How to set up staff logins, roles and permissions

Last updated: September 23, 2026

This guide explains how to control what your staff can see and do in the VenueSumo back office. It covers creating logins, customising access for a whole role or for one person, and the system-wide settings that apply to every login of a certain type.

How permissions work

Every staff member has a login, and every login has a login type (e.g. Manager, Supervisor). Each login type comes with a default set of permissions, called roles. VenueSumo has over 190 of these, covering every area of the back office.

You can customise access in two ways:

Option 1: Role-based

Option 2: Login-based

How it works

Change what a login type can access. Every staff member with that login type gets the change.

Change access for one staff member without affecting anyone else.

Best for

Tier-based staffing where everyone at the same level needs the same access

Staff with varied or complex needs, where two people at the same level need different access

Where

Settings > Roles

Settings > Logins

You can use both options at once, e.g. Option 1 for gate staff and Option 2 for departments that need individual control.

⚠ Global Configuration settings sit above both options. Some sensitive permissions, such as amending past bookings, are set for an entire login type and can't be changed for one person. See Global Configuration permissions below.

Login types and default access

VenueSumo has a fixed set of login types. You can't create new ones, except Report Roles (see below).

Section / Feature

Administrator

Venue Manager

Senior Manager

Manager

Supervisor

Operator

Dashboard

✅

✅

✅

✅

✅

Dashboard / QuickLinks > Create new handover note

✅

✅

✅

Dashboard / Venue Summary widget

✅

✅

✅

Orders

✅

✅

✅

✅

✅

Orders / New Orders

✅

✅

✅

✅

✅

Orders / Bookings

✅

✅

✅

✅

✅

Orders / Bookings / Availability

✅

✅

✅

Orders / Bookings / Blocked Capacity

✅

✅

✅

Customers / Members

✅

✅

✅

✅

✅

Operations

✅

✅

✅

Operations / Products

✅

✅

✅

Operations / Facilities

✅

✅

✅

Operations / POS Facilities

✅

✅

✅

Operations / Events

✅

✅

✅

Reports

✅

✅

✅

✅

✅

Stock

✅

✅

✅

✅

✅

Forms

✅

Settings

✅

  • Administrator has access to everything, and its access can't be changed.

  • POS Operator is for floor and gate staff. Most of your staff will only need a POS Operator login with a PIN.

  • POS Terminal is a separate login for each POS device, used to log in to the POS Facilities you've set up. Staff then use their PIN at that terminal, so their actions are logged against them.

Create a login

  1. Go to Settings > Logins.

  2. Click + New Login.

  3. Enter the staff member's name, email and a temporary password. Ask them to reset it the first time they log in.

  4. Choose a Login Type. The default permissions for that type are applied automatically.

  5. (Optional) To customise this person's access, see Option 2.

  6. Issue a PIN if they need POS access.

  7. Click Save. Access is live immediately.

💡 You can only create logins for login types lower than your own.

Option 1: Customise access for a whole login type

Use this when everyone at the same level should have the same access.

View roles

Go to Settings > Roles.

You'll see every role and the login types that have access to it. You can search by role name, category or login type, and page through the list.

Edit a role

  1. Click the role's row. A panel opens showing which login types have access.

  2. Add or remove login types.

  3. Click Save to apply the change, or Cancel to close without saving.

The change applies immediately to every staff member with that login type. Ask one of them to refresh or log out and back in to confirm.

Option 2: Customise access for one staff member

Use this when two people with the same login type need different access.

  1. Go to Settings > Logins and click the staff member's name, or create a new login.

  2. Choose the closest matching Login Type and save.

  3. Set Override Default Roles to Yes. The full list of permissions appears.

  4. Use the Login Type drop-down to move between permission categories: Customers, Dashboard, Forms, General, Operations, Orders, Reports, Settings and Stock.

  5. Tick or untick permissions as needed.

  6. Click Save, then ask the staff member to log in and check their access.

💡 To undo individual changes, set Override Default Roles back to No and save. The login resets to the default permissions for its login type.

Keep a Permissions Register

If you use Option 2, keep a simple internal register so new staff get consistent access. Here's an example:

Department

Login type

Key access enabled

Key access disabled

Finance

Administrator

Full access, refunds, past amendments, reporting

N/A (review Global Configuration carefully)

Sales

Senior Manager

Bookings, agents, contracts, availability

Settings, Forms

Marketing

Senior Manager

Operations, products, facilities, events, templates

Settings

Duty Managers / Shift Leads

Manager

Orders, reports, day/date management, login management

Settings, Forms

Gate Staff

Supervisor

Cash reconciliation, EFTPOS/cash refunds, discounts

Settings, Forms, Operations

Executives

Administrator

Full access

N/A

Store it somewhere only Administrators can access, and review it regularly.

When onboarding a new staff member under Option 2:

  1. Identify their department and level.

  2. Find the agreed access for that department in your register.

  3. Create their login, choose the login type and set Override Default Roles to Yes.

  4. Set their permissions to match the register, save and check with the staff member.

  5. Update the register if you agreed any changes.

Report Roles

Report Roles are the one type of role you can create yourself. They control which reports each login type can see.

To create one: go to Settings > Roles and click New Report Role in the top right-hand corner.

To edit one: click the report role's row. You can change its name, the login types it applies to and which reports it includes. You can also filter reports by category.

Click Save to apply the change, or Cancel to close without saving.

Global Configuration permissions

Some sensitive permissions are set in Settings > Global Configuration and apply to an entire login type. If you add a login type to one of these fields, every login of that type gains that ability, including logins created later. You can't remove it for one person without removing it for the whole login type.

Permission

What it allows

Amend Past Bookings / Transactions

Change records from past dates

Create FOC Bookings/Orders

Put through free-of-charge (complimentary) orders

Discounting / Price Overrides

Apply discounts and override prices

Voucher Expiry/Usage

Change a voucher's expiry date or redemption quantity

To change one:

  1. Go to Settings > Global Configuration.

  2. Find the permission field. It shows which login types currently have access.

  3. Add a login type to grant access, or remove it to restrict access.

  4. Click Save. The change takes effect immediately, so test with a login of the affected type.

⚠ For example, adding Supervisor to Amend Past Bookings gives that ability to every Supervisor. If only one person needs a Global Configuration permission, give that person a higher login type instead of adding a whole login type to the field.

Online refund permission

Permission to refund online payments is set separately for each login. It covers payments made through your online booking site, payment links and live payment links. It doesn't cover EFTPOS or cash refunds.

  1. Go to Settings > Logins and open the staff member's login.

  2. In the Details section, find Allow Online Refund.

  3. Set it to Yes to allow online refunds, or No to block them. If you're unsure, choose No.

  4. Click Save. The change is immediate, so let the staff member know.

FAQs

A staff member can't see something they need. How do I fix it?
If you use Option 1, go to Settings > Roles and add their login type to the role. If you use Option 2, go to Settings > Logins, open their login, set Override Default Roles to Yes and tick the missing permission.

Can I give one person extra access without changing everyone else's?
Yes. Use Option 2 and set Override Default Roles to Yes on their login. The exception is Global Configuration permissions, which can't be set per person.

Can I give one person a Global Configuration permission only?
No. These apply to the whole login type. The workaround is to give that person a higher login type.

Can I create a new login type?
No. You can only create Report Roles. All other customisation happens within the existing login types.