Retail POS User Access Review Checklist
Review who can use the POS, what each identity can do, and whether access still matches the person's job and the store's operating model.
Build the access register
- Record every staff, manager, administrator, service, integration, and support account.
- Name an owner for each account and role; investigate accounts with no current owner.
- Record the locations, tills, reports, settings, APIs, and administration tools each identity can reach.
- Separate individual accounts from emergency, device, service, and integration identities.
Review joiners, movers, and leavers
- Give new staff only the permissions needed for their current duties.
- Recheck access after a role, location, employment, or supplier relationship changes.
- Disable departed or suspended users promptly while preserving required transaction history.
- Expire temporary access and retain its approver, purpose, and end time.
Test sensitive POS actions
| Action | Review question | Evidence |
|---|---|---|
| Discounts and overrides | Can only approved roles change a price or apply a discretionary discount? | Test transaction, user, reason, and approval. |
| Voids, refunds, and returns | Are completed-sale changes attributable and independently reviewable? | Original sale, action, operator, reason, and reviewer. |
| Cash drawer and close | Are manual opens, cash movements, and closeout changes restricted? | Drawer event, shift, variance, and approval. |
| Stock and purchasing | Can staff alter quantity, cost, receiving, or supplier records beyond their duties? | Before and after values, operator, source record, and review. |
| Reports and exports | Are customer, sales, tax, and staff exports limited to people who need them? | Export type, requester, time, and purpose. |
| Settings and integrations | Can only administrators change taxes, payments, synchronization, backups, or API credentials? | Change, approver, validation, and rollback plan. |
Check real operating conditions
- Test permissions on the exact desktop, browser, handset, and back-office paths staff use.
- Verify that Offline POS operation does not silently bypass authorization or lose attribution.
- For Online/Offline POS deployments, test access against local and hosted servers and after synchronization resumes.
- Avoid shared staff accounts. Where a device identity is unavoidable, keep staff actions separately attributable.
- Confirm passwords, sessions, recovery methods, support access, and stored credentials follow the organization's policy.
Reconcile and repeat
Investigate dormant, duplicate, excessive, or unexplained access instead of merely recertifying it.
Compare the register with current staff, contractors, locations, devices, integrations, and support arrangements. Record removals, reductions, exceptions, owners, due dates, and completion evidence. Repeat after material changes and on a defined schedule.
Posnic is offline-first open source POS and Billing Software for retail shops and restaurants. Review the public Posnic/POS source repository and test access controls in the exact version and deployment you plan to use. This checklist is operational guidance, not a certification or substitute for legal, accounting, employment, privacy, or security advice.