# Permissions reference

> Every permission, what it allows, and which built-in roles have it.

Source: https://sofra.tablixai.com/docs/permissions-reference

Section: Reference

Permissions are strings in the form `area:action`. A role is a list of them. “All branches” means the permission applies across the branches the person can access.

> **Reading the table:** O = Owner, M = Manager, BM = Branch Manager, C = Cashier, W = Waiter, K = Kitchen.

## Orders

| Permission | Allows | Roles |
|---|---|---|
| orders:read | View orders (own only, without read_all). | O M BM C W K |
| orders:read_all | View every order in the branch. | O M BM C K |
| orders:write | Create and edit orders, take payment, hold, move, add items. | O M BM C W |
| orders:delivery | Create and see delivery-fulfilment orders. | O M BM C |
| orders:online | Online, QR and external-channel orders. | O M BM C |
| orders:void | Void items and orders, cancel kitchen items, approve cancel requests. | O M BM |
| orders:refund | Refund paid orders. | O M BM |
| orders:discount | Apply or remove discounts. | O M BM C |
| orders:status | Change order and item status. | O M BM C W K |
| orders:cancel | Cancel orders. | O M BM |

## Floor, tables and bookings

| Permission | Allows | Roles |
|---|---|---|
| tables:read / read_all | View tables (only your own, or all). | read: O M BM C W · read_all: O M BM C |
| tables:write | Create and edit tables, change status, merge tables (managers). | O M BM W (merging and blocking need read_all) |
| floor:read / floor:write | View and edit floor areas and the floor plan. | read: all but K · write: O M BM |
| reservations:read / read_all / write | View, view all and manage reservations. | read: O M BM C W · read_all: O M BM C · write: O M BM C W |
| walk_ins:read / read_all / write | Walk-ins. | As reservations |
| waitlist:read / read_all / write | Waitlist. | As reservations |

## Catalog, branch menu and settings

| Permission | Allows | Roles |
|---|---|---|
| menu:read / menu:write | Branch-level menu visibility. | read: all · write: O M BM |
| catalog:read | View the global catalog. | O M BM |
| catalog:write / catalog:delete | Create, edit and delete menus, categories, items, modifier groups. | O M |
| branch_menu:read / write | Assign menus and override items and prices per branch. | O M BM |
| settings:read | View taxes, discounts, coupons, service charges, payment methods and prep settings. | O M BM |
| settings:write | Change those settings. | O M |

## Kitchen, printing and documents

| Permission | Allows | Roles |
|---|---|---|
| kitchen:view / update | See the kitchen display; act on tickets. | O M BM K |
| printing:view | See printers and rules. | O M BM C K |
| printing:print / reprint | Print and reprint tickets. | O M BM C W K (reprint: not W) |
| printing:manage_printers / manage_rules | Add printers, agents and rules. | O M BM |
| printing:view_jobs / retry_jobs / cancel_jobs | See and manage the print queue. | O M BM · K can view and retry |
| documents:view / view_all | See bills, receipts, invoices (own, or all). | view: O M BM C W · view_all: O M BM C |
| documents:create / finalize / print / reprint | Create, number and print documents. | O M BM C (W: create, finalize, print) |
| documents:void | Void a finalized document. | O M BM |
| documents:templates_manage | Edit and select templates. | O M BM |

## People and management

| Permission | Allows | Roles |
|---|---|---|
| inventory:read / write | View and manage inventory and recipes. | O M BM |
| staff:read / write / delete | View, add and edit, and remove staff; shifts and attendance. | O M · BM read, write |
| customers:read / read_all / write | Customers. | read: O M BM C W · read_all: O M BM C · write: O M BM C |
| departments:read / write | Departments. | read: O M BM · write: O M |
| reports:read | Reports. | O M BM |
| billing:read | View subscription, usage and invoices. | O C |

> **Note:** Owner-only actions (not controlled by permissions): adding and editing branches, creating and editing roles, changing a staff member’s tenant role, and changing the subscription plan.