Documentation /Settings
Permissions
Permissions is an Elite feature.
On the free plugin a staff member given a WordPress account reaches a fixed set of screens: Dashboard, Calendar, Bookings, Customers, Payments and Staff. They may correct a colleague's details but not add or remove anybody, and nothing else is open to them. That set cannot be changed.
On Elite you write it yourself. Everybody who can open the admin sees all of it — every booking, every payment, every setting — until a role says otherwise for one group of people, leaving everyone else alone.
Find it under Business → Permissions.
Writing a role
Add role opens a page with two tabs.
Role details is the name, the staff who are in it, and a note to yourself about what it is for.
Permissions is the list. Each module is a card (Events, Bookings, Payments, Customers, Settings and the rest) with its actions underneath. The cards are in the same order as the admin menu, so you can find one where you would expect it. Tick what that group needs. Anything left unticked is refused, not hidden behind a message but refused by the server.
The first action in each card is View: opening the module and reading it. Tick only View and the person can look at bookings but not add, edit or delete them. Ticking Add, Edit or Delete ticks View with it, because there is nothing to edit in a module you cannot open.
The box in a card's header selects or clears everything in that card at once. It shows a dash when some of the actions are ticked and some are not.
Access all permissions grants the lot in one switch, which is the quickest way to start from everything and take things away. The search box filters the whole list — type invoice and only the cards and lines that mention it stay on screen.
A role can be paused rather than deleted. A paused role stops applying, and the people in it are no longer limited by it.
Only their own
Two sections can be narrowed further:
- Bookings — only the bookings that person took.
- Events — only the events that person is assigned to as staff.
This holds in the list and when a row is opened directly, so a booking a person cannot see in the list does not open for them through a link either.
Settings, panel by panel
Settings has no View and is not one switch. Its panels are granted separately, grouped under the same three headings the settings screen uses:
- General settings — General, Company, Bookings, Public pages, Ticket PDF, Customer panel, System information
- Payments — General, Payment methods
- Integrations — Bot protection, Email, Telegram, SMS, WhatsApp, Zoom
So somebody who keeps the company address up to date does not also get the payment gateways and the SMTP password.
Two roles
A person can be in more than one role. The answers merge to the most restrictive: if one role allows payments and another refuses them, payments are refused. Adding a role can only ever take away, never add — so a role written to limit somebody cannot be undone by giving them a second one.
Administrators
WordPress administrators are never limited, on any plan. Permissions exist for everybody else: the desk, the box office, a guest coordinator. If you want to limit yourself for testing, sign in as the staff member rather than editing your own account.
Signing in
Giving staff an account is part of the free plugin — it is deciding what they see that is not. A staff member needs a WordPress account to sign in with. From Business → Staff, the row menu offers WordPress account. Give an email and it creates one, with a role of its own that can read the site and nothing more.
If the email already belongs to a WordPress user, it says so and offers to link that user to this staff member instead of creating a second account.
What a limited person sees
The menu, the sidebar and the buttons on a row follow the role. Somebody who may not open Payments is not shown Payments at all, rather than being shown it and refused on arrival.