Staff and roles
Who may do what, which role you give to whom, how you invite someone, and where you see what each staff member has done and scanned.

You are not doing this alone. The treasurer wants to see the figures, the volunteer at the door has to be able to scan, and your accountant wants to get in once a year. This article explains how to give each of them exactly what they need — and no more.
You find the screen under Settings → Staff. It is visible only to the owner.

What you need beforehand
- The owner role. Only owners see this screen; an administrator does not get to it either, because anyone who can add staff can give themselves rights.
- The email address of every person you want to invite. Preferably the address they read daily.
- An idea of what each person has to be able to do. The table below helps you choose.
- Five minutes per staff member.
If you come across a word you do not know, look in the glossary.
What is a role?
A role is a name for a bundle of rights. Instead of setting twenty tick boxes per person, you give someone a single role and the system then knows immediately what they may do: view orders, issue refunds, change products, scan tickets, and so on.
There are four roles: owner, administrator, desk and scanner. A staff member has exactly one role within one organisation. If you give them another, it replaces the old one — roles do not stack.
Why not everyone may do everything
That sounds distrustful, and it is not. Three reasons, all practical:
- A lost phone. The device at your entrance is in a coat pocket belonging to a volunteer you are seeing for the first time that evening. If that device disappears, there must be nothing to be done with it but scanning tickets.
- A wrong click. Anyone who does not see a Refund button cannot press it by accident. You prevent half of all accidents simply by not showing the button.
- Peace of mind for the staff member. A volunteer who only has to scan does not want a screen full of revenue figures and settings. Fewer buttons means less hesitation.
The four roles
| Role | What they see and may do | What they do not see |
|---|---|---|
| Owner | Everything: settings, payments, staff, products, orders, refunds, reports, gift vouchers, season passes, external passes, point of sale, scanning | Nothing |
| Administrator | Products, prices, time slots, events, discount codes, venues, VAT sets, orders, refunds, invoices to buyers, reports and revenue, gift vouchers, season passes, devices, point of sale and scanning, and the Subscription page with your invoices (view, download, pay), and Support | The settings of the organisation, the payment provider, the list of staff, the external passes, resellers, API access, messages to visitors, and anything that changes the subscription itself: switching plan, cancelling, pausing and setting up the automatic payment |
| Desk | Selling at the desk, opening and closing the till, viewing orders and tickets, scanning, today's tickets and today's revenue on the dashboard | Changing products and prices, issuing refunds, reports, creating gift vouchers, settings, Support |
| Scanner | Only scanning tickets and viewing today's tickets | Amounts, orders, visitors' addresses, products, reports, settings, Support |
Note one difference that surprises people: an administrator may issue refunds and may see your entire revenue, but not touch the settings. A desk user may sell and close the till, but not issue refunds. That is deliberate: a refund is money leaving your organisation.
The subscription works the same way. An administrator may open the Subscription page, view and download your invoices and pay an outstanding one — exactly what a treasurer or an accountant needs. What changes the subscription itself stays with the owner: switching plan, cancelling, pausing and setting up the automatic payment. See Your plan, your invoices and pausing.
Which role do you give to whom?
| Who | Which role | Why |
|---|---|---|
| Yourself, when you set the system up | Owner | You need the settings and the payment provider |
| Your co-chair or second committee member | Owner | Somebody else has to be able to get in when you are ill |
| The treasurer | Administrator | They want the revenue, the orders and the refunds. Connecting the payment provider is not their job |
| Your accountant | Administrator | They need the reports, the orders and your invoices under Subscription, not your settings |
| Whoever maintains the products and prices | Administrator | Products, prices and time slots sit in that role |
| The permanent member of staff at reception | Desk | Selling, opening and closing the till, scanning |
| The one-evening volunteer at the door | Scanner | They scan, nothing more. Even if the phone disappears |
| The student who helps out during the summer | Desk or scanner | Desk if they sell, scanner if they only stand at the entrance |
Note: give the treasurer administrator and not owner, unless they also have to manage the payment provider. Two owners is enough, three is usually one too many.
But always keep at least two owners. One owner is one holiday or one hospital stay away from an organisation nobody can reach the settings of any more.
