A platform built for the trust restaurants need.
Cibus combines role and capability checks, restaurant-scoped access, database tenant boundaries, payment records and privacy-conscious observability. We review the controls and evidence that apply to each proposed workflow.
| Role | Refund | Void | Discount | Menu edit | Role change |
|---|---|---|---|---|---|
CSCashier | — | — | — | — | — |
SVServer | — | ✓ | ✓ | — | — |
MGManager | ✓ | ✓ | ✓ | ✓ | — |
OWOwner | ✓ | ✓ | ✓ | ✓ | ✓ |
- RecordedPayment recordOrder and allocation context
- CheckedRole capabilityAction permission
- ScopedRestaurant accessAssigned restaurant
Role templates establish a practical starting point.
Access follows assigned restaurant and portfolio scope.
Restaurant data is scoped with database policies.
Current control coverage is documented for the proposed scope.
Where 'good enough' security fails restaurants
From open by default to scoped by design
- Shared logins across staff
- Partner access broader than needed
- Customer PII in unmanaged tools
- No clear tenant boundaries
- Sensitive actions untraceable
- Capability-aware permissions per role
- Scoped restaurant access for partners and managers
- Documented customer-data responsibilities
- Restaurant scope enforced with database policies
- Current activity-record coverage reviewed by workflow
How control is established and maintained
- 01DefineDefine roles and capabilitiesStart from sensible defaults or shape roles to your operation.
- 02ScopeScope access per restaurantStaff and partners receive access according to their assigned restaurant scope.
- 03OperateOperate with capability checksSensitive actions require the right capability; nothing implicit.
- 04ReviewReview supported recordsConfirm the payment and operational activity context available for each selected workflow.
- 05DocumentSet data-handling responsibilitiesDefine processing roles, retention requirements and rights-request routes before go-live.
What's in the trust layer
Decision-making stays with the owner
Not open by default. Scoped access and tenant boundaries by design.
Role and capability checks, restaurant scope, row-level security, privacy-conscious observability and defined payment records provide a reviewable control foundation. Current evidence is assessed for the workflows in scope.
Where these controls show up
Security and compliance questions
Is access role-based or capability-aware?
Both. Roles give sensible defaults; capabilities gate sensitive actions per user.
Can partners be scoped to their portfolio?
Yes. The Sales Agent Portal uses restaurant-scoped access for a partner's assigned portfolio.
Is restaurant data isolated between tenants?
Cibus uses database row-level security policies to scope restaurant data to authorised restaurant access. The applicable architecture and controls can be reviewed during discovery.
Is there an audit trail?
Payment workflows retain order and allocation records. Broader per-action coverage varies by workflow, so current coverage and available evidence are documented during discovery rather than described as a universal audit log.
How does Cibus support GDPR and customer-privacy workflows?
Cibus applies scoped platform access and PII-scrubbing controls to error telemetry. The applicable privacy terms document processing roles, authorised access, retention, subprocessors and rights-request routing for the selected workflow and market.
Do you store card data?
Payment-card entry and processing are handled through Stripe. Cibus application records do not store raw card numbers.
Does using Cibus make a restaurant compliant?
No software establishes legal compliance on its own. Cibus provides technical and operational controls that can support a restaurant's governance processes; the restaurant remains responsible for assessing its obligations with appropriate advisers.
Discuss controls, roles and tenant isolation.
See how Cibus connects service, kitchen operations, payments, reporting, customer engagement and delivery into one restaurant operating system.