Add your team
Panel access is given through roles. You build a role once, then assign it to people. Nobody gets an individual permission directly, with one exception: Wallet transfer access, which you switch on per person in Users.
Step 1 — Get them an account
A colleague needs an account on your platform first. There are two ways.
| Way | How |
|---|---|
| They register | They sign up on your storefront like any customer, with a verification code sent to their email or through a social provider you enabled under Social login. Ask for the name they registered under — you will search for it |
| You add them | In Users, Add user, enter User's email and submit. Needs Users → Create |
An account you add is created right away, without email verification, and only whoever controls that address can sign in to it. Check the email letter by letter: a typo gives the account to whoever owns the mistyped address. You set only the email; they sign in with it the normal way, by a verification code or a social provider.
Either way they start with the role your customer accounts hold, and cannot open the panel until you assign them one in Step 3.
Step 2 — Build the role
Roles → Add Role
Add Role opens the role editor on its own page. A role needs a Role name (3 to 50 characters, not already used by another role on your platform) and at least one permission. Save role saves it.
The editor shows every access grouped into modules and actions. Working tools:
| Tool | Use |
|---|---|
| Search | Find a permission, module or action by name |
| Select all / Clear all | Start from everything or nothing |
| Expand all / Collapse all | Navigate long lists |
| Full / Partial badges | See at a glance how complete a module is |
| High risk marker | Spot the accesses worth thinking about |
| Summary panel | Running counts and an unsaved-changes indicator |
What high risk means
Four actions are flagged wherever they appear:
| Action | Why |
|---|---|
| Delete | Removes data, usually permanently |
| Manage | Broad control over a module |
| Withdraw | Moves money out of your wallet |
| Assign role | Lets someone change what other staff can do, including handing out a role with more access than their own |
Two whole modules are flagged beyond viewing: Roles and Commissions.
Anyone holding it can give any other staff member any role on your platform, including one with more access than their own. Keep it with the owner and at most one deputy.
Build a role around a job
Decide what the person's job actually is, then give the accesses that job needs.
| Job | Typically needs |
|---|---|
| Reservations | Order lists and details, receipts |
| Finance | Wallet, transactions, withdraw, receipts, incoming payments |
| Content editor | Pages, menus, FAQs, home pages, marketing screens |
| Tour manager | Tours, tour orders, tour reviews |
| Support | Order lists, visa requests, hotel comments, tour reviews |
| Blog writer | Only Blog → Access, which opens the Blog Panel |
Start narrow. Adding an access when someone asks is easy; noticing that a role has too much is not.
Remember that view list and view are separate from create, edit and delete. A read-only role is a real option.
Step 3 — Assign it
Search by Profile Name, Nickname, or a registration field you have enabled. On the person's row, use Assign Role and pick the role. You cannot change your own role, and nobody can change the owner's.
Show Full Information displays everything they submitted at registration, which is useful for confirming you have the right person.
Step 4 — Check what they see
The sidebar is filtered twice:
- A screen is hidden if the person lacks its access.
- A group disappears when every screen inside it is hidden.
So if a colleague reports a missing section, check their role before assuming something is broken. Every page in the Panel reference names the access it needs.
What you cannot do from this screen
| Not available | Instead |
|---|---|
| Delete a user | Not available in the panel |
| Edit someone's personal details | They edit their own profile |
| Give one access without a role | Build a role containing it |
| Give someone two roles | Build a role that covers both jobs |
Which registration details you collect
Registration Fields decides what new users are asked for at signup, and whether each is required. You can also add your own custom fields.
Whatever you enable appears as a column in the Users list and as a search option, so this screen quietly decides how findable your customers are later.
Ask for less at signup and more people finish it. Ask for what you will genuinely use.
Scenarios
A new reservations agent starts on Monday
Ask them to register on your storefront before they start, or add them by email yourself. Build or reuse a Reservations role. Assign it on their first day. They see only the order screens.
Someone changes job
Assign them the role for the new job. The change takes effect on their side.
Someone leaves
There is no delete. Assign them the role your customer accounts hold. With it they can no longer open the panel.
A colleague says a page is missing
Find the page in the Panel reference, read the access it needs, and check their role has it. If the page is missing even for a role that holds every access, it is not a role problem — see Who can do what.
You want a read-only manager
Give them the view list and view actions across the modules they care about, and none of create, edit or delete.
Important notes
- One role per person.
- The owner is a label, not a bypass. The owning account is marked Owner in the header, but what it can open still comes from its role's accesses — normally a full one.
- Customers cannot open the panel at all, whatever their registration details.
- A role someone still holds cannot be deleted. Deleting a role also removes its related information, so give everyone holding it another role first.
- Some screens are not role-controlled — Commissions appears only on controlled-markup platforms, regardless of role.
Related
- Who can do what — the model behind this
- Roles · Users · Registration Fields · Social login