
Payments & Reconciliation
POS security and controls
Set POS access by role, protect administrator accounts, review transaction exceptions and remove access when staff leave.
A useful POS security setup answers four questions: who can sign in, who can approve an exception, who reviews sensitive actions, and who removes access when duties change.
Write down the answer for each location and for both the till and its administration account.
Assign access by task
List the actions staff need: completing sales, applying discounts, issuing refunds, voiding unpaid tickets, handling cash, changing products and prices, viewing reports, and managing users. Give routine checkout access to the people serving customers. Reserve broader settings and staff management for named, authorised people.
Use individual staff identities where the system supports them. On Square, a shared team passcode does not track activity by team member.
Shopify POS staff use unique PINs. On the POS Pro plan, custom POS roles can give POS staff a defined set of permissions for POS app activities. POS app-only staff are available to merchants using Shopify POS Pro and can log in only at POS Pro locations. Record the subscription and location alongside the access plan.
Define approval and review
Set a business rule for discounts and refunds before configuring permissions. A discount before payment, a void of an unpaid ticket and a refund of a completed payment are different actions. Staff should be able to refer an exception to an authorised person without using that person's PIN.
Decide which records a reviewer needs for each action: the original order, amount, staff identity, reason and approval where available. Check what the POS actually retains. Square records its open-ticket void in Dashboard; that void closes an unpaid ticket and is not a completed-payment refund.
Shopify's POS activity log captures voids, refunds and manual discounts, but excludes cash drawer operations and failed or cancelled actions. Cash activity therefore needs its own record.
Review exceptions for a defined period and location. Inspect the underlying transaction or drawer session before drawing a conclusion. An unusual count or an unexplained difference is a reason to investigate, not evidence of misconduct.
Protect accounts and devices
Give administrators their own accounts, unique credentials and an available second authentication step. Keep those credentials away from the counter. After an administrator uses a shared device, return it to the staff PIN or lock screen before the next person serves a customer.
Set a practical passcode timeout where the POS provides one. Restrict who can change device settings and keep supported software updated. Limit account access to each person's duties, avoid shared accounts where possible and enable multifactor authentication where available. Account authentication and a till PIN are separate controls.
Limit top-level access
Treat the owner account as the highest-access identity, not a routine staff login. Square recommends giving owner-level access only to the most trusted people; its Full Access permissions include access to sales reports and team-member permissions.
Check what the POS plan allows before promising separate permission sets.
Square Shifts Free and Square for Restaurants Free subscribers can create one custom permission set; Square Shifts Plus and Square for Retail Plus subscribers can create two. Square Advanced Access, Square for Restaurants Plus and Square Appointments Premium subscribers can create unlimited custom permission sets.
Square permission sets are managed in Square Dashboard. Team members can access and manage data only for their assigned locations.
When a team member is assigned Full Access, Square also designates them as an authorised representative. Treat that setting as a material change to business authority.
Make location access explicit
Document each person's assigned POS locations separately from their general account access. In Shopify, a staff member added through the POS app is assigned to that device's location. Someone added in Shopify admin is assigned to all locations unless specific locations are removed.
A Shopify POS location assignment restricts where a staff member can use their PIN. It does not necessarily restrict all data they can see. Staff can view product inventory for all locations. Viewing or editing orders from other locations depends on the Manage orders at all locations permission.
Distinguish POS app access from Shopify admin access when setting up staff. Shopify POS app-only staff are available to merchants using POS Pro and can log in only at POS Pro locations. Staff with both POS and admin access can use the POS app at POS Pro and POS Lite locations and access Shopify admin.
Use auditable identities and records
Set an expectation that staff actions are performed under the identity of the person doing the work. Shopify records each activity-log event under the staff member logged in at the time. Each event includes the date, time, location and staff member's name. The log retains events for one year and cannot be exported from Shopify admin.
For actions requiring manager approval in Shopify POS, the activity details record both the staff member who performed the action and the approving manager. The approval is part of the action's event details, rather than a separate activity-log event.
Keep POS app activity distinct from administration activity when assigning review responsibility. Shopify POS's activity log covers actions in the POS app. Actions taken directly in Shopify admin, such as deleting a product or changing a store setting, are reviewed through Shopify admin activity logs.
Remove and recheck access
When a person leaves or changes duties, update their POS and administration access. Check connected services or shared credentials they used. Change a shared secret they knew. Preserve historical transaction records through the provider's supported process.
Have an authorised person check permitted and restricted actions with the actual staff roles, plan and locations. Record the result and any gap. Repeat the review after changes to roles, subscriptions, devices or branches.
In this guide
- Assigning permissions for refunds and discountsBuild POS permissions for discounts and refunds, define approval points and check restrictions on the actual plan and location.
- Reviewing voids and cash adjustmentsReview POS voids and cash adjustments using the right records, trace exceptions and keep unexplained differences open.
- Removing former staff from POS accessClose a departing worker’s POS, admin and connected-service access, change shared secrets and check the result.
- Protecting administrator accounts on shared counter devicesSeparate POS administrator login from staff PIN use, protect account credentials and set a shared-counter handover.


