Advanced Permissions
The Advanced Permissions activity in PAR OPS is used to empower administrators to assign specialized access rights to user logins that go beyond the standard role-based permissions. Designed for flexibility and control, this activity allows you to grant elevated or unique capabilities—such as access to sensitive data, configuration or settings —that are not automatically inherited through default user roles. Whether you're managing franchise-level oversight or enabling trusted staff with tailored privileges, assigning additional permissions ensures secure, precise access aligned with your operational needs.
This activity is available on the Smart Client ONLY.
What is the function of each Advanced Permission?
| Description | Default User Type | Comments |
|---|---|---|
| Adjust Tip Recipient Weights | Unit | This permission is OBSOLETE and will be removed in a future release. |
| Administrate Security | Admin, SupAdmin, Multi-Unit | Allows a user to assign smart groups regardless of the smart groups assigned to their login |
| Advanced Payroll | Admin, Multi-Unit | Allows a user to export and lock payroll data, ensuring accuracy and preventing further edits. Additionally, users with this access can move the payroll cycle forward to the next reporting period or roll it back to the previous one, |
| Allow Close Period With Missing POS Data | Admin, Multi-Unit | Allows a user to close a period with missing sales and/or labor data |
| Allow Delete POS Mappings | Admin, SupAdmin | Allows a user to delete rows in the Sales Item Linking, Category Linking, and Employee Linking forms |
| Allow Edit Min Wage | Admin, SupAdmin | Allows a user to create a new dated row in Payroll Rules > Minimum Wage and hide the existing default row. |
| Allow Edit Past Schedule | Unit | Allows a user to edit a schedule for a date in the past |
| Allow Edit Recipe Card | All roles | Allows a user to edit Recipe Cards |
| Allow Edit Recipe Contents | Admin | Allows a user to edit recipe contents in the Item Master |
| Allow Employee Self-Service | Unit | This permission is OBSOLETE and will be removed in a future release |
| Allow In-Form Approvals | All roles | Allows a user access to the Complete button in the Purchase Management, Journals and Inventory activities. |
| Allow Master Lock | Admin | Allows a user to lock/unlock in Item Master, Sales Item Linking, Category Linking, Configurable Linking, To Do Setup, Network Credentials, Accounts, Data Source Setup, Reports Scheduling, Forecast Setup, and Vendors |
| Allow Performance Budget Check-Out Overwrite | Unit, Multi-Unit | This permission is OBSOLETE and will be removed in a future release. |
| Allow Performance Budget Deletion | Unit, Multi-Unit | This permission is OBSOLETE and will be removed in a future release. |
| Allow Performance Journal Check-Out Overwrite | Unit, Multi-Unit | This permission is OBSOLETE and will be removed in a future release. |
| Allow Performance Journal Deletion | Unit, Multi-Unit | This permission is OBSOLETE and will be removed in a future release. |
| Allow Unit B2B Document Linking | Unit | Allows a unit user to link an invoiced item whose linking has not been completed in the Link Vendor Items activity The linking is for this one invoice and not permanent for future invoices. |
| Allow Web Scheduling | Unit | This permission is OBSOLETE and will be removed in a future release. |
| Allow Web-Based Reports | All roles | This permission is OBSOLETE and will be removed in a future release. |
| Authorize Business Journal Imports | All roles | Allows the user to approve imported business journals |
| Edit/Approve All AP Vouchers | All roles | Allows a user to approve any AP voucher. Without this permission, a user can only approve an AP voucher they entered. |
| Employee linking: Create / Synch | Unit | Allows a user to create and/or synch employees in the Employee Links to POS |
| Force Historic Recalculation | All roles | Allows the user to recalculate data in a past period and run the Force Recalculation report |
| Full Purchase Order Control | Unit | Allows a user to adjust the status of any Purchase Order. Without this permission, the status of Purchase Orders for vendors who are not EDI linked can be adjusted. |
| Generate Check/Station Template | Unit | This permission is OBSOLETE and will be removed in a future release. |
| Generate Inventory Count Templates | Unit | This permission is OBSOLETE and will be removed in a future release. |
| Hide Menu | Unit | This is the one Advanced Permission where it removes a permission when applied. Applying this permission to a user forces them to navigate through To Do's to access an activity and removes the Activities Menu option. |
| Import Business Journals | All roles | Allows a user to import data into a business journal |
| Lock Documents | All roles | Allows a user to lock/unlock documents by providing the lock button in Approve for Accounting (Purchases, Counts, Trades) |
| Lock Performance Budget | Unit, Multi-Unit | This permission is OBSOLETE and will be removed in a future release. |
| Lock Report Layout | Admin | Allows a user to lock the report layout in Reports Setup |
| Lock Report Parameters | Admin | Allows a user to lock the report parameters in Reports Setup |
| Maintain DC Rates | Unit, Multi-Unit | Allows a user to add, edit and approve job rates that are manually entered in the unit level Employees activity (this should be granted to someone with Payroll permissions). This is not for users importing data from the POS. |
| Manager Log Private Comments | Unit | This permission is OBSOLETE and will be removed in a future release. |
| Open/Close Period | All roles | Allows an Admin or Above Store user to open or close an accounting period. |
