Who sees what: roles and access in a student-run store
The access map every store needs: who can sell, who can refund, who can change a price, and why the lines are the lesson.
Sooner or later every store faces the Tuesday where a price was different at lunch than it was at breakfast, and nobody knows who changed it, or how. The fix is boring and powerful: an access map. Who can do what, written down, enforced by something sturdier than trust.
Districts require this thinking everywhere else money moves. Here’s how to apply it to a store staffed by students, without smothering the ownership that makes the store worth running.
The principle: generous floor, guarded edges
Give students real authority over the daily operation, and put the small set of dangerous actions behind an adult. That’s the whole design. A store where students can’t do anything teaches nothing; a store where anyone can do everything teaches the wrong thing the hard way.
The access map
Draw this for your store, whatever system you run:
| Action | Cashier | Manager / CFO | Advisor |
|---|---|---|---|
| Sell, take payment, make change | Yes | Yes | Yes |
| View sales numbers | Yes | Yes | Yes |
| Count and log the drawer | With a partner | Yes | Yes |
| Process a refund | Request it | Request it | Authorize |
| Change a price | No | Propose | Approve |
| Add / remove products | No | Propose | Approve |
| Export records, adjust settings | No | No | Yes |
Adjust titles to your crew, but keep the shape: selling is open, money-out and price-setting are gated, and system settings belong to the adult of record.
Two design notes worth stealing. Refunds are the classic gate because they’re the easiest way for money to leave a store irregularly; a refund should always involve a second, senior set of eyes. And “propose” is a real status, on purpose: your CFO should be building the price-change case. Approval is the control; participation is the curriculum.
Kill the shared login
The most common access failure in school stores has one name on it: everybody’s. A shared password taped under the register means every action is anonymous, every variance is unattributable, and every investigation turns into a feelings conversation.
Whatever you run, get to a world where actions attach to people (or at minimum, to one named drawer-owner per window, per the count-to-count routine). Accountability that can’t identify anyone is decoration.
Run the quarterly access review
Districts audit access on a cycle; teach your crew the same habit in 10 minutes a quarter:
- Read the roster: who has which role right now?
- Remove the ghosts: graduated, transferred, dropped the class.
- Check the gates: did any “temporary” permission become permanent by inertia?
- Log that you did it, dated and initialed.
Do this in November, February, and (most importantly) June: the year-end handoff is where store access goes to rot, and we’ll publish the full succession checklist in the spring.
How RallyOrder draws these lines
For stores on our platform, the map above is structural rather than aspirational: registers are paired devices your advisor can revoke remotely, refunds require an authorized PIN, and every transaction carries a record. Catalog and price changes live in HomeRoom, where students hold their own logins with permissions you set (inventory, pricing, cost), so “propose” and “approve” are real statuses rather than a policy binder. The design goal is exactly this post: students run the store all day, and the guarded edges hold without anyone hovering.
The one-page version
- Selling open to all; refunds and price changes gated; settings with the advisor.
- “Propose” is a role’s power too; approval is the control, participation is the lesson.
- No anonymous actions: end shared logins, or at minimum enforce one named drawer-owner per window.
- Quarterly access review: roster, ghosts, gates, logged.
Draw the map once, and the Tuesday price mystery retires forever.