STATIC REVIEW PROTOTYPE Sample data only — no real customers, payments or health records. Nothing you do here is saved.

HQ administration HQ admin Signed in as HQ Admin A ← Review hub

Organization & access

Branches, staff postings and roles — plus the workspace where an HQ admin corrects a member's wallet or points balance. Sample records only.

Structure

Branches

A branch owns its own catalog publication, payment methods, earn rates and tables. Configuration lives on commerce settings.

Branches (sample)
BranchCodeTables StaffStatusActions
HQ Demo Branch — Central HQ-CEN 18 11 Trading
HQ Demo Branch — North HQ-NTH 12 7 Trading
HQ Demo Branch — Riverside HQ-RIV 0 2 Fitting out — not trading

People

Staff and postings

A staff record is posted to one or more branches. Permissions resolve per branch, so the same person may hold different authority at different sites. Sample staff only.

Staff records (sample)
StaffRolePosted to StatusActions
HQ Admin A HQ admin All branches Active
Store Manager A Store manager HQ-CEN Active
POS Operator A Cashier HQ-CEN, HQ-NTH Active
Kitchen Lead A Kitchen staff HQ-CEN Active
Coach A Recovery coach HQ-CEN Active
Therapy Staff A Therapy staff HQ-NTH Suspended

Rule shown here

Every role or posting change requires a reason and writes an audit entry, exactly like a balance adjustment. A staff member who is also a member holds two separate identities and two logins — staff privilege never opens their own member record.

Access

Roles

All eight roles exist from day one, even where a branch has nobody in a given role. Every restriction below is enforced on the server; hiding a control in the interface is a usability measure, never the control itself.

Roles and their hard limits
RoleWorks inMay not
Customer Member app See staff records, other members, or any internal scoring logic
Recovery coach Coach portal Publish an unreviewed report, or override a safety flag without a reason
Therapy staff POS / store portal View assessment answers or scores, or override a safety block
Cashier POS / store portal View any health data, or complete a refund above the authorised threshold alone
Kitchen staff Kitchen queue Reach member records, payment or health data
Store manager POS / store portal Change assessment rules, publish reports, or read assessment content
HQ admin HQ admin portal Publish a member's report, or delete an audit record
Super admin HQ admin portal Edit or delete an audit record — break-glass access is itself audited

Correction

Customer balance adjustment

Where an HQ admin corrects a member's balance — a service recovery credit, a goodwill award, or a reversal of a mistake. Wallet money and points are adjusted separately, because they are separate ledgers in different units.

Rule shown here

Reason is mandatory. An adjustment cannot be posted until a reason is written, the before and after figures are shown to the admin first, and the posted entry appends to the immutable audit log. The member sees the same reason, read-only, in their own ledger.

Aisyah Demo

Member M-10042 · +60 1•-••• 4407 · HQ Demo Branch — Central

Wallet balance
RM 120.00
Points balance
1,240 pts

Wallet adjustment

Wallet money is held in RM. This form never touches the points ledger.

Positive to credit the wallet, negative to debit it.
Written to the audit log and shown to the member, word for word. Clear this field and press Post wallet adjustment to see the block.

Before and after

Before

Wallet
RM 100.00
Points
1,240 pts

After

Wallet
RM 120.00
Points
1,240 pts — unchanged

Audit entry that would be written

Ledger
Wallet (RM)
Actor
HQ Admin A
Subject
Aisyah Demo · M-10042
Before → After
RM 100.00 → RM 120.00
Delta
+RM 20.00
Reason
Service recovery — delayed order 2026-08-01

Rule shown here

A wallet adjustment and a points adjustment are two entries, never one. Crediting RM 20.00 does not award points, and awarding 100 pts does not add RM to the wallet. Correcting a posted adjustment means writing a new, opposite entry that refers to the original — the original is never edited or deleted.

Not on this surface

Staff administration shows employment and access data only. No wellness indicator, assessment answer or session note is visible to an HQ admin — that stays with the coach and the member.

Every branch, staff member, balance, reason and timestamp on this page is fabricated for design review. No adjustment is posted, no audit entry is written, and no record is stored.