Users & Roles
A Pickpad account can have several users. Everyone signs in with their own email and password, and their role decides what they can see and change in the dashboard and the API.
The person who registers the account becomes its first Administrator.
Roles
| Role | Meant for |
|---|---|
| Administrator | Owners and managers who run the whole account, including settings and the team |
| Manager | Shift leads and kitchen staff who run day-to-day operations |
| Integrator | Partners or developers connecting a POS or another system through webhooks and the API |
What each role can do
| Area | Administrator | Manager | Integrator |
|---|---|---|---|
| Stations | Full | Full | View |
| Pickpads (add, rename, calibrate, tare, unbind…) | Full | Full | View |
| Clusters | Full | Full | View |
| Orders & queue (create, accept, mark ready/finished, cancel) | Full | Full | View |
| Catalog | Full | Full | View |
| Screens | Full | Full | — |
| Notifications (text message scenarios) | Full | — | — |
| Message history | Full | — | — |
| Data insights | Full | — | — |
| Settings — General (distribution, accuracy, queue, timezone) | Full | — | — |
| Settings — Webhooks | Full | — | Full |
| Settings — Order source / integrations | Full | — | View |
| Settings — API keys | Full | — | Full |
| Team (users) | Full | — | — |
Full means create, view, edit and delete. View means read-only. — means the area is hidden.
What the dashboard shows follows these rights:
- Sidebar entries you can't view are hidden. Opening Settings, Team or Message history directly without access takes you back to Stations.
- On view-only pages every field is read-only, and Save, Create and Add buttons are hidden.
- Delete buttons only appear if you're allowed to delete.
- Settings opens if you can view at least one of its sections. Sections you can only view are shown read-only.
Station and cluster access
A user can be limited to specific stations and clusters under Access scope on their user page. Leave a list empty to allow all of them.
A user limited to stations only sees those stations in the station list, and is refused when opening or changing any other station. Cluster limits work the same way for clusters.
Managing the team
Administrators manage users under Team in the sidebar:
- Add new: enter email, name, password and role, and optionally the access scope.
- Edit: change name, role or scope, or set a new password with Reset password.
- Active / Inactive: the toggle next to the User heading. An inactive user is signed out on their next request and can't log in, but their history stays.
- Delete: removes the user completely. Prefer deactivating if you want to keep their history.
A few rules keep an account from locking itself out:
- Every account keeps at least one active Administrator. The last one can't be demoted to another role, deactivated or deleted.
- You can't change your own role, deactivate yourself or delete yourself.
Each email can belong to only one Pickpad user, across all accounts. Emails aren't
case-sensitive: Mia@Example.com and mia@example.com are the same user.
Your profile
Click your avatar in the header to open Profile. There you can see your role, change your own password (enter the current one first), and switch between the light and dark themes.
API access
Tokens from POST /account/login belong to the user
who logged in, so API calls get exactly that user's rights. A forbidden call returns
403 Forbidden, and the API reference lists the permission each endpoint needs.
GET /account/me returns the signed-in user as actingUser, with their role and effective
permissions.