Inviting someone, step by step
Step 1 — Open the invitation window
Go to Settings → Staff. At the top right is the Invite a staff member button. Click it; a window appears with three fields: Email address, Name and Role.
Step 2 — Fill in the email address
This is the address the person will sign in with. Ask for the address they read daily, not an address belonging to the association that happens to be in their name. Typing errors here produce an invitation nobody ever sees.
Step 3 — Fill in a name if you wish
Optional. The name helps you see who is who in the list. If this person already has an account — because they also work for another organisation — their own name stays and yours is ignored.
Step 4 — Choose the role
Choose from the four roles; Desk is selected by default. Below the drop-down list it says what a scanner may and may not do, and when you are better off choosing desk. What each role may do exactly, you see in one sentence under the role of every staff member in the list. That is the same sentence the person invited gets to read in their email, so that the two of you do not have two different promises.
Step 5 — Send
Click Invite. You get a confirmation that the email has gone out, and the person appears in your list straight away with the status invited.
What the person invited sees in their mailbox
They receive an email from your organisation containing:
- who is inviting them — your organisation name, not the platform's;
- which role they get and what that role may do, in one sentence;
- the Set your password button, with the link repeated below it;
- what they sign in to the scan app with: the organisation code, their email address and the password they choose.
The link in that email stays valid for 7 days. After that, send a new one with Invite again.
What they do: click the link, type a password of their own choosing twice, save. After that they are in. They have nothing to install and nothing to pay. If they are going to scan at the door, they then also install the scanning app and sign in there with the organisation code and the same email address. See Scanning app and scanning staff.
As soon as they have set their password, their status in your list jumps from invited to active, and their email address is confirmed straight away as well.
If that email address already has an account, your organisation is simply added to it; they become active as soon as they sign in for the first time. One sign-in, several organisations, with its own role per organisation. The same person can be an administrator with you and a scanner at the club next door.
Has the email not arrived, or has the link expired? Use the Send the invitation again action in the list; a fresh link then goes out. Have the person check their junk mail folder too. They can also use Forgot password? on the sign-in screen themselves.
How long an invitation is valid
The link in the invitation is valid for 7 days. If it has expired, or the email never arrived, use the Invite again button in the list or on the detail page. A new link is sent, again for 7 days, and the previous one stops working.
An ordinary password reset email is only valid for an hour. That one is meant for someone who has lost their password and deals with it right away, not for an invitation that sits in a mailbox for a few days.
Changing a role
In the list, click Change role next to the right person, choose the new role and confirm. The old role is replaced, not added to.
Two things to know:
- The change is immediate. If the person is signed in at that moment, they notice it as soon as they open a next screen.
- The last owner cannot demote themselves. There always has to be one left, otherwise nobody can reach the settings, the payments and the staff any more — and that can only be undone by a platform administrator. If you do try, you get the message that at least one owner must remain.
The detail page of a staff member
Click someone's name in the list — or the Details action — and you get their own page. Everything about that one person is gathered there: who they are, what they may do, and what they have done.

What is at the top
| What you see | What it means |
|---|---|
| Name and email address | What they sign in with. You cannot change the address here — that is their account |
| Role | Their role with you, with one sentence underneath saying what that role may do |
| Language | The language of their screen and of the emails they get |
| Access | active once they have set their password (or, with an existing account, have signed in for the first time), invited for as long as that has not happened |
| Last signed in | When they were last in here |
| Invited on / Accepted on | When the invitation went out, and when they used it |
| Devices | The devices they have scanned on or worked at the till with |
| Today, This week, Total | How much they scanned, and how much of that was refused |
About those devices: a device belongs to your organisation and not to a person. The phone at the door goes from hand to hand in the course of an evening. What is here is therefore not an assignment but an observation — this is what they have worked on.
What you can change
With the Edit button you adjust three things: the name, the role and the language. Nothing more, and that is deliberate.
You cannot set a password for somebody else. A password two people know is not a password: it goes over the phone, it sits in a group chat, and when something goes wrong later nobody can say any more who it was. Instead there are two buttons:
- Send password reset email — for someone who has been in already and has lost their password. They get a link and choose a new password themselves. You never see that password.
