Skip to main content

Roles and permissions

Every admin has one of three roles. This page is the complete list of what each role can do, for checking before you give someone access. For how to choose and change roles, see The three kinds of admin and Add, change or remove an admin.

The three roles are Site Admin, Admin and Manager. Their descriptions in the admin panel are:

  • Site Admin: everything, including adding and removing admins.
  • Admin: everything except adding and removing admins.
  • Manager: concerts, members, tickets and the rest of the day-to-day, but not Site Settings, Pages or how the site is set up.

What each role can do​

Yes means allowed, and no means the server refuses it.

WhatSite AdminAdminManager
Site Settings (every section, including Features and Theme)YesYesNo
Pages (your own extra pages)YesYesNo
The guided setupYesYesNo
Updates (checking for and installing new versions)YesYesNo
The Email page (own mail server; hosted sites only)YesYesNo
Saving the receipt settings (Donors, the charity details and receipt wording)YesYesNo
The custom style sheet (Site Settings, Theme; self-hosted only)YesNoNo
See the list of admins (the Admins page)YesYesNo
Add, change or remove adminsYesNoNo
Concerts, Gallery, Past EventsYesYesYes
Ticketing, including recording sales, cancelling orders and refunds, check-in, and mailing ticket holdersYesYesYes
Donors, including recording gifts, campaigns, imports, issuing, printing and cancelling receipts, and mailing donorsYesYesYes
Messages (contact-form messages kept on the server)YesYesYes
Members, Announcements (including emailing them), Schedule, Rehearsal Tracks, Member Files, Useful LinksYesYesYes
Uploads of pictures and files into any of the aboveYesYesYes
Looking at the receipt settings (without saving)YesYesYes

Pages in the admin panel only appear for features that are switched on in Site Settings; see Feature switches. Roles never give access to a switched-off feature.

Who is a Site Admin​

An admin who has no role recorded is a Site Admin. That covers:

  • The one username and password set on the server (ADMIN_USERNAME and ADMIN_PASSWORD). With ADMIN_AUTH=env, that shared login is the only admin and is a Site Admin.
  • Any admin added from the command line (npm run admin:add) before anyone has changed their role.
  • On a site we host, the first admin who signs up.
  • Every admin that existed before roles were introduced.

With ADMIN_AUTH=table, a Site Admin can give each other admin a role on the Admins page. The panel will not let you demote, disable or delete the last active Site Admin.

The Admins page exists only with ADMIN_AUTH=table. With a single shared login there is no Admins menu item for anyone.

What happens when a role opens a page it may not use​

  • The menu does not show items the role cannot use. The dashboard's tiles are the same list.
  • If an admin types the address of such a page (/admin/settings, /admin/pages, /admin/updates, /admin/email, /admin/setup, /admin/admins), they are sent back to the dashboard.
  • If the browser is somehow asked to do the action anyway, the server refuses, whatever the page does: "Your admin account does not include this. Ask a Site Admin if you need it."
  • An Admin who opens the Admins page sees the list, but not the New Admin button or the controls to change anyone.
  • A theme saved by an Admin or through the guided setup keeps the existing custom style sheet unchanged: only a Site Admin's save can change it.

Members are not admins​

A member is someone who uses the member portal to see the schedule, files and rehearsal tracks. A member has no access to the admin panel at all, and the two logins are separate. Members are added under Members in the admin panel (see Add, change, disable or remove members); admins are added under Admins.