Skip to main content

Controlling who can do what

Not every employee on your team needs the same access. For example, a front-desk employee should not be able to change your deposit policy or view your payroll report. Groups let you control this access.

info

Only users with the Petsoft Account Owner permission can manage security groups.

How groups work

A group is a named role, for example "Managers" or "Front Desk". You assign employees to a group. There are two kinds. Both are sections on the Organization > Settings > Manage page:

  • Organization Groups — the employee's role for daily work, and its application permissions.
  • Report Groups — which reports its members can run.

Petsoft describes Organization Groups this way: "Organization Groups are utilized by Petsoft to grant and revoke application permissions. Here, you can manage the groups that can be assigned to users and change the areas of the application that they have access to."

The Organization Groups list A typical setup. Look at the Supervising Group column. Every group has a supervising group, usually the owner group. This is what makes a role assignable.

Petsoft does not include preset groups such as "Owner" or "Manager". Each organization creates its own groups and names them as needed.

important

Basic access is broad. Extra permissions add to it. Membership in any Organization Group gives an employee access to the core areas of the application: customers, reservations, pets, runs, and the point-of-sale (POS) system. Permissions are a flat list of extra grants for specific, sensitive features. These extra grants add to the basic access.

No permission exists for "bookings only" or "checkouts only" access. You cannot create a group that can make bookings but cannot view customers. Plan your groups around the sensitive extra permissions. Do not plan groups around blocking access to ordinary pages.

Creating an organization group

On the Organization Groups section, click New Organization Group.

FieldWhat it does
Organization Group Name"The name for the organization group that will identify the users permissions." For example, "Weekend Supervisor" rather than "Group A".
Supervising Group"If configured, sets the group that manages this group from a permissions perspective to prevent modifications in parent groups." Read the warning below before you leave this field blank.
Description"A brief description for the group that defines the roles and responsibilities for this group."
Display Order"The order in which this role appears on the employee schedule and list pages. 1 appears at the top, with higher numbers appearing lower. Roles with the same display order are grouped together."
Require Multi-Factor Authentication"When enabled, all members of this group must have an authenticator app configured before they can access the system."

Editing an organization group The group form: name, Supervising Group, description, Display Order, and the Multi-Factor Authentication requirement, with the Group Permissions table below.

danger

Always set a Supervising Group. Normally, this is your owner or manager group.

A manager can assign only the roles that the manager's group supervises. This includes roles supervised directly or through a group further down in the hierarchy. A group with no Supervising Group cannot be assigned by anyone at your organization. This includes you, unless you are a member of that group. The role will exist but will never be assignable.

If you create a group and cannot find it in the Role dropdown list on an employee, this is the reason.

Setting permissions

Group Permissions is a table with one row for each permission and three radio buttons: Allow, Deny, and Inherit.

  • Allow — grant this extra permission.
  • Deny — refuse this permission.
  • Inherit — no extra grant or refusal. The member has only standard staff access.

Set Allow only for the extra permissions a role needs.

The Group Permissions table One radio button row for each permission. In this example, the front-desk group allows a few extra permissions and inherits the rest. Petsoft Account Owner is an ordinary row in the same list.

The full list is flat and in alphabetical order. It has no categories:

Permission
Allow Pre-Payment OverrideManage Facility Services
Apply TagsManage Hours of Operation
Delete CustomersManage Payment Triage
Edit Employee Time EntriesManage Promo Codes
Grant RefundsManage Support Tickets for entire Organization
Manage Employee Facility AssignmentsManage Tags
Manage Employees and SchedulesPetsoft Account Owner
Manage Facility ProductsReceive Facility Health Checks
Unlock Employee AccountsShow All Facility Services in Service Calendar
View Daycare Availability Settings (Read-Only)
caution

Use caution with Petsoft Account Owner, Delete Customers, and Grant Refunds. These permissions carry almost full administrative control, and you cannot undo a deleted customer record. If you are not sure that an employee needs one of these permissions, do not grant it. Start with fewer permissions. It is easier to add a permission later than to explain why you removed access.

Note this dependency: a group cannot have Manage Employee Facility Assignments without Manage Employees and Schedules. Petsoft shows this message if you try: "A group cannot manage employee facility assignments without managing employees and schedules."

tip

Show All Facility Services in Service Calendar scopes what an employee sees, not what they can change. Without it, an employee only sees their own assigned appointments on the Dashboard's tabs and on the Service Calendar — useful for a groomer who only needs their own day, not the whole facility's. With it, they see everyone's. See Dashboard & daily overview and Grooming Appointments for what changes on each screen. Account owners always see everything regardless of this setting, like every other permission.

Click Save.

Report groups

Report groups control which reports an employee can see. Petsoft gives this example:

"Report Groups associate reports with assigned groups, for example, all Financial reports can be assigned to a Finance Users Report group, restricting access to those reports to only those users assigned to the report group."

On the Report Groups section, click New Report Group. Give the group a Report Group Name, a Description, and, if needed, a Supervising Group. Then select each report that the group can run.

A common setup uses two groups. A "Finance Users" group gives the owner and bookkeeper access to revenue and payroll reports. A standard group gives everyone else access to operational reports, such as arrivals and daily medications.

Assigning employees to groups

You cannot add members from the Organization Groups or Report Groups section. You select an employee's Role (an Organization Group) and Report Role (a Report Group) on the employee record. Both fields are required when you create an employee. See Employee management.

An employee can belong to multiple groups. Add roles from the employee's Roles tab. You cannot remove an employee's last core role. This makes sure that every employee always has one core role.

If an employee needs one extra permission, create a new group instead of assigning the employee to two groups.

What happens when someone leaves

Set the employee to Inactive on the employee's General tab, and save. The employee can no longer log in.

If a former employee shared a login with another person, change the password from the employee's Credentials tab. You can also have that person use the standard forgot-password procedure.

note

Permissions attach to groups, not to individual employees. If an employee moves from front desk to manager, move the employee to the Manager group. Do not grant extra permissions to an individual employee. Petsoft does not support per-person permissions.

Deleting a group

The trash button appears only when you can delete a group. You cannot delete a group while it still has members, or while another group names it as its Supervising Group. Reassign the members or the Supervising Group first. Petsoft shows this message:

"Unable to remove the Organization Group [name] as there are currently members assigned." "Unable to remove the Organization Group [name] as there are other Organization Groups that are children of this Organization Group."

Best practices

  • Do not give every employee admin access. Small businesses often do this because it is easier than creating groups.
  • Review your groups every six months. Employees change roles, and permissions increase over time.
  • Do not share logins. Each employee must have a separate account. This makes the record of who changed data reliable.
  • Train employees to log out when they leave their workstation. Groups control access correctly only when the correct employee is logged in.

Security review checklist

ReviewFrequency
Audit group membershipsEvery 6 months
Check for unused admin accessEvery 6 months
Reset password on shared loginsImmediately
Deactivate former employeesImmediately upon departure
Was this page helpful?

Still stuck?

Our team is happy to help. Reach out and we'll get you back on track.