Troubleshooting User Roles, Permissions & 2FA
Amwal provides granular Role-Based Access Control (RBAC) to ensure financial security, segregation of duties, and compliance with SAMA standards across multi-store and multi-branch retail operations.
Rendering diagram...
Official Roles & Permissions Summary
| Role | Financial Statements & Payouts | Generate Payment Links | Issue Refunds | Manage Stores & Branches | API Keys & Webhooks |
|---|---|---|---|---|---|
| Owner | Full Access | Full Access | Full Access | Full Access | Full Access |
| Admin | Full Access | Full Access | Full Access | Full Access | Full Access |
| Accounting | Full Access | View Only | View Only | View Only | No Access |
| Operation | View Only | Full Access | Full Access | Full Access | Full Access |
| Supervisor | No Access | Branch Only | Branch Only | Branch Only | No Access |
| Cashier | No Access | Branch Only (QR) | No Access | No Access | No Access |
1. "You Do Not Have Permission to Perform This Action"
Common Cause
A team member assigned a restricted role (e.g. Cashier or Supervisor) attempted to access financial statements, adjust store API keys, or issue an unapproved refund.
Resolution
- An Organization Owner or Admin must log in to the Amwal Merchant Portal.
- Navigate to Users & Permissions → Users.
- Select the user account and click Edit Role.
- Upgrade the role to match their operational responsibilities (e.g., from
CashiertoSupervisororOperation). See User Roles & Permissions.
2. Cashier / Supervisor Cannot Access Branch Terminal
Symptom
Staff member logs in but sees no active branches or cannot generate in-store payment links.
Resolution
- In the Merchant Portal, go to Branches → Branch Users.
- Confirm that the user is explicitly linked to their physical retail branch location.
- If staff members rotate between multiple branches, an Admin must update their branch assignment in the portal. See Branch Users.
3. Two-Factor Authentication (2FA) Recovery
If an Administrator or Owner loses access to their authenticator device:
- Use Emergency Backup Codes: When 2FA was initially configured, emergency one-time recovery codes were generated. Enter one of these codes on the 2FA challenge screen.
- Organization Owner Reset: Any other Organization Owner can reset a team member's 2FA under Users → Edit User → Reset 2FA.
- Amwal Support Escalation: If the sole Organization Owner is locked out, email
support@amwal.techfrom your corporate email domain with your Commercial Registration (CR) to initiate identity verification.
