Who Can Void a Sale? POS Permissions That Protect Your Takings
28 August 2026 · MidaOne
Most café owners set up their POS in an afternoon, hand every member of staff the same login, and never think about it again. It works fine until the first evening the till is short and there is no way to tell whether it was a mistake, a rushed refund or something worse. The problem is rarely that someone is stealing. It is that nobody can prove they aren't, which is a miserable position to put a good team in.
What a cashier actually needs to do the job
Start from the opposite end of where most people start. Instead of asking what to lock, ask what a cashier genuinely needs on a busy morning: ring up a sale, take cash or card, apply a discount you have already decided on, print a receipt, and open a new shift. That is the whole list for most cafés. Everything else — changing what a product costs, editing stock counts, opening the accounting screen, adding a member of staff — is work that happens away from the counter, usually by you.
This matters because over-locking is its own kind of problem. If a cashier has to phone you to pair a receipt printer or correct an obvious typo in an order, you have not made the café safer. You have made yourself the bottleneck, and you will end up handing out your own password to get through a rush, which is worse than having given them the permission in the first place.
The four actions worth putting behind a manager
There is a small set of till actions where the money moves in a direction that no sale explains. These are the ones to think about properly.
| Action | Why it needs care | Sensible default |
|---|---|---|
| Void or cancel a sale | Removes a recorded sale, and with it the reason the cash drawer opened | Allowed, but recorded against the person who did it |
| Refund a completed sale | Takes cash back out of the till after the customer has gone | Manager or owner, or at minimum reviewed daily |
| Change a price at the till | Turns your menu into a suggestion and quietly breaks your margins | Owner only — cashiers apply set discounts, they don't invent them |
| Edit stock counts | Makes a shortage disappear from the record rather than explaining it | Manager or owner, never the person who just counted |
Notice that only one of those is a hard no. A cashier who cannot void a mis-punched order will find another way around it — ringing the correct item and pocketing the difference, or simply not ringing the sale at all — and both are far harder to see than a void with a name on it. The aim is not to prevent the action. It is to make sure the action leaves a mark.
The record matters more than the lock
This is the part owners underestimate. A permission that stops something happening tells you nothing on the evening it doesn't happen. A record that shows what happened, when and under whose login is what actually lets you manage — because it turns a vague worry into a specific conversation, and most of those conversations end with a genuine explanation.
So when you look at any POS, look past the permissions screen and ask what the system keeps: are sales attributed to the person who rang them, are refunds and voids visible after the fact, and does a shift close show what was expected against what was counted? That last one does more work than any lock. A till that reconciles itself every shift surfaces a problem within a day, while a monthly review surfaces it long after anyone can remember the evening in question — which is the whole argument for a daily cash-up routine.
The same logic applies to stock. Most of what goes missing in a café is not taken; it is over-poured, given away, or dropped and never recorded. Permissions on stock edits are useful mainly because they keep the count honest enough to be worth reading, which is where finding out where stock actually disappears starts.
When there is more than one branch
Permissions get more interesting the moment you open a second location. A supervisor at branch one has no business editing branch two's menu or reading its takings, and the person who covers both sites needs to see both without becoming a second owner. Look for permissions that are scoped by branch as well as by role, rather than a single account per location that you then have to keep in sync by hand — one of the things worth checking before you commit to a system for more than one branch.
Setting this up without treating your team like suspects
How you introduce this decides how it lands. Framed as a response to a suspicion, it poisons a shift. Framed as what it actually is — every action has a name on it so that nobody carries the blame for someone else's mistake — it tends to be welcomed, particularly by the staff who have been on the receiving end of a vague accusation before.
- Give everyone their own login. A shared password makes every other control decorative, and it is the single most common gap in small cafés.
- Set permissions when you hire, not after an incident. Changing someone's access the week after a bad shift says something you probably don't mean.
- Write down who may refund and up to what. An unwritten rule is an argument waiting for a Friday night.
- Review the exceptions weekly, not the people. Voids, refunds and discounts are worth ten minutes on a Sunday; individuals are not worth watching.
- Remove access the day someone leaves. This is the one that gets forgotten, and it is the one that matters most.
Cover the permission rules during induction rather than leaving people to discover them mid-rush — it takes about two minutes inside the hour it should take to train someone on the till, and it saves the awkward moment where a new cashier taps something and gets a refusal they weren't expecting.
How MidaOne handles roles and permissions
MidaOne has three roles — owner, manager and cashier — and the owner grants access to each part of the system separately: the till, the day's report, products, inventory, customers, suppliers, purchases and accounting are each their own permission rather than one all-or-nothing switch. Only the owner can add or edit staff, and the owner can't be locked out of their own café. Managers can set up the named discounts; cashiers can apply them at the till but can't change what one is worth. Permissions are scoped by branch as well as by role, so a supervisor at one location doesn't inherit another.
On the record side, sales are attributed to the employee who rang them, the day's report shows how many sales were refunded or voided and leaves them out of the day's totals, and shift closes show cash expected against cash counted with the difference. All of it is included in the flat AED 200 a month, along with unlimited devices — so giving each person their own login never costs extra, which removes the most common reason cafés share one.
Give every member of staff their own login and their own permissions. Free for 14 days, no card.
Start your free trialFrequently asked questions
Should cashiers be allowed to void a sale?
In most small cafés, yes — mis-punched orders are constant and blocking the fix creates worse workarounds. What matters is that the void is recorded against the person who made it and that you look at the day's voids as a routine, rather than only after something goes wrong.
Who should be able to issue a refund in a café?
Refunds move cash out of the drawer after the customer has left, so most owners restrict them to a manager or to themselves. If your opening hours make that impractical, the workable compromise is to allow it and review every refund the same day rather than leaving it unexamined.
Does every member of staff need their own POS login?
Yes, and it is the single most valuable control on this list. Without individual logins, nothing else is attributable — every sale, void and refund belongs to the same anonymous account, so you can see that something happened but never who was on the till.
How do I stop staff giving away free drinks?
Make the legitimate route easy and recorded — a named staff-drink or comp option at the till — so nobody has to improvise. Then read the totals weekly. Free drinks handled openly are a cost you can size and manage; free drinks handled quietly show up as stock that doesn't match sales.
What should I ask a POS vendor about permissions?
Ask whether permissions are per person or only per role, whether they can be scoped by branch, whether sales and refunds are attributed to the individual who performed them, and what the shift close actually shows. Those four answers tell you more than the feature list does.
Almost every café that ends up with a serious till problem had the same starting point: one login, no attribution, and a genuine reluctance to seem distrustful. The fix costs nothing and is far friendlier than it sounds. Give people their own access, keep the small set of actions that move money visible, and you will spend far less time wondering and far more time knowing.