Skip to content
Help

Staff and invitations

Inviting people, assigning branches, and removing access.

Team & operations3 min read

#Inviting

Staff → Invite. Enter an email, pick a role, and assign branches. Restro sends an invitation link.

Invitations are pending until accepted, and expire. You can resend or revoke one at any time from the staff list.

The person does not need a Restro account first — accepting the invitation creates one.

#Seats

Your plan caps how many staff seats you may fill. Pending invitations count against the cap, because they are about to become people. If an invite is refused with a limit message, either revoke an unused invitation or upgrade in Settings → Plan.

#Assigning branches

Assignment happens at invite time and can be changed later from the staff member's row. For roles that are branch-scoped, an empty assignment means an empty dashboard — always assign at least one.

#PINs and terminals

Staff apps — the point of sale, the kitchen display, the waiter and driver apps — run on a paired terminal rather than a personal login. Pairing binds the device to one restaurant and one branch; after that, individual staff sign in with a short PIN so a shift handover takes seconds instead of an email round-trip.

A PIN is not a password. It is only ever accepted on a device that is already paired, and only for someone who works at that restaurant and has access to that branch. It never signs anyone in over the open internet, it is stored hashed, and it is never shown back to anyone — including you.

  • Setting one — a member sets their own PIN from Settings → Devices, or from the account sheet in any staff app.
  • Resetting one — a manager can clear a forgotten PIN from the staff member's row. The member then sets a new one; nobody can read the old one.
  • One per restaurant — a PIN is never shared across restaurants, so working at two never means one PIN opens both.
  • Wrong guesses — repeated failures lock that member out on that terminal for a cooling-off period and raise an alert. Four digits are only safe because the attempts are bounded.

An idle terminal locks itself back to the staff picker without unpairing, so the next person just taps their name. How quickly depends on the app: a till locks in about a minute, a kitchen display never does.

Everything done after signing in is attributed to that person — the orders, the tips, the cash, the voids.

#Removing access

Removing a staff member revokes their access immediately, including their PIN and any signed-in terminal session. That includes screens they already have open — dashboard tabs and any terminal they are signed in to are signed out within seconds, not on their next click. Changing someone's role has the same reach: if the new role no longer covers an app, they are signed out of it.

Their history stays: orders they took, cash sessions they ran, and activity log entries all keep their name, because removing a person should not rewrite what happened.

If they were signed in to a terminal that still holds orders waiting to send, those orders stay on the terminal and the lock screen says how many. They send if that person signs in again. If they cannot — because you have removed them — a manager can discard them from Account on the terminal. Nothing is dropped without someone choosing to drop it.

Did this page miss something? Tell us.

Back to top