Leaving the counter to staff: roles, permissions and the missing 500 rupees

18 August 2026 · Layerdots team
Owner, manager and staff login badges, each unlocking a different set of billing buttons, with an activity log beside them

You cannot stand at the counter twelve hours a day. At some point the billing screen belongs to someone else: a salaried boy, a relative, a manager you mostly trust. For most shops that goes fine. But when the drawer keeps counting a little short, the shortfall rarely announces itself. It is 200 here, 500 there, and it never leaves a note. This post is about what billing software can honestly do about that: separate logins, limited roles, an activity trail and a recycle bin. It is also about what software cannot do, because pretending otherwise sells licences and catches nobody.

The leak is rarely one big theft, it is 500 rupees at a time

A stolen cash box is obvious the same evening. The losses that actually eat a shop's margin look different: small, plausible and repeated. A sale rung up short. A discount given quietly. A bill that existed at noon and did not exist at closing. None of these is worth a police complaint on its own, and each has an innocent explanation ready. That is exactly why they repeat. Five hundred rupees a day is around fifteen thousand a month, and on a counter running thin margins, that is the difference between a profitable month and a confusing one.

Worth saying plainly: most staff are honest. The trouble is that a counter with no records treats honest and dishonest people identically, and gives you no way to tell a leak from a mistake from plain bad luck.

One shared password means nobody did anything

The most common setup is one login for the whole shop, or no login at all. Whoever is at the counter bills. The moment something looks wrong, "who deleted this bill?" has exactly one answer available: nobody knows.

A shared login does two bad things at once. It makes every action anonymous, so a pattern can never be traced to a person. And it makes every person a suspect, so your honest staff carry the cloud for shifts they did not work. Separate logins fix both. When each person signs in as themselves, an edit or a deletion carries a name. So does its absence.

The usual gaps: sale without a bill, discount nobody approved, a deleted bill

Roles in practice: what staff need, what only the owner should touch

Locking everything down fails in the other direction: a counter that stalls waiting for the owner's password loses customers instead of cash. The useful split is boring and practical. A person at the counter needs to make and print bills, search old bills, add a customer and record a payment. What they do not need in their daily work: deleting or editing saved bills, changing prices, reading profit and purchase reports, touching settings, or managing other people's logins. Keep the first list open and the second list yours.

In Layerdots ERP this is the staff logins feature: each person signs in as themselves, and roles with permissions decide which screens and actions each login gets. A billing-only role bills at full speed all day; the delete button and the settings screen simply are not part of its world. And being away from the shop no longer means being blind to it: with the companion phone app you can check the day, or even bill from your phone when the shop computer is off.

An activity trail changes behaviour before it catches anyone

Alongside logins, the app keeps an activity history: the actions that matter at a counter, each with a name and a time attached. Bill made, bill edited, bill deleted, payment recorded.

The real value is not the day you catch someone. It is every day before that. The 500-rupee leak survives on anonymity, and a counter where actions carry names behaves differently from the first week, without a single confrontation. Think of it like the shutter lock: it rarely catches a thief in the act, it mostly makes the attempt not worth it.

Deleted is not gone: why a recycle bin matters at the counter

In Layerdots ERP a deleted bill does not vanish. It goes to a recycle bin and stays there for 30 days, where the owner can review it and restore it. The person who deletes a bill at 2 pm hoping it is gone by closing time is wrong twice: the deletion is in the activity history, and the bill itself is sitting in the bin.

There is a tax reason to care too. Rule 46(b) of the CGST Rules requires tax invoices to be numbered in a consecutive series, unique for the financial year. A bill that silently vanishes leaves a hole in that series, and a hole in the series is a question an officer, or your own accountant at GSTR-1 time, is entitled to ask. A recycle bin means the answer exists.

Records only protect you if they survive. Logins, trails and bins all live in your shop's data, on your own computer. That is a strength, and a responsibility: a dead hard disk takes the evidence with it. Set up a routine once; our shop data backup guide walks through it.

Trust the person, still close the gap: it protects honest staff too

Some owners hesitate here, because giving a long-serving employee a limited login feels like an accusation. It is not, any more than locking the shutter at night accuses the neighbourhood. A limited role protects the staff member as much as it protects you: when the drawer is short, the trail clears the people who did nothing, by name. Without records, suspicion lands on everyone and stays there.

Two honest limits. First, user controls are not unique to us: Tally, Marg, Busy and others offer user management too, and if you already run one of them, learn its controls rather than leaving them off. What a local-first desktop app like ours adds is that all of this works with no internet at all, on data stored in your own machine. Second, no software survives a shared owner password. If the master login is taped to the monitor, everything above is decoration.

Common questions

Will separate logins slow down a busy counter?
No. A person signs in when they take the counter, not on every bill. After that, billing is the same screen and the same keys. A role removes buttons a person should not press; it does not add steps to the ones they should.

My nephew runs the shop when I travel. Should I just give him the owner password?
Give him his own login with a wider role instead. The moment two people share the owner password, you are back to the anonymous counter. If he genuinely needs more access, widen what his own login can do. The trail then still records his actions under his name, which protects him as much as you.

Can software stop a sale that was never billed at all?
No, and be careful with anyone who claims yes. Cash handed over with no bill leaves no trace at the moment it happens. What software can do is show it sideways: stock counts drift away from recorded sales, and daily totals sag on particular shifts. The pattern surfaces, and then the decision is yours, made on numbers instead of suspicion.

Give every person at your counter their own name

7-day free trial · full features · no card, no online account

Download Layerdots ERP