POS operations guide

POS security audit for owner permissions

Most POS security problems are not dramatic. They come from old staff accounts, shared passwords, unrestricted discounts, quiet price edits, uncontrolled refunds and backups nobody checks. A regular permission audit protects cash, stock and reports.

Practical workflow

Where this setup helps

This audit helps restaurants, supermarkets, pharmacies, textile stores, salons, cafes, kiosks, multi-outlet shops and any owner who depends on staff billing responsibly.

How the workflow should run

List every POS user, remove old accounts, check role permissions, test discount and refund approval, review admin access, verify backup ownership, check cloud users and repeat the audit after staff changes.

What to decide before buying hardware

Decide which actions need owner or manager approval: refund, void, price edit, stock adjustment, item deletion, report export, backup restore and cloud access.

Reports or checks after rollout

Review login history, voids, refunds, manual discounts, price edits, stock adjustments, reprints, deleted items, failed backups, cloud access and branch-level permission changes.

Owner permission audit flow

Security is strongest when every sensitive action has an owner and a report.

Step 1

List users

Export or write down active owners, managers, cashiers, kitchen users and support accounts.

Step 2

Remove old access

Disable staff and support accounts that are no longer needed.

Step 3

Check roles

Compare every role against what that person should actually do.

Step 4

Test approvals

Try refund, void, discount and stock adjustment from a cashier login.

Step 5

Review reports

Owner checks sensitive activity after the next busy day.

Hardware and software required

Hardware

  • Owner or admin computer for permission review.
  • POS terminals used by cashiers.
  • Backup storage or restore test device.
  • Secure password storage method approved by the owner.
  • Stable internet where cloud access is enabled.

Software and data

  • User and role permission settings.
  • Audit logs for refunds, voids, discounts and edits.
  • Backup and restore status.
  • Cloud dashboard user list where applicable.
  • Branch-wise access controls for multi-outlet businesses.

Setup sequence

  1. Create named logins instead of shared cashier passwords.
  2. Disable old staff accounts immediately.
  3. Restrict refund, void, price edit and stock adjustment permissions.
  4. Keep owner admin access separate from daily cashier access.
  5. Check backup and cloud users during the same audit.
  6. Review sensitive activity reports after every permission change.

What each person sees

Cashier

Bills normally but cannot quietly change sensitive parts of the business.

Manager

Approves exceptions with accountability.

Owner

Knows who can touch money, stock, reports, backup and cloud data.

Mistakes to avoid

Avoid these during rollout

  • Sharing one password across all staff.
  • Leaving old support or staff accounts active.
  • Giving cashiers admin access for convenience.
  • Not reviewing refunds, voids and discounts.
  • Assuming cloud users and local users are the same list.

Questions

How often should POS permissions be audited?

At least monthly for busy businesses and immediately after staff changes, branch openings or support handover.

Which permissions are most sensitive?

Refund, void, discount, price edit, stock adjustment, item deletion, report export, backup restore and cloud admin access.

Should owners use admin login for daily billing?

No. Keep admin access for configuration and use a lower-risk login for daily checks.

Where Posnic fits

Posnic Community Edition is the free open-source local POS for billing, stock, tax setup and daily operations. Posnic Cloud is only needed when a business wants branch sync, managed backups, remote dashboards or connected ordering workflows.