Getting started with roles and permissions
By Demo Editor
Every panel needs an answer to "who may do what", and the honest answer is usually "it depends who". Here is the model this application ships with.
The five roles
- User -- signs in, manages their own account. No panel access.
- Editor -- content: pages, the blog, uploaded files, contact messages.
- Bookkeeper -- reads the money: payments, refunds, subscriptions, disputes.
- Manager -- day-to-day operations: everything an Editor and a Bookkeeper do, plus acting on payments and editing anyone's posts.
- Administrator -- everything, including settings and roles.
Permissions, not role names
Code never asks "is this user an Editor". It asks "may this user update pages". Roles grant permissions; the grants are the thing the application checks. The practical difference: the day a sixth role appears, nothing that checks permissions needs to change.
Handing out the least
Start a new staff member on the least role that covers their job. Upgrading is one field. The alternative -- starting everyone as a Manager and meaning to walk it back -- never gets walked back.