Advanced Permissions

The Advanced Permissions activity in PAR OPS is used to empower administrators to assign specialized access rights to user logins that go beyond the standard role-based permissions. Designed for flexibility and control, this activity allows you to grant elevated or unique capabilities—such as access to sensitive data, configuration or settings —that are not automatically inherited through default user roles. Whether you're managing franchise-level oversight or enabling trusted staff with tailored privileges, assigning additional permissions ensures secure, precise access aligned with your operational needs.

This activity is available on the Smart Client ONLY.

What is the function of each Advanced Permission?

Description Default User Type Comments
Adjust Tip Recipient Weights Unit This permission is OBSOLETE and will be removed in a future release.
Administrate Security Admin, SupAdmin, Multi-Unit Allows a user to assign smart groups regardless of the smart groups assigned to their login
Advanced Payroll Admin, Multi-Unit Allows a user to export and lock payroll data, ensuring accuracy and preventing further edits. Additionally, users with this access can move the payroll cycle forward to the next reporting period or roll it back to the previous one,
Allow Close Period With Missing POS Data Admin, Multi-Unit Allows a user to close a period with missing sales and/or labor data
Allow Delete POS Mappings Admin, SupAdmin Allows a user to delete rows in the Sales Item Linking, Category Linking, and Employee Linking forms
Allow Edit Min Wage Admin, SupAdmin Allows a user to create a new dated row in Payroll Rules > Minimum Wage and hide the existing default row.
Allow Edit Past Schedule Unit Allows a user to edit a schedule for a date in the past
Allow Edit Recipe Card All roles Allows a user to edit Recipe Cards
Allow Edit Recipe Contents Admin Allows a user to edit recipe contents in the Item Master
Allow Employee Self-Service Unit This permission is OBSOLETE and will be removed in a future release
Allow In-Form Approvals All roles Allows a user access to the Complete button in the Purchase Management,  Journals and Inventory activities.
Allow Master Lock Admin Allows a user to lock/unlock in Item Master, Sales Item Linking, Category Linking, Configurable Linking, To Do Setup, Network Credentials, Accounts, Data Source Setup, Reports Scheduling, Forecast Setup, and Vendors
Allow Performance Budget Check-Out Overwrite Unit, Multi-Unit This permission is OBSOLETE and will be removed in a future release.
Allow Performance Budget Deletion Unit, Multi-Unit This permission is OBSOLETE and will be removed in a future release.
Allow Performance Journal Check-Out Overwrite Unit, Multi-Unit This permission is OBSOLETE and will be removed in a future release.
Allow Performance Journal Deletion Unit, Multi-Unit This permission is OBSOLETE and will be removed in a future release.
Allow Unit B2B Document Linking Unit Allows a unit user to link an invoiced item whose linking has not been completed in the Link Vendor Items activity The linking is for this one invoice and not permanent for future invoices.
Allow Web Scheduling Unit This permission is OBSOLETE and will be removed in a future release.
Allow Web-Based Reports All roles This permission is OBSOLETE and will be removed in a future release.
Authorize Business Journal Imports All roles Allows the user to approve imported business journals
Edit/Approve All AP Vouchers All roles Allows a user to approve any AP voucher.  Without this permission, a user can only approve an AP voucher they entered.
Employee linking: Create / Synch Unit Allows a user to create and/or synch employees in the Employee Links to POS
Force Historic Recalculation All roles Allows the user to recalculate data in a past period and run the Force Recalculation report
Full Purchase Order Control Unit Allows a user to adjust the status of any Purchase Order.  Without this permission, the status of Purchase Orders for vendors who are not EDI linked can be adjusted.
Generate Check/Station Template Unit This permission is OBSOLETE and will be removed in a future release.
Generate Inventory Count Templates Unit This permission is OBSOLETE and will be removed in a future release.
Hide Menu Unit This is the one Advanced Permission where it removes a permission when applied.  Applying this permission to a user forces them to navigate through To Do's to access an activity and removes the Activities Menu option.
Import Business Journals All roles Allows a user to import data into a business journal
Lock Documents All roles Allows a user to lock/unlock documents by providing the lock button in Approve for Accounting (Purchases, Counts, Trades)
Lock Performance Budget Unit, Multi-Unit This permission is OBSOLETE and will be removed in a future release.
Lock Report Layout Admin Allows a user to lock the report layout in Reports Setup
Lock Report Parameters Admin Allows a user to lock the report parameters in Reports Setup
Maintain DC Rates Unit,  Multi-Unit Allows a user to add, edit and approve job rates that are manually entered in the unit level Employees activity (this should be granted to someone with Payroll permissions). This is not for users importing data from the POS.
Manager Log Private Comments Unit This permission is OBSOLETE and will be removed in a future release.
Open/Close Period All roles Allows an Admin or Above Store user to open or close an accounting period.
PDA Inventory Synchronization Unit This permission is OBSOLETE and will be removed in a future release
Read Employee Documents Unit, Multi-Unit This permission is OBSOLETE and will be removed in a future release.
Report Designer All roles Allows a user to open the Report Designer
Save Custom Reports To Server All roles Allows a user to save report changes to the server
Save Public Layouts All roles This permission is OBSOLETE and will be removed in a future release.
View Full SSN All roles Allows a user the ability to view an employee’s full Unique Identifier in reports and activities, rather than the default masked version. This permission applies only to stores where Disable SSN Validation is set to FALSE. It is a required permission for any login used to create new employees.
View Secure Rates All roles Allows a user to view rates for those jobs marked as secure in Payroll Setup - Jobs

