You cannot stand at the counter twelve hours a day. At some point the billing screen belongs to someone else: a salaried boy, a relative, a manager you mostly trust. For most shops that goes fine. But when the drawer keeps counting a little short, the shortfall rarely announces itself. It is 200 here, 500 there, and it never leaves a note. This post is about what billing software can honestly do about that: separate logins, limited roles, an activity trail and a recycle bin. It is also about what software cannot do, because pretending otherwise sells licences and catches nobody.
The leak is rarely one big theft, it is 500 rupees at a time
A stolen cash box is obvious the same evening. The losses that actually eat a shop's margin look different: small, plausible and repeated. A sale rung up short. A discount given quietly. A bill that existed at noon and did not exist at closing. None of these is worth a police complaint on its own, and each has an innocent explanation ready. That is exactly why they repeat. Five hundred rupees a day is around fifteen thousand a month, and on a counter running thin margins, that is the difference between a profitable month and a confusing one.
Worth saying plainly: most staff are honest. The trouble is that a counter with no records treats honest and dishonest people identically, and gives you no way to tell a leak from a mistake from plain bad luck.
One shared password means nobody did anything
The most common setup is one login for the whole shop, or no login at all. Whoever is at the counter bills. The moment something looks wrong, "who deleted this bill?" has exactly one answer available: nobody knows.
A shared login does two bad things at once. It makes every action anonymous, so a pattern can never be traced to a person. And it makes every person a suspect, so your honest staff carry the cloud for shifts they did not work. Separate logins fix both. When each person signs in as themselves, an edit or a deletion carries a name. So does its absence.
The usual gaps: sale without a bill, discount nobody approved, a deleted bill
- The sale without a bill. Cash comes in, no bill is made. No software prevents this at the moment it happens, whatever a salesman tells you. What records do is make it visible later: if bills say 40 strips sold and the shelf is missing 46, a stock report asks the question for you. One more reason to bill everything, however small.
- The quiet discount. Ten percent off for a friend costs you exactly your margin. On a shared login it looks like a business decision. On personal logins it is a line with a name on it, and named discounts get rarer.
- The deleted bill. The oldest counter trick: make the bill, take the cash, delete the bill later. The day's total looks normal, minus one sale nobody remembers.
- The udhaar entry. Credit sales are the softest spot, because cash and paper separate in time. A payment collected against a ledger but never entered simply stays in a pocket. A clean customer ledger closes that gap, and it is the same ledger that helps you recover the udhaar itself.
Roles in practice: what staff need, what only the owner should touch
Locking everything down fails in the other direction: a counter that stalls waiting for the owner's password loses customers instead of cash. The useful split is boring and practical. A person at the counter needs to make and print bills, search old bills, add a customer and record a payment. What they do not need in their daily work: deleting or editing saved bills, changing prices, reading profit and purchase reports, touching settings, or managing other people's logins. Keep the first list open and the second list yours.
In Layerdots ERP this is the staff logins feature: each person signs in as themselves, and roles with permissions decide which screens and actions each login gets. A billing-only role bills at full speed all day; the delete button and the settings screen simply are not part of its world. And being away from the shop no longer means being blind to it: with the companion phone app you can check the day, or even bill from your phone when the shop computer is off.
An activity trail changes behaviour before it catches anyone
Alongside logins, the app keeps an activity history: the actions that matter at a counter, each with a name and a time attached. Bill made, bill edited, bill deleted, payment recorded.
The real value is not the day you catch someone. It is every day before that. The 500-rupee leak survives on anonymity, and a counter where actions carry names behaves differently from the first week, without a single confrontation. Think of it like the shutter lock: it rarely catches a thief in the act, it mostly makes the attempt not worth it.
Deleted is not gone: why a recycle bin matters at the counter
In Layerdots ERP a deleted bill does not vanish. It goes to a recycle bin and stays there for 30 days, where the owner can review it and restore it. The person who deletes a bill at 2 pm hoping it is gone by closing time is wrong twice: the deletion is in the activity history, and the bill itself is sitting in the bin.
There is a tax reason to care too. Rule 46(b) of the CGST Rules requires tax invoices to be numbered in a consecutive series, unique for the financial year. A bill that silently vanishes leaves a hole in that series, and a hole in the series is a question an officer, or your own accountant at GSTR-1 time, is entitled to ask. A recycle bin means the answer exists.
Trust the person, still close the gap: it protects honest staff too
Some owners hesitate here, because giving a long-serving employee a limited login feels like an accusation. It is not, any more than locking the shutter at night accuses the neighbourhood. A limited role protects the staff member as much as it protects you: when the drawer is short, the trail clears the people who did nothing, by name. Without records, suspicion lands on everyone and stays there.
Two honest limits. First, user controls are not unique to us: Tally, Marg, Busy and others offer user management too, and if you already run one of them, learn its controls rather than leaving them off. What a local-first desktop app like ours adds is that all of this works with no internet at all, on data stored in your own machine. Second, no software survives a shared owner password. If the master login is taped to the monitor, everything above is decoration.
Common questions
Will separate logins slow down a busy counter?
No. A person signs in when they take the counter, not on every bill. After that, billing is the
same screen and the same keys. A role removes buttons a person should not press; it does not add
steps to the ones they should.
My nephew runs the shop when I travel. Should I just give him the owner
password?
Give him his own login with a wider role instead. The moment two people share the owner
password, you are back to the anonymous counter. If he
genuinely needs more access, widen what his own login can do. The trail then still records his
actions under his name, which protects him as much as you.
Can software stop a sale that was never billed at all?
No, and be careful with anyone who claims yes. Cash handed over with no bill leaves no trace at
the moment it happens. What software can do is show it sideways: stock counts drift away from
recorded sales, and daily totals sag on particular shifts. The pattern surfaces, and then the
decision is yours, made on numbers instead of suspicion.