Roles
A role is a named bundle of accesses. You build it here and assign it from Users. Nobody gets an individual access directly — everything goes through a role.
| Section | Users & Access |
| Panel route | /admin/roles |
| Access needed | Roles → View list |
The list
| Column | Shows |
|---|---|
| Display Name | The role's name, as staff see it |
| Access Level | A summary: how many permissions, across how many modules, and how many are high risk |
| Actions | View permissions, Edit Role and Delete Role |
Search by Display Name, and sort Newest or Oldest. View permissions shows everything a role contains without opening the editor.
You cannot edit or delete the role you hold yourself: its Edit Role and Delete Role buttons are hidden. The list also shows roles the platform provides for everyone, such as the role every customer account holds. Those cannot be changed or deleted either.
The Seller Manager role cannot be edited: its Edit Role button is hidden. You can still view its permissions, and delete it like any other role you do not hold.
Creating a role
Add Role opens the role editor on its own page. It has one field:
| Field | Accepts |
|---|---|
| Role name | Required, 3 to 50 characters, and not already used by another role on your platform |
Then you pick its permissions. At least one is required. Save role stays disabled until you change something; Discard and Back to roles leave without saving.
The permission editor
Every access is grouped into modules, and each module into actions. The editor gives you:
| Tool | Use |
|---|---|
| Search | Find a permission, module or action by name |
| Select all / Clear all | Start from everything, or nothing |
| Expand all / Collapse all | Navigate long lists |
| Full / Partial badges | See how complete each module is |
| High risk marker | Spot the accesses worth pausing over |
| Summary panel | Running counts, plus an Unsaved changes indicator |
The actions
The same verbs appear across modules:
| Action | Grants |
|---|---|
| View list | Seeing the list screen — this is what puts a page in someone's sidebar |
| View | Opening a single record |
| Available services | Listing the services your platform can use, on screens that ask you to pick one |
| Create · Create or update · Edit | Adding and changing |
| Change status · Approve · Reserve · Recommend · Cancel | Workflow actions |
| Assign role | Giving someone a role |
| Withdraw | Moving money out of the wallet |
| Access | Opening a separate panel: Blog → Access lets someone open the Blog Panel |
| Export · Manage · Delete | Everything else |
A screen only appears in someone's sidebar if their role has its View list access. Without it they cannot reach the page at all.
High risk
Four actions are flagged wherever they appear:
| Action | Why |
|---|---|
| Delete | Removes data, usually permanently |
| Manage | Broad control over a module |
| Withdraw | Moves money out of your wallet |
| Assign role | Lets someone change what other staff can do, including handing out a role with more access than their own |
Two whole modules are flagged beyond viewing: Roles and Commissions.
The flag is a prompt to think, not a prohibition. A finance role needs Withdraw; a content editor does not.
Editing and deleting
Editing a role changes what everyone holding it can do, immediately.
Deleting a role removes its related information, so the panel refuses while anyone holds it. Give each of them another role in Users first, then delete it.
What a role does not control
Some things are decided above any role:
- Which services your platform may sell. This hides no panel screen; it decides what you can switch on in Seller Information and offer on your storefront
- Commissions, which exists only on controlled-markup platforms
- Which gateways, palettes and layout variants you can choose from
If a page is missing even for a role that holds every access, it is Commissions on a platform without controlled markup.
Questions
Can someone have two roles? No. Build a role that covers both jobs.
Why does a colleague see a whole missing section? A group disappears when every screen inside it is hidden. Their role has no access in that group at all.
How do I make a read-only role? Give View list and View across the modules they need, and none of create, edit or delete.
Does the owner need a role? The owner is labelled Owner in the header, but what it can open still comes from its role's accesses — normally a full one. It is not a bypass.
Related
- Who can do what — the model
- Add your team — building and assigning roles
- Users