
Changing workstations should not blur identity
A colleague helps at the bar, moves to checkout and later covers service. Each move changes work context, but the person remains the same. On a shared device, it must be clear who is currently active. Bonzumo connects identity, roles and operating areas; setup should prevent new actions from being recorded under the previous user.
Map the usual paths between devices and areas in your venue. Who signs in where, when does an old session end and which open transactions need a handover? Access should not slow every move unnecessarily. It should make later questions about an order, change or approval answerable without guesswork.
Open work remains while its operator changes
One server enters an order and passes the tablet to a colleague. The table stays open, but the next action should belong to the person taking over. The same is true at checkout for a partial payment or an unclear terminal response. Shared transaction context helps when it shows current state without attributing new steps to the earlier operator.
Rehearse a handover in the middle of a split bill. The incoming colleague checks which amount is confirmed and which remains outstanding. If payment status is unclear, they do not blindly try again. This exercise shows whether device, login and transaction view work together. A general permissions chart cannot replace a real handover at a table.
Service, kitchen and office need different views
Kitchen needs production status, service needs table and order context, while office staff work with different reports and records. When someone temporarily moves area, check the view needed for that work. Rota assignment or an available device should not alone open broad access to staff or business information. Bonzumo offers roles as the technical foundation; exact assignment follows task and place.
For each frequent move, test two routes: an action allowed at the new workstation and a sensitive view that should remain unavailable. If the required action fails, ask the responsible lead for targeted access. Do not borrow another login as a shortcut. Colleagues remain flexible without mixing responsibility across service, kitchen and office.
A borrowed device should not carry borrowed rights
A tablet moves from terrace to counter, possibly with an earlier session still open under a more privileged colleague. Check not just whether the device works but which identity and work area it displays. The device is a tool; permission belongs to the person using it. This distinction is especially important at shift changes.
A short handover routine is enough: name the open transaction, change personal session, check the work area and then act. For an exception, the authorised person handles that limited action and returns the device. The next normal sale should again be under the service colleagues access. Attribution stays clear without a lengthy approval ritual for guests.
External services retain their own identities
Card terminals, reservation services and accounting portals can have separate accounts. A successful Bonzumo switch does not automatically change permissions in those systems. For each work route, decide where another login is needed, who manages it and how an unresolved external status is passed on. Provider credentials should not be kept as a general team note beside checkout.
Consider an unclear card payment during a shift change. The incoming colleague must distinguish the existing Bonzumo transaction from confirmation by the payment provider. They need to know who can verify provider status without entering an external portal with a borrowed password. That boundary is part of a real identity handover, not a minor technical detail.
Demo the transition rather than a paper matrix
In a Bonzumo demonstration, use a service device, a kitchen view and checkout in sequence. Service enters a table, kitchen sees production context and a shift lead handles a limited exception. Each person signs in personally. Check that open work remains visible and each new action is attributed correctly. Also test a view one role should be unable to open.
Record where the transition becomes awkward: sign-out, finding the table, approval or an external service. That point can be configured or resolved as a team procedure. The benefit is a clear handover without searching for borrowed passwords or losing work state. General permission design is discussed elsewhere; this article focuses on the live move between people and work areas.