Test
Guides 5 Aug 2026 · 1 min read

Getting started with roles and permissions

By Demo Editor

Getting started with roles and permissions

Every panel needs an answer to "who may do what", and the honest answer is usually "it depends who". Here is the model this application ships with.

The five roles

  • User -- signs in, manages their own account. No panel access.
  • Editor -- content: pages, the blog, uploaded files, contact messages.
  • Bookkeeper -- reads the money: payments, refunds, subscriptions, disputes.
  • Manager -- day-to-day operations: everything an Editor and a Bookkeeper do, plus acting on payments and editing anyone's posts.
  • Administrator -- everything, including settings and roles.

Permissions, not role names

Code never asks "is this user an Editor". It asks "may this user update pages". Roles grant permissions; the grants are the thing the application checks. The practical difference: the day a sixth role appears, nothing that checks permissions needs to change.

Handing out the least

Start a new staff member on the least role that covers their job. Upgrading is one field. The alternative -- starting everyone as a Manager and meaning to walk it back -- never gets walked back.

More from the blog