Invite staff and assign roles

IVPrior uses role-based access so owners can delegate work without sharing the owner account.

Screen overview

Users and invites team management screen

Figure: Users & invites — invite teammates and assign roles per Location.

What each role means

Every tenant user has exactly one role, and every role except OWNER can also be scoped to specific Locations (see the Locations column in the table). A user only sees and works with the Locations assigned to them.

OWNER

Full control of the tenant: billing/subscription, all Locations, all users (including inviting other staff), and every setting. There is always at least one OWNER; it cannot be assigned from the invite/edit form — it is set when the tenant is created.

ADMIN

Day-to-day operations across the business: menu, orders, dispatch, settings, and (unless further restricted) user management. The closest role to OWNER without billing control.

MANAGER

Runs one or more Locations: orders, dispatch, menu edits, and reports for their assigned Locations, without full tenant-wide settings access.

STAFF

General front-of-house / back-of-house work scoped to their assigned Location(s): taking and managing orders, limited menu tasks.

KITCHEN

Focused on the kitchen display and order preparation flow — accepting, preparing, and marking orders ready, scoped to their Location(s).

CASHIER

Focused on checkout and payment-related tasks at the counter, scoped to their Location(s).

Exact screens available to each role can evolve as IVPrior adds features; always review what a user can access right after inviting them, especially for a new role.

Custom roles (Settings → Access → Roles)

Besides the system roles above, the tenant can define custom roles under Settings → Access → Roles. Those roles appear in the invite/edit Role picker by name.

  • Custom roles always require at least one Location.
  • Permissions come from the IVPrior global catalog — tenants choose which keys a role has, but do not create new permission keys.
  • OWNER cannot be assigned from invite/edit; inactive roles do not appear in the picker.

Invite a team member

  1. Open Settings → Users & invites in the admin sidebar.
  2. Click Invite user — IVPrior opens the invite wizard at /settings/users/new (full page, not a modal).
  3. Enter their email, first and last name, and Role (system or custom). Role controls which screens and actions they get; see “What each role means” above.
  4. Choose Locations they can access (empty = all Locations for ADMIN; other roles typically need at least one). Location scope limits orders, menu, and ops data they see.
  5. Click Send invitation — they accept via the email link, optionally add a profile photo, and set their password.

Edit an existing user

  1. From the Users list, open the row menu ⋮ → Edit user.
  2. IVPrior opens /settings/users/{id} with a three-step wizard:
    • Profile — name and profile photo (avatar). Email stays read-only.
    • Access — role and Location scope (same meaning as invite).
    • Security — optional new password (leave blank to keep the current one).
  3. Use Save or Save and close. Pending invites are not edited here — use Resend or Revoke on the list.

An invited user shows status Pending invite until they accept; you can Resend the invitation or Revoke it before that.

Fine-tune permissions per user (Permission overrides)

Below Role and Locations (invite wizard, or the Access step when editing), a Permissions matrix lists every permission that role grants, grouped by resource. It lets you customize a single user's access without creating a new role:

  • Checked = the user has the permission (either from the role, or added on top of it).
  • Unchecked = the user does not have the permission (either the role never had it, or you removed it for this user).
  • Checking a permission the role doesn't include creates a GRANT override for that user; unchecking one the role does include creates a DENY override. Only the differences from the role's defaults are stored — everything else keeps following the role.
  • Use Select all / Deselect all per resource group, or the search box to jump to a specific permission by name or key.

Changing the Role resets the matrix. Because a different role has a different baseline, switching roles discards any GRANT/DENY overrides and starts from the new role's default permissions — this matches what happens on save (IVPrior clears stored overrides for that user when the role actually changes).

OWNER is locked. Since OWNER always has full access, the permissions matrix is shown as read-only (all permissions checked, no editing) for OWNER accounts — overrides do not apply to OWNER.

Security practices

  • Give the minimum role needed for the job — prefer a custom role with only the permissions required, or MANAGER/STAFF/KITCHEN/CASHIER instead of ADMIN when full access isn't needed.
  • Manage custom roles under Settings → Roles — see Tenant Roles.
  • Remove access promptly when someone leaves the business (deactivate, or delete if they have no activity tied to their account).
  • Keep OWNER accounts limited to trusted business owners.

Plan limits

If your plan is at capacity, IVPrior blocks new locations or invites and points you to Billing to upgrade.