Tighten receptionist permissions — remove access to financial dashboard, wallets, invoice creation
A receptionist should only:
- Register participants (wizard)
- Look up participant info (read-only)
- Collect payments on existing invoices
- Sell via POS
- Open/close their cash session
Removed: invoices.list (gates financial overview), invoices.create,
wallets.list/view/credit, participants.update, guardians.update,
enrollments.list, cash_sessions.manage, payments.list,
pos_sessions.open/close/list
Co-Authored-By:
Claude Opus 4.6 <noreply@anthropic.com>
Showing
Please register or sign in to comment