03/Company model
Who signs in, and which document posts where.
Permissions are keys on the login, not a shared password in a drawer. Trade customers use a separate cookie on the same hostname. Staff tokens and customer tokens are not interchangeable.
Roles and what each login can do| Login | Can | Cannot |
|---|
| Owner | Users, locations, CSV import, settings, full books. | Nothing hidden. This is the login created at signup. |
| Warehouse | Pick, pack, load, deliver, transfer, stocktake. | Price lists, posting invoices, other companies’ hosts. |
| Till / sales | Quotes, sales orders, cash-up, layby, walk-in customers. | Cost, if the permission is off. Books close and VAT201. |
| Books | Invoices, bills, credit notes, bank import, VAT201 draft. | Skipping warehouse states to ‘make the invoice match’. |
| Trade customer | Catalogue at their prices. Draft sales orders on your hostname. | Staff screens, cost, other customers, your books. |
Documents and general ledger effect| Document | Number | What it does |
|---|
| Quote | QT- | No stock hold, no GL. |
| Sales order | SO- | Hold at a location. ATP drops. |
| Pick / pack / deliver | — | Warehouse quantity. Shorts recorded. |
| Customer deposit | — | GL 2300 Customer deposits. |
| Tax invoice | INV- | 1100 Debtors, 4000 Sales, 2200 VAT output. |
| Credit note | CN- | Reverses tax and, where configured, stock. |
| VAT201 | draft | A read of the ledger. You copy it into eFiling. |
Chart of accounts is seeded for the owner. You can add accounts. You cannot delete ones the documents still post to. Opening balances and Cin7/Xero-shaped CSVs are in settings after the first login — there is no live two-way sync on day one.