- Invite again — for someone who has never used their invitation. That button disappears as soon as they are in.
There is also the Delete button, which does the same as in the list: their access to your organisation goes, their account and their work stay.
Two limits apply here too: you cannot remove yourself, and the last owner cannot be demoted or removed. If you do try, you get the message that at least one owner must remain.
May everybody see this page?
No. The list of members — with everybody's email addresses — stays reserved for the owner.
But: everybody may open their own page. A volunteer who wants to check how much they scanned yesterday does not have to disturb anyone for it. They then see their own details, their own activity and their own scans — and they cannot change anything there: the Edit button is not there for them.
A colleague's page they do not get to see. And if someone also works for another organisation, everything they do there stays there: you see only what has happened with you.
The activity log: who changed what
On the detail page is the Activity tab. Per line it says: when, what happened, to what, and old → new.
An example of such a line: 14/05/2026 11:02 · Changed · Price · amount_cent: 1200 → 1500. In plain language: that day at two minutes past eleven this person moved a price from 12 to 15 euros.
What the log keeps
- Products, prices, time slots and events: creating, changing, deleting.
- Discount codes and gift vouchers.
- Venues.
- VAT sets.
- The settings of your organisation and your settings for invoices to buyers.
- Connecting and disconnecting a payment provider.
- API keys: creating and revoking.
- Messages to visitors that were sent.
- Staff: inviting, changing a role, removing someone.
- Refunds and cancelled tickets.
- Till sessions: opening and closing, with the cash difference alongside, and who opened the till in the app on which device.
With a change, the old value and the new one are always there. That is exactly what it exists for: "the price has changed" helps nobody, "from 12 to 15 euros, by Jan, on 14 May" does.
What the log deliberately does not keep
- Passwords, API keys, tokens and other secrets. Those are actively kept out of it. A key from your payment provider in a log line would be worse than no log at all: it would sit there in readable text and stay there for a year.
- Viewing. The log says what someone has changed, not which screens they have opened.
- Sales at the desk. Every keystroke is already in the till journal, which has its own, far stricter retention. See The desk till.
- Scans. Those are on their own tab, below.
- Changes without a difference. Save a screen without adjusting anything and no line is added.
Searching the log
Above the table are four filters: type of action (created, changed, deleted, role changed, …), type of object (product, price, venue, …), a period from–to, and the log that was worked in.
Lines cannot be changed and cannot be deleted, not even by an owner. A log that can be rubbed out does not answer the question it exists for. Lines older than a year are cleared away automatically.
The scan history: who scanned what
The second tab is called Scans. For a staff member with the scanner role, this is the most important part of the page.
At the top of the page, in the Scans block, are three figures: today, this week and total, each with the number of refused scans behind it. That last number is the interesting one. A lot of refusals means either an entrance where people are turning up with the wrong day, or someone scanning the wrong code. Both are worth knowing about.
What each line says
| Column | What it is |
|---|---|
| When | The moment of the scan. If it was scanned offline, underneath it says when the device passed it on |
| Ticket or pass | Which ticket or which season pass was held up to the reader. If a code was scanned that belongs to nothing, it says unknown code |
| Holder | The name on the ticket or the season pass, if there is one |
| Result | Admit, Already scanned, Invalid, Wrong day or Cancelled |
| Device | The device it was scanned with |
The refused scans are in there too. That is deliberate: a scan that came to nothing is exactly the line you are looking for when someone claims afterwards that they were not let in.
Scanned offline? The scanning app carries on without a network. Such a scan sits at the time it happened, with the time it was passed on underneath. That explains why a ticket sometimes only showed up in the system as used in the evening.
You can filter on result, on today only, and on a period from–to. The newest scan is at the top.
Scans, just like the activity log, cannot be changed and cannot be deleted. A count at the door that can be adjusted afterwards is not a count.
Removing someone after the season
The list shows per staff member when they last signed in. That is the column that shows you after a season which volunteers still have access and have not been back for a year. If it says never yet, that person has never used their invitation.
You remove someone with the Delete action next to the right person. You first get a confirmation question.
What then happens:
- their access to your organisation disappears, immediately;
- their account continues to exist, because it is theirs, and they may also still work for another organisation;
- what they created stays: an order from last month must not disappear because a volunteer has stopped.
You cannot remove yourself, and you cannot remove the last owner.
Make a habit of it: once a year, after the season, go through this list and remove whoever no longer belongs. It takes five minutes and it is the cheapest security there is.
Passwords — and why we do not choose them
You cannot set a password for a staff member. That is not a missing button, that is intentional.
A password two people know is not a password. It goes over the phone, it sits in a group chat, it stays behind on a scrap of paper. And when something goes wrong later, nobody can say any more who it was.
So: you invite an email address, and the person behind that address chooses their own password via a link in their own mailbox. That is at the same time the proof that they really do manage that mailbox.
If someone has forgotten their password, they use Forgot password? on the sign-in screen. You do not have to do anything for that. If it does not work, you send their invitation again.
What if someone leaves on bad terms?
It happens. Do this, in this order, on the day itself:
- Remove the person from Settings → Staff. Their access is then gone immediately.
- If they were an owner, first check that there is still another owner. If you cannot remove them, they are the last one — first make someone else an owner.
- Change the passwords of shared accounts they knew: the association's mailbox, the account with your payment provider, your social media. Those stand apart from this system and we cannot close them off for you.
- If they were signed in on a shared device at the door or at the desk, sign that device out and back in with a different staff member.
- Check in Orders and in your till sessions whether anything is still open from that day that has to be closed.
What you do not have to do: delete orders or tickets they created. Those belong to your bookkeeping and they stay.
Commonly made mistakes
- Having one owner. Go away on a trip and nobody can reach the settings any more. Always make a second one.
- Giving a volunteer the administrator role "because it is easier". They then see your full revenue and can issue refunds. Give scanner or desk.
- Sending the invitation to the association's address instead of the person's own. Two people in the same mailbox then share one account.
- Clearing nothing up after the season. Volunteers from two years ago then still have access. Use the Last signed in column.
- Thinking that removing someone erases their work. It does not, and just as well.
What if …
What if the invitation does not arrive?
First check the address for typing errors. Have the person look in their junk mail folder. If that does not help, use Invite again. If it keeps going wrong with an address belonging to a company or a school, their mail server is probably blocking the message — use a different address in that case.
What if someone already has an account with another organisation?
Then your organisation is simply added to it. They sign in with the same password and switch between organisations at the top. Their role with you stands apart from their role elsewhere.
What if I am the only owner and I want to stop?
First make someone else an owner, and then have that person remove you. In that order, because you cannot remove yourself.
What if a staff member cannot see a screen that I can see?
Then they have a role that is not allowed to open that screen. Look at the table above and change their role if that matches what they have to do. Do not invent a detour — the role is meant to be the boundary.
What if I have removed someone by accident?
Invite them again with the same email address. Their account still exists, so they are back in straight away with the role you give them. They do not have to choose a new password.
Frequently asked questions
How many staff may I invite? As many as you need. Do give each of them the smallest role that will do.
Can someone have two roles at once? Not within the same organisation. One person, one role, per organisation. The same person can have a different role in two organisations, though.
Does my scanner see how much a ticket cost? No. The scanner role shows no amounts, no orders and no visitors' addresses. They see one thing: may this person come in, yes or no.
Can an administrator get at my subscription invoices? Yes. They find them under Subscription → Invoices, with the PDF and the UBL, and they can pay an outstanding invoice. Switching plan, cancelling, pausing or setting up the automatic payment they cannot.
Why may an administrator not open the list of staff? Because anyone who can add staff can give themselves rights. The owner keeps that door shut.
Can I see who did what? Yes. Click a staff member and you get their detail page with two tabs: Activity (what they have changed, with the old value and the new one) and Scans (what they have scanned at the door, including what they refused). Every keystroke at the till is in the till journal besides; see The desk till.
Updated on 2026-09-24
Read next
-
Your organisation
Setting up a venue
Every field of the venue screen explained — name, address, VAT set, entrance, photo, time...
-
Your organisation
Languages
What a multilingual shop means in practice, what you translate yourself, and why two langu...
-
Your organisation
Setting up your organisation
Every field explained separately — name, VAT, time zone, code, house style and putting you...
Still stuck? Write to us at support@passavo.eu