Posnic Open Source POS

Retail POS User Access Review Checklist

Review who can use the POS, what each identity can do, and whether access still matches the person's job and the store's operating model.

Build the access register

Review joiners, movers, and leavers

Test sensitive POS actions

ActionReview questionEvidence
Discounts and overridesCan only approved roles change a price or apply a discretionary discount?Test transaction, user, reason, and approval.
Voids, refunds, and returnsAre completed-sale changes attributable and independently reviewable?Original sale, action, operator, reason, and reviewer.
Cash drawer and closeAre manual opens, cash movements, and closeout changes restricted?Drawer event, shift, variance, and approval.
Stock and purchasingCan staff alter quantity, cost, receiving, or supplier records beyond their duties?Before and after values, operator, source record, and review.
Reports and exportsAre customer, sales, tax, and staff exports limited to people who need them?Export type, requester, time, and purpose.
Settings and integrationsCan only administrators change taxes, payments, synchronization, backups, or API credentials?Change, approver, validation, and rollback plan.

Check real operating conditions

Reconcile and repeat

Investigate dormant, duplicate, excessive, or unexplained access instead of merely recertifying it.

Compare the register with current staff, contractors, locations, devices, integrations, and support arrangements. Record removals, reductions, exceptions, owners, due dates, and completion evidence. Repeat after material changes and on a defined schedule.

Posnic is offline-first open source POS and Billing Software for retail shops and restaurants. Review the public Posnic/POS source repository and test access controls in the exact version and deployment you plan to use. This checklist is operational guidance, not a certification or substitute for legal, accounting, employment, privacy, or security advice.