Skip to content

Roles and permissions

A role answers two questions at once: what shifts someone can be scheduled for, and what they can see and change in the app.

Owner. Full access across every store in the business, including payroll and business settings. Owners are the only people who can change pay rates and submit payroll.

Manager. Full operational access at the stores they are assigned to: build and publish schedules, edit and approve timecards, add and deactivate employees. Managers do not see other stores.

Employee. Their own schedule, their own timecards, and their own pay statements. Nothing about anyone else.

This is the part that surprises people. Access is granted store by store, so the same person can be a manager at one location and an hourly employee at another. Their role is whatever their assignment at that store says — there is no single account-wide rank.

The practical consequence: if a manager says they cannot see a schedule or approve a timecard, the answer is almost always that they do not have manager access at that store, not that something is broken. See Manage store access.

Clockout hides what you cannot use, but the real check happens on the server for every action. You cannot get to someone else’s pay statement by guessing a URL, and a stale browser tab does not carry old permissions.

Change it on their profile. The change takes effect immediately; it does not alter anything they did under the previous role — past approvals and edits keep the identity that made them. To take access away entirely, deactivate rather than delete, so their timecards and pay history survive — see Add a team member.