Roles, and what each one can do

The four roles, what each unlocks, and the rules that protect you from yourself.

Everyone in your brand holds exactly one role. They stack: each one can do everything the role below it can, plus more.

Viewer → Creator → Approver → Brand admin

Every article in this knowledge base that describes a task shows, at the top, which roles may perform it.

Viewer

Reads published recipes. Cannot write, submit or approve anything, and never sees drafts or anything in review — a Viewer sees the same published content the line does.

Signing in as a Viewer takes you straight to the line view rather than the dashboard, because that is the surface a Viewer is for.

Creator

Everything a Viewer can, plus authoring:

  • create and edit recipes and preps, including ingredients, steps, allergens and control points
  • add ingredients to your catalog, and create units and sections as they are needed
  • import recipes — pasted text, a photo, or a spreadsheet
  • submit for review

A Creator cannot publish. That is the point of the role: the person who wrote a recipe is not the last person to look at it before a cook follows it.

Approver

Everything a Creator can, plus the decision:

  • see the approvals queue and approve or reject anything in it
  • publish directly, skipping the queue
  • archive recipes, and run those actions in bulk

The queue is a shared pool. There is no assigned approver — any approver can decide any submission, so work does not stall behind one person.

An approver may approve a recipe they wrote themselves. That is deliberate: a brand with a single approver would otherwise be unable to publish anything. If you want a second pair of eyes enforced, give authoring to Creators and keep Approver for the people whose job is checking.

Brand admin

Everything an Approver can, plus running the brand:

  • Locations — stores, recipe viewers, enrollment codes, manager PINs, which menus each store can open, and regions
  • Menus — creating them, building versions, store pins and per-store exceptions
  • Users — inviting people, setting roles, deactivating and archiving
  • Brand identity — your logo and palette
  • Recipe groups and Languages
  • View as — previewing the product as a lower role

Rules that protect you from yourself

You cannot lock yourself out. Specifically, you cannot change your own role, deactivate yourself, archive yourself, or delete yourself — even as a brand admin. Someone else with brand admin has to do it.

People who have signed in or written anything can be archived but not deleted, so the audit trail stays intact. Deleting is only offered for accounts that never got used.

A note on names

These four names are what Tavorly calls them internally, and what this documentation uses throughout. Your brand can rename what they are displayed as — so what you see in the product may say something else while the underlying role is unchanged.

How long you stay signed in

Brand admins are signed out after 24 hours. Everyone else stays signed in for 14 days. A recipe viewer on the line stays enrolled for 180 days, because nobody wants to re-enrol an iPad mid-service.

Last checked against the product on August 18, 2026.