The five tabs under Settings > Company, which permission opens each one, and the handful of fields that are refused on purpose.
Three grants, not one
Company Settings is one page with five tabs: Company Profile, Outlets, Inventory Policy, Notifications and Email Templates. Reading it needs view_company. Changing things is split across three permissions, and that split is deliberate, because who may rename the company is not who may open a branch or decide when a write-off needs a second signature:
| Tab | Permission to change it |
|---|---|
| Company Profile, Notifications, Email Templates | manage_company |
| Outlets | manage_outlets |
| Inventory Policy | manage_inventory_settings |
Out of the box only the Admin role holds all three. A tab you can't change tells you so in place of the form ("Outlet setup needs the manage outlets permission. Ask a company administrator."). See Roles & Permissions.
One thing about saving. The Save Changes button in the page header appears only on the Company Profile and Notifications tabs, and only once you've changed something. The Outlets and Inventory Policy tabs save themselves, each with its own button, so a header button that quietly wrote the profile form while you were looking at outlets never gets the chance to exist.
Company Profile
The logo accepts PNG, JPG, SVG or WebP under 2 MB; 200 by 200 pixels or larger looks right. Uploading saves at once, as does Remove; neither waits for Save Changes.
Below it sit two cards. Basic Information holds the company name, the kind of venue (Restaurant, Bar, Nightclub, Lounge, Hotel F&B, Café, Catering or Other), website, company email and phone. Location & Tax holds the physical address, city, country and KRA PIN.
Two fields you might expect here aren't on the page. Currency and the company-level timezone are set when Bohari creates the company (KES and Africa/Nairobi unless told otherwise) and there's no control for them. The business day a stock movement lands on is decided per outlet, on the Outlets tab. The company-level timezone still matters for one thing: the compliance module uses it to decide what "today" is when it judges whether a licence has expired.
What the page will not let you change
Three fields on the company record describe what you've paid for, and the server refuses them from anyone who isn't Bohari platform staff, regardless of role: subscriptionPlan, billableOutlets and isActive. A request carrying any of them is answered with "Subscription changes are billing-driven: subscriptionPlan can only be changed by Bohari support or by completing a payment."
The reasoning is plain enough. A tenant Admin holds manage_company; if the plan were self-serve, an Admin could set it to enterprise and unlock every licensed module with no payment behind it. The same goes for the account's on/off switch: a suspended company doesn't un-suspend itself by editing a form. Plans change on the Billing page by paying; suspension is lifted by settling up or by support.
Outlets
An outlet is a branch, club or restaurant this company trades from. Each one holds its own stock, runs its own counts and carries its own costs, so two branches buying the same item from different suppliers value it differently, and that's intended.
Add outlet asks for four things:
- A code, short and permanent. Letters, digits and dashes only, uppercased as you type, at most 32 characters. It appears on documents and in imports and is fixed once the outlet exists; a wrongly coded outlet is closed and replaced, not renamed. A duplicate is refused:
Outlet code "WLU" already exists. - A name and an optional address.
- A timezone, picked from a list with the East African zones first. The server checks it too, and a name it can't resolve comes back with "timezone must be an IANA timezone name this system recognises, such as Africa/Nairobi". This decides which business day a movement lands on.
Edit changes everything but the code. Close takes an outlet out of service without touching its stock, documents or history; a closed branch still has to explain the period it was open. Reopen brings it back. Closed outlets show a red "closed" chip and still appear on the Users page's outlet pickers, flagged, so pinning a new storekeeper to a mothballed branch is a choice rather than an accident.
Expand any outlet to see its storage locations: a code, a name and a kind (Main store, Kitchen, Bar, Cold room or Other). Stock is counted and held per location, so an outlet needs at least one before anything can be received into it; the panel says exactly that while the list is empty. Locations are retired and restored rather than deleted, and a retired one keeps its balances and history. A duplicate code within the same outlet is refused with Location code "BAR" already exists in this outlet.
Who works where
Under the outlet list is a panel for pinning people to branches. Pick a person, tick the outlets they should reach, press Save access.
The one thing to hold onto: the list is a restriction, so ticking nothing means no restriction at all. The panel says so in amber every time the selection is empty ("Nothing ticked means no restriction: this person reaches every outlet in the company."). That's right for Finance, Procurement and an Auditor and almost never right for someone based at a branch. The Users page shows the same fact as an amber All outlets chip.
Someone whose role carries manage_outlets can't be pinned. The server answers "This person manages outlets, so they cannot be restricted to a subset of them. Change their role first if they should only reach one branch." An administrator who could only see one branch could silently narrow a colleague's access to a list they can't themselves read, which is why the contradiction is refused rather than allowed.
New people are usually pinned on the invitation itself; see User Management.
Inventory Policy
Two thresholds in shillings and one evidence rule. Both thresholds are in money rather than units on purpose: fifty units spans sukuma wiki and single malt.
Approval threshold (KES), default 5,000. A waste note worth this much or more posts nothing until a second person accepts it; anything smaller posts immediately. Zero means every waste note waits for approval. A negative figure is refused ("The waste approval threshold cannot be negative."). Free-form manual adjustments have been retired; see Stock on Hand for the documented correction paths.
Require a photograph on every waste note, off by default. Worth knowing before you switch it on: uploads don't ride the offline outbox, so waste capture will need a working connection.
Alert threshold (KES), default 10,000. A posted count whose variance reaches this alerts everyone who can read reports. It's measured on the absolute value, so a large overage raises the alarm as loudly as a large shortage. Zero alerts on every posted count, including the ones that balanced.
The policy is readable by the people it binds (view_inventory, record_waste and approve_waste holders as well as manage_inventory_settings), so a storekeeper learns a photo is required before being refused for not attaching one.
Notifications and Email Templates
Notifications holds three things. The Reply-To Email is where replies to mail sent on your behalf go; messages leave as "Your Company via Bohari IMS". The Escalation approver is the person a purchase order or invoice falls to when its approval chain resolves to nobody, and the card warns you plainly when none is set, because such a document is otherwise auto-approved. Choose someone with broad authority over spend. The card also lists the compliance-expiry email trigger.
Email Templates lists every message the platform sends, each with a toggle, an editor for the subject and HTML body, a list of the merge variables it accepts (such as {{documentName}}), a sandboxed preview, and Reset to Default. Disabling a template stops that email going out; that's the reliable switch for the compliance reminders, since the sender checks the template before anything else.
FAQ
Why can't I move us to a bigger plan from here? Because the plan describes what you've paid for, and the server refuses it from tenant administrators with the billing-driven message above. Use the Billing page, where a completed payment changes the plan and reconciles your module licences in one step.
I typed the outlet code wrong. Can I fix it? Not by editing. Documents and imports are filed under the code, so it's fixed once the outlet exists. Close the outlet and add a replacement with the right code; the closed one keeps its history.
Where did the Save button go? You're on the Outlets or Inventory Policy tab, which save themselves. The header button only ever applies to Company Profile and Notifications, and only once something has changed.
I pinned someone to no outlets and now they can see the whole company. Why? Because an empty restriction list is no restriction. Tick the branches they belong at and save; the panel states the effect of the current selection in words every time you change it.
What does a threshold of zero do? For waste, every note waits for a second person. For variance, every posted count alerts. Neither switches the control off; if you want that, set the threshold higher than any figure you expect to see.