Account administration
Team and roles
Everybody you invite joins your organisation and gets a role. The role decides what they can do; a separate branch restriction decides where they can do it. The two are independent, and both are enforced on the server rather than merely hidden.
Inviting somebody
Team in the account view.
Needs the permission users.create (create users). Owners and Admins have every permission by default.
Enter their email address
They get an invitation with a link. Accepting it is how they join — there is no account for you to create on their behalf.
Choose a role
Start with the narrowest one that lets them do their job. Widening a role