| PDA Inventory Synchronization | Unit | This permission is OBSOLETE and will be removed in a future release |
| Read Employee Documents | Unit, Multi-Unit | This permission is OBSOLETE and will be removed in a future release. |
| Report Designer | All roles | Allows a user to open the Report Designer |
| Save Custom Reports To Server | All roles | Allows a user to save report changes to the server |
| Save Public Layouts | All roles | This permission is OBSOLETE and will be removed in a future release. |
| View Full SSN | All roles | Allows a user the ability to view an employee’s full Unique Identifier in reports and activities, rather than the default masked version. This permission applies only to stores where Disable SSN Validation is set to FALSE. It is a required permission for any login used to create new employees. |
| View Secure Rates | All roles | Allows a user to view rates for those jobs marked as secure in Payroll Setup - Jobs |
Explanation of All Columns and Tabs
- 'DETAILS': Allows the user to drill down to the next sub tab
- 'DESCRIPTION': Advanced Permission name
- 'USER TYPE': The user type associated with this permission
- 'HIDE': A check in this box, hides this permission and prevents it from being used even with a Smart Group assigned
- 'CUSTOM 1', 'CUSTOM 2', 'CUSTOM 3', 'CUSTOM 4', 'CUSTOM 5': Allows you to enter custom text
Details Tabs
- 'SMART GROUP': The group assigned to the Advanced Permission must also be assigned to a Login to grant users the permission
- Review Smart Groups for more information
- 'GROUP CODE': The unique identifier is auto-populated based on the Smart Group selected. Use this code to help validate that the correct Smart Group has been selected.
- 'GROUP TYPE': Displays the task type associated with the Smart Group (Activity, Report, Item, etc).
- This form will only populate Smart Groups which use the Activity or All roles
- 'GROUP SCOPE': Defines the scope of the permission grant.
- Group Only: The login(s) with this Smart Group assigned will have this permission
- Group and Parents: The login(s) with the parent of and/or the assigned Smart Group with have this permission
- Group and Children: The login(s) with the children of and/or the assigned Smart Group with have this permission
- Group and Parents and Children: The login(s) with the children of and/or the parents of and/or the assigned Smart Group with have this permission
- In the image, the Smart Group assigned is Group 1, with the parents Add Documents and Advanced Permissions
- 'COMMENT': A field for comments if needed
How Do I Assign A Smart Group To An Advanced Permission?
Once you have opened Advanced Permissions, perform the following
- Navigate to the Advanced Permission to assign
- Click "..." in the 'DETAILS' column
- Select a Smart group in the 'SMART GROUP' column
- Select a scope in the 'GROUP SCOPE' column
- Group Only: The login(s) with this Smart Group assigned will have this permission
- Group and Parents: The login(s) with the parent of and/or the assigned Smart Group with have this permission
- Group and Children: The login(s) with the children of and/or the assigned Smart Group with have this permission
- Group and Parents and Children: The login(s) with the children of and/or the parents of and/or the assigned Smart Group with have this permission
- Click Save
How Do I Apply A Smart Group To A Login With Advanced Permissions?
Once you have opened Logins, perform the following
-
Select each Login that should have the Advanced Permission
-
Click Smart Groups
-
Set the parameters:
- Operation: Assign Group
- Group: Select the correct Smart Group
- Filter Scope: Group and Children and cannot be changed
-
Click Ok
-
Click Save
How Do I Remove Advanced Permissions From A Login?
Once you have opened Advanced Permissions, perform the following
-
Navigate to the permission to be removed
-
Click "..." in the 'DETAILS' column
-
Make note of the smart group(s) assigned
-
Open Logins
-
Select each login that should have the advanced permission
- To select multiple logins, hold the CTRL key and select each login
-
Click Smart Groups
-
Set the parameters:
- Operation: Assign Group
- Group: Select the correct Smart Group
- Filter Scope: Group and Children and cannot be changed
-
Click Ok
-
Click Save
How Do I Change An Advanced Permissions From A Login?
Once you have opened Advanced Permissions, perform the following
- Navigate to the permission to be removed
- Click "..." in the 'DETAILS' column
- Select the Smart Group in the 'SMART GROUP' column
- Assign a scope in the 'GROUP SCOPE' column
- Group Only: The login(s) with this Smart Group assigned will have this permission
- Group and Parents: The login(s) with the parent of and/or the assigned Smart Group with have this permission
- Group and Children: The login(s) with the children of and/or the assigned Smart Group with have this permission
- Group and Parents and Children: The login(s) with the children of and/or the parents of and/or the assigned Smart Group with have this permission
- Click Save
How Do I Remove Advanced Permission From A Smart Group?
Once you have opened Advanced Permission, perform the following
- Navigate to the permission whose smart group should be removed
- Click "+ ..." in the 'DETAILS' column
- Select the smart group to be removed
- Click Delete
- Click Save
What is the difference between Smart Groups and Advanced Permissions?
Smart Groups grant or restrict access to tasks or activities whereas Advanced Permissions will grant or restrict additional options within a task or activity. Also Smart Groups can be assigned to Advanced Permissions to determine which users are granted access.