS Back Office.

Step 3

Within Settings select the option for Devices.

Step 4

Navigate to the Settings & Permissions tab at the top.

Step 5

Terminal Security is separated into three separate parts, Transactions, Operations, and Session settings.

Step 6

Setting the permission to Disabled, makes it so no user, neither Cashier or Manager, has the ability to perform that action.

Step 7

Setting the permission to Always Allowed, makes it so every user, both Cashier and Manager, has the ability to perform that action.

Step 8

If you select Cashier Pin, this will only allow a user to perform the action if a Cashier or Manager pin is entered at the terminal.

Step 9

If you select Manager Pin, this will only allow a manager to perform the action once a Manager pin is entered at the terminal.

Step 10

Another setting to note is the Session Settings section. Here you can set the interval for when the terminal times out, at which point the user will be required to re-enter their password to log back in due to inactivity.

Step 11

Lastly, be sure to save any changes you've made at this time.


The 15 Controllable Actions

These are the actions you can gate, along with their default level. You can change any of them. A few can't be fully disabled — they can only be set to require a PIN.

Action

Default

Can be disabled?

Process refunds

Cashier PIN

No

Open drawer (no-sale)

Cashier PIN

No

Open-price item sales

Cashier PIN

No

Cash deposit

Cashier PIN

No

Cash withdrawal

Manager PIN

No

Manual card entry

Manager PIN

No

No-receipt refund

Manager PIN

Yes

Inventory adjustment

Manager PIN

Yes

Manage loyalty points

Manager PIN

Yes

Tax exemption

Cashier PIN

Yes

Custom item creation

Cashier PIN

Yes

Custom price (override)

Cashier PIN

Yes

Custom discount

Always allowed

Yes

Allocated item sales

Always allowed

Yes

Age-verification override

Always allowed

Yes


What It Looks Like at the Register

When an employee taps a PIN-gated action, the terminal shows "Authorization required — Enter your PIN to continue."

  • A valid PIN with an allowed role proceeds.

  • A valid PIN without the required role shows "Insufficient permissions." (For example, a Cashier PIN on a Manager-only action.)

  • Always allowed actions never prompt for a PIN.

  • Disabled actions don't appear on the terminal at all.


Reviewing the Audit Trail

Every time a controlled action happens, the terminal sends a record to Back Office. To review it, go to Analytics → Employees and use the Activity and Anomalies views.

Each record captures:

  • What and when — the action, plus the date/time, store, and terminal.

  • Who — who performed the action (the cashier) and who authorized it (the employee whose PIN approved it). When those are different — a manager approving a cashier's action — it's flagged as a manager override.

  • The details — invoice number, plus specifics like discount amount, old→new price, quantity adjusted, or loyalty points changed.

A few everyday actions are logged too, even though they don't require a PIN: item removed from cart, cart cleared, and payment removed.

Because this report runs on synced terminal data, it's near real-time rather than instant. A just-performed action may take a short while to appear.

Did this answer your question?