Most small hospitality businesses start with one admin account. The owner sets it up, shares the credentials with the manager, and the manager occasionally shares it with whoever covers on weekends. By the time the operation has three outlets and a dozen staff members, six people are logging into the same account — and nobody knows exactly who has done what.
This is a problem that compounds quietly until something goes wrong: a deleted order, a menu price that changed unexpectedly, a discount applied that shouldn't have been. At that point, the investigation is impossible because all actions look identical in the logs. They all happened under the same account.
Why full access is the wrong default
When everyone has the same access level, you lose two things simultaneously: accountability and security.
Accountability means knowing who made a change. If any of six people could have updated the menu price, you can't investigate an error — you can only shrug and roll it back. An audit trail only works when actions are tied to specific, authenticated users. Without that, you have a log of events with no authorship.
Security means limiting the surface area of what can go wrong. A barista doesn't need to see cost data or manage suppliers. A delivery rider doesn't need to see table-level order history. Every permission that exists but shouldn't be there is a risk that doesn't need to exist — and a potential point of failure when someone makes an honest mistake, or an intentional one.
The roles that matter in a café
A typical multi-outlet café operation has five meaningful access levels. These aren't bureaucratic distinctions — they're the difference between a system where everyone can do their job clearly and a system where anyone can accidentally (or deliberately) cause problems beyond their remit.
Owner / Director. Full access to everything: financials, all-outlet analytics, system configuration, user management. Typically one or two people. This is the only role that should be able to add or remove other users.
Outlet Manager. Full access within their assigned outlet. Can manage the menu, staff scheduling, orders, and inventory for their location. No visibility into other outlets' financial data or performance. This is the most important boundary in a multi-outlet setup — an outlet manager should run their outlet, not the whole group.
Floor Staff / Barista. Can see the order queue, update order status, and view their current shift. Cannot change prices, modify the menu, access inventory levels, or see other outlets. Their screen should show exactly what they need to serve a table well — nothing more.
Kitchen. Order queue view only. What's been ordered, what's pending, what's done, what's been called. No administrative access of any kind. The KDS (kitchen display) is the whole job.
Inventory / Procurement. Can view and update stock levels across assigned outlets, log deliveries, create purchase orders, and see par-level alerts. No access to financial reporting, staff management, or order history. They manage supplies, not operations.
What happens when someone leaves
One of the most underappreciated benefits of proper access control is offboarding. When a staff member with a named account leaves, you deactivate that account. Done. Their access is gone.
When six people share one admin account, and two of those people leave, the account password either has to be changed and redistributed to everyone still using it — or it doesn't, and former employees retain access indefinitely because nobody wants to deal with the disruption of a password reset.
The cleanest security audit is the one you never have to do because access was right-sized from the start.
What good access control looks like in practice
The best access control systems are invisible when they're working correctly. Each person sees exactly what they need to do their job well. They don't encounter walls for things they reasonably need. They can't make changes that aren't theirs to make.
The owner has full visibility — not because they're watching, but because the data is there when they need it. When something goes wrong and an investigation starts, the answer isn't "I don't know." The log shows who changed what, when, from which device. That's not surveillance. That's accountability — and for a well-run operation, it's what makes trust possible at scale.
EatOps includes role-based access across all modules — with outlet-level isolation, named accounts for every team member, and a full audit trail. Deactivate departing staff in seconds.