Setting Up the Right Role for an Employee Who Fills Machines

Nayax Core: build a machine filler role with pick list, quantity, and product access only - no reports, no admin, no unnecessary access risk.

General

Nayax Core › Settings and User Management
Nayax Core › Settings and User Management

Setting Up the Right Role for an Employee Who Fills Machines

Recommended access level for a route or warehouse employee whose job is filling machines: reviewing the pick list, adjusting quantities, and adding or swapping products. Covers what to include, what to leave out, and how to set it up in Nayax Core.

Before You Start

  •       You have administrator access in Nayax Core Management Suite, with permission to create and assign user roles.
  •       The employee already has a user account in Nayax Core, or you are ready to create one.
  •       You know which machines or routes this employee is responsible for.
  •       You have decided whether this employee will also handle cash collection, since that changes which permissions the role needs.
Why this matters
Getting this role wrong costs you either way. Too little access and your filler is calling you every visit to adjust a quantity or add a product you forgot to load. Too much access and a route employee can see revenue reports, commission settings, or other users' accounts they have no reason to touch - a real compliance gap if your business is ever audited on data access controls.

What the Role Needs to Cover

Picture a route employee, Priya, arriving at a coffee machine inside a call center that runs 60 vends a day. She needs to see what to load, adjust the quantity if half the almond milk pods already sold, add a new snack line the account manager just approved, and confirm the machine reflects what she actually filled. That is the entire job. Nothing about her day requires seeing the machine's monthly revenue, changing commission rates, or creating other user accounts.

That one scenario is the basic access level every machine-filling role should be built around, regardless of what you end up naming the role in Nayax Core.

Include in the role
  •     View and open the pick list for assigned machines
  •     Adjust pick quantities before or during a fill
  •     Add a new product or swap a product on the product map
  •     Update stock levels after completing a fill
Leave out of the role
  • Revenue and sales reports
  • Commission and pricing configuration
  • Device or terminal configuration
  • User management for other accounts
Consequence of getting this wrong
If the role is too narrow, Priya cannot adjust a quantity or add a product on the spot, so machines sit partially filled until someone with broader access fixes it later - lost sales in the meantime. If the role is too broad, she has standing access to financial data and configuration screens she never needs, which is exactly the kind of unnecessary access an audit will flag.

Build the Role in Nayax Core

Set up the permission set once, then reuse it for every employee whose job is filling machines.

  1.  

    In Nayax Core, go to Settings and open Users and Roles.

  2.  

    Create a new role, or duplicate an existing one, and name it something that describes the job rather than the person - for example, Route Filler or Field Restock.

  3.  

    Enable access to these screens: Pick List, Product Map, and the edit-level permission for Adjust Quantities and Add or Swap Product. View-only access to a screen is not the same as edit access - confirm both are checked where the employee needs to make changes, not just look.

    Tip
    Set this up as its own named role rather than editing an existing broad role down. A dedicated role is easier to audit later and safer to reuse across every employee you hire.
  4.  

    Leave every other screen disabled by default, including Reports, Commission Settings, Device Configuration, and User Management. Do not enable these to save time now - go back and add only what is proven necessary later.

  5.  

    Save the role, then assign it to the employee's user account.

Most filling employees fit the base role above. Expand whichever variation matches your situation.

Most common Single-site or single-route filler

This is Priya's case: one employee, a fixed set of assigned machines, no cash handling. The base role above - Pick List, Product Map, Adjust Quantities, Add or Swap Product - is the complete access this employee needs. Nothing further to add.

Edge case Filler who also collects cash

Some route employees also empty the cash box during the same visit, for example on a machine in a break room with no card reader. This needs one addition to the base role: the specific Cash Collection permission, which logs the collection event without opening Reports or revenue data. Do not grant Reports access as a shortcut to give someone cash collection - the two are separate permissions in Nayax Core and only one of them is needed here.

Assign and Verify Access

Confirm that the role actually behaves as you configured it before the employee's first solo visit.

  1.  

    Have the employee log out and log back in, or restart the app if they are using it on a mobile device. Role changes do not always apply to an open session.

  2.  

    Confirm they can see and open the Pick List and Product Map, and that the Adjust Quantities and Add or Swap Product actions are available, not just visible as greyed out.

  3.  

    Confirm Reports, Commission Settings, Device Configuration, and User Management do not appear at all in their view.

    If a restricted screen still shows
    Return to the role and check whether it was created by duplicating a broader existing role - duplicated roles sometimes carry over screens you did not intend to include. Disable them individually and save again.
  4.  

    Document which role you assigned and to whom, so the next person setting up a filling employee can reuse it instead of building a new one from scratch.

Result

Role configured and confirmed

The employee can open the pick list, adjust quantities, and add or swap products on every machine assigned to them, with no delays waiting on someone else. Reports, commission settings, device configuration, and other users' accounts are not visible to them. The role is saved and reusable, so setting up the next filling employee takes minutes, not a rebuild.

Role Comparison: Filling and Route Staff

Use this to check what to add - or hold back - as an employee's responsibilities grow beyond basic filling.

Task Basic Filler Filler + Cash Collection Full Operator / Admin
View pick list Yes Yes Yes
Adjust pick quantities Yes Yes Yes
Add or swap products on the product map Yes Yes Yes
Update stock after fill Yes Yes Yes
Collect and log cash No Yes Yes
View revenue and sales reports No No Yes
Configure commission or pricing No No Yes
Configure device or terminal settings No No Yes
Manage other user accounts No No Yes

Troubleshooting

The employee can see revenue or sales reports even though I did not intend to grant that.
This usually happens when the role was created by duplicating a broader existing role instead of building it from scratch. Open the role, check the Reports screen toggle specifically, and disable it. Save and have the employee log out and back in to confirm it is gone.
The employee can open the pick list but cannot adjust quantities.
Viewing a screen and editing it are separate permissions. Check that the edit-level toggle for Adjust Quantities is enabled, not just the view-level toggle for the Pick List screen itself.
There is no option to add or swap a product on the product map.
Confirm the edit-level permission for Product Map is enabled, separately from view access. If it is enabled and the option is still missing, confirm the employee's account is actually assigned to the machine in question - product map edit rights only apply to machines the account has access to.
I assigned the role, but the employee still sees the old set of screens.
Role changes do not always apply to a session that is already open. Have the employee log out and log back in, or fully close and reopen the app on a mobile device, then check again.
I want this employee to also collect cash, but not see financial reports.
Cash Collection and Reports are separate permissions. Add the Cash Collection permission on top of the base filler role and leave Reports disabled - granting Reports is not required to allow cash collection.

FAQ

FAQ

Did you find this article helpful?