Users and permissions

Control who can sign in and which modules each person can use. Open Settings → Users.

Roles

When you add or edit a user, choose a role preset:

  • Owner — full access to everything, including Settings and Users.
  • Staff — bookings, deposits, POS, orders, products (including stock), gift cards, contacts, portfolio, and reports by default. Does not include gift card Management, Settings, or Users unless you add them.
  • Artist — bookings only by default; you can tick extra modules below.

Owners can always manage every artist and shop-wide blockouts.

Modules

Permissions match the admin menu:

  1. Bookings
  2. Deposits
  3. POS
  4. Orders
  5. Products → optional Stock (receive, stocktake, adjustments)
  6. Gift cards → optional Management (PIN reset)
  7. Contacts
  8. Portfolio
  9. Reports
  10. Settings → optional Users

Missing a module sends people to Help with an access-denied note.

Artist access

For non-owners with Bookings:

  • All artists (including shop-wide blockouts) — full calendar mutate access.
  • Selected artists only — can change bookings, leave, cover, and artist-scoped blockouts for those artists; the rest of the calendar remains visible.

Recovery email

Set a recovery email so the user can use Forgot password and receive MFA sign-in codes. Without one, only another admin can reset their password manually, and MFA cannot be turned on.

Passwords

Passwords must be at least 8 characters. Avoid common passwords and do not reuse the username as the password.

Multi-factor authentication (MFA)

Optional email codes at sign-in. On each user:

  1. Set a recovery email.
  2. Tick Require MFA.
  3. Save.

When MFA is on, sign-in asks for a 6-digit code emailed to that recovery address. After a successful code, that browser is trusted for about one week before another code is required. See Signing in.

Enforce MFA (shop-wide)

At the top of Settings → Users:

  1. Tick Enforce MFA for admin users.
  2. Save MFA policy.

While enforce is on:

  • New users are created with MFA required.
  • Existing users keep their current MFA setting, but MFA cannot be turned off.
  • Users who already have MFA on (or new users) see Require MFA locked on.