A driver may need to select a site, complete a cash-up and issue a receipt. That does not automatically mean they need access to reports for the whole business, every site agreement or the records of other team members.
Permissions tend to grow by accident. Somebody receives broad access because a round is busy, changes role a few months later and keeps the same account. A practical access policy prevents that drift without making ordinary site work awkward.
Start with the work, not the job title
“Driver”, “collector” and “manager” mean different things in different vending businesses. List the tasks each person performs before choosing their access. A driver who only services an assigned round may need to:
- identify the correct site and machine;
- enter a coin count and complete the collection record;
- check the commission calculation relevant to that visit;
- print or email the site receipt; and
- record a correction or note when something unusual happens.
An office colleague may need to review completed visits, reconcile deposits and prepare reports, but may never need to change a figure from the roadside. The owner may need the broadest view, including site and machine performance.
Writing this down exposes vague areas quickly. If “help with admin” is the only reason for giving somebody full access, the task has not been defined closely enough.
Use individual accounts and minimum access
Shared logins are convenient until a figure changes and nobody can say who made the change. Give each team member an individual account. Their access should cover the work they currently do, rather than every function they might need one day.
This follows the National Cyber Security Centre’s principle of least privilege: different users should have only the access or functions their role requires. It is sensible operational practice as well as a security measure. Clear accounts make it easier to investigate a correction, answer a site query and remove access when somebody leaves.
Keep the permission groups understandable. If every person has a unique tangle of exceptions, nobody will know what “normal” looks like. A small operator might begin with working profiles for an owner, a driver or collector, and office support, then document any genuine exception.
Separate field work from business reporting
Most roadside tasks concern the site being visited. Company-wide reports concern the business. Treat those as different levels of access.
A driver can usually complete a collection without seeing year-on-year performance across the round. They may need the commission details used in that cash-up, but not the commercial history of every venue. Likewise, the ability to enter a cash figure need not include permission to alter standing site terms.
VendMetrix team permissions use tick-box controls so staff can be given access for their work without automatically seeing business reports. This is a confirmed current capability. The same page explains that VendMetrix supports mobile cash-ups, site receipts and reports, which makes it useful to decide who needs each part rather than opening the whole system to everybody.
Decide who can correct a completed cash-up
Mistakes happen: a denomination is entered incorrectly, a receipt needs to be reissued or a collection is attached to the wrong machine. The risky response is either to hide all correction tools from the field team or to let everyone overwrite records freely.
Set a simple rule. For example, a driver may report or propose a correction, while an owner or office reviewer approves it. If a trusted round manager can correct records directly, make sure the original entry remains traceable and the reason is recorded.
The rule should also cover disputed commission, missing cash and a receipt that does not match the amount handed over. These are exceptions, not reasons to give permanent wide access to every user.
Build access checks into staff changes
Permissions need attention when somebody joins, changes duties or leaves. Use a short checklist:
- create the individual account and assign the agreed working profile;
- test it with a normal task before the first solo round;
- review access when routes or responsibilities change;
- remove temporary permissions once the extra work ends; and
- disable access promptly when the working relationship finishes.
The NCSC also advises organisations to review user accounts for unnecessary privileges and revoke privileged access when it is no longer required. A quarterly check may suit one operator, while a growing team may need a review whenever the rota or responsibilities change. The important part is that the review happens, has an owner and leaves a record.
Test the roadside experience
Tight controls should not force a driver to phone the office at every machine. Before settling on a permission set, run through a normal visit on the same type of phone or tablet used on the round.
Can the driver find the assigned site, complete the count, deal with the commission shown for that visit and provide the receipt? Can they record an honest mistake without concealing it? If the answer is no, adjust the workflow or explain the escalation route. Do not solve poor setup by granting blanket access.
VendMetrix was built around the work of UK vending rounds, including cash-ups, site commissions and team use. Its permission controls can support a sensible policy, but the operator still decides who should see what. Keep that decision tied to real tasks, revisit it when the team changes and make exceptions visible.