Users and permissions
Control who can sign in and which modules each person can use. Open Settings → Users.
Roles
When you add or edit a user, choose a role preset:
- Owner — full access to everything, including Settings and Users.
- Staff — bookings, deposits, POS, orders, products (including stock), gift cards, contacts, portfolio, and reports by default. Does not include gift card Management, Settings, or Users unless you add them.
- Artist — bookings only by default; you can tick extra modules below.
Owners can always manage every artist and shop-wide blockouts.
Modules
Permissions match the admin menu:
- Bookings
- Deposits
- POS
- Orders
- Products → optional Stock (receive, stocktake, adjustments)
- Gift cards → optional Management (PIN reset)
- Contacts
- Portfolio
- Reports
- Settings → optional Users
Missing a module sends people to Help with an access-denied note.
Artist access
For non-owners with Bookings:
- All artists (including shop-wide blockouts) — full calendar mutate access.
- Selected artists only — can change bookings, leave, cover, and artist-scoped blockouts for those artists; the rest of the calendar remains visible.
Recovery email
Set a recovery email so the user can use Forgot password and receive MFA sign-in codes. Without one, only another admin can reset their password manually, and MFA cannot be turned on.
Passwords
Passwords must be at least 8 characters. Avoid common passwords and do not reuse the username as the password.
Multi-factor authentication (MFA)
Optional email codes at sign-in. On each user:
- Set a recovery email.
- Tick Require MFA.
- Save.
When MFA is on, sign-in asks for a 6-digit code emailed to that recovery address. After a successful code, that browser is trusted for about one week before another code is required. See Signing in.
Enforce MFA (shop-wide)
At the top of Settings → Users:
- Tick Enforce MFA for admin users.
- Save MFA policy.
While enforce is on:
- New users are created with MFA required.
- Existing users keep their current MFA setting, but MFA cannot be turned off.
- Users who already have MFA on (or new users) see Require MFA locked on.