Explanation of All Columns and Tabs

  • 'DETAILS': Allows the user to drill down to the next sub tab
  • 'DESCRIPTION': Advanced Permission name
  • 'USER TYPE': The user type associated with this permission
  • 'HIDE': A check in this box, hides this permission and prevents it from being used even with a Smart Group assigned
  • 'CUSTOM 1', 'CUSTOM 2', 'CUSTOM 3', 'CUSTOM 4', 'CUSTOM 5': Allows you to enter custom text

Details Tabs

  • 'SMART GROUP': The group assigned to the Advanced Permission must also be assigned to a Login to grant users the permission
    • Review Smart Groups for more information
  • 'GROUP CODE': The unique identifier is auto-populated based on the Smart Group selected. Use this code to help validate that the correct Smart Group has been selected.
  • 'GROUP TYPE': Displays the task type associated with the Smart Group (Activity, Report, Item, etc).
    • This form will only populate Smart Groups which use the Activity or All roles
  • 'GROUP SCOPE': Defines the scope of the permission grant.
    • Group Only: The login(s) with this Smart Group assigned will have this permission
    • Group and Parents: The login(s) with the parent of and/or the assigned Smart Group with have this permission
    • Group and Children: The login(s) with the children of and/or the assigned Smart Group with have this permission
  • Group and Parents and Children: The login(s) with the children of and/or the parents of and/or the assigned Smart Group with have this permission
    • In the image, the Smart Group assigned is Group 1, with the parents Add Documents and Advanced Permissions
  • 'COMMENT': A field for comments if needed

How Do I Assign A Smart Group To An Advanced Permission?

Once you have opened Advanced Permissions, perform the following

  1. Navigate to the Advanced Permission to assign
  2. Click "..." in the 'DETAILS' column
  3. Select a Smart group in the  'SMART GROUP' column
  4. Select a scope in the 'GROUP SCOPE' column
    1. Group Only: The login(s) with this Smart Group assigned will have this permission
    2. Group and Parents: The login(s) with the parent of and/or the assigned Smart Group with have this permission
    3. Group and Children: The login(s) with the children of and/or the assigned Smart Group with have this permission
    4. Group and Parents and Children: The login(s) with the children of and/or the parents of and/or the assigned Smart Group with have this permission
  5. Click Save

How Do I Apply A Smart Group To A Login With Advanced Permissions?

Once you have opened Logins, perform the following

  1. Select each Login that should have the Advanced Permission

  2. Click Smart Groups

  3. Set the parameters:

    1. Operation: Assign Group
    2. Group: Select the correct Smart Group
    3. Filter Scope: Group and Children and cannot be changed
  4. Click Ok

  5. Click Save

How Do I Remove Advanced Permissions From A Login?

Once you have opened Advanced Permissions, perform the following

  1. Navigate to the permission to be removed

  2. Click "..." in the 'DETAILS' column

  3. Make note of the smart group(s) assigned

  4. Open Logins

  5. Select each login that should have the advanced permission

    1. To select multiple logins, hold the CTRL key and select each login
  6. Click Smart Groups

  7. Set the parameters:

    • Operation: Assign Group
    • Group: Select the correct Smart Group
    • Filter Scope: Group and Children and cannot be changed
  8. Click Ok

  9. Click Save

How Do I Change An Advanced Permissions From A Login?

Once you have opened Advanced Permissions, perform the following

  1. Navigate to the permission to be removed
  2. Click "..." in the 'DETAILS' column
  3. Select the Smart Group in the 'SMART GROUP' column
  4. Assign a scope in the 'GROUP SCOPE' column
    1. Group Only: The login(s) with this Smart Group assigned will have this permission
    2. Group and Parents: The login(s) with the parent of and/or the assigned Smart Group with have this permission
    3. Group and Children: The login(s) with the children of and/or the assigned Smart Group with have this permission
    4. Group and Parents and Children: The login(s) with the children of and/or the parents of and/or the assigned Smart Group with have this permission
  5. Click Save

How Do I Remove Advanced Permission From A Smart Group?

Once you have opened Advanced Permission, perform the following

  1. Navigate to the permission whose smart group should be removed
  2. Click "+ ..." in the 'DETAILS' column
  3. Select the smart group to be removed
  4. Click Delete
  5. Click Save

What is the difference between Smart Groups and Advanced Permissions?

Smart Groups grant or restrict access to tasks or activities whereas Advanced Permissions will grant or restrict additional options within a task or activity. Also Smart Groups can be assigned to Advanced Permissions to determine which users are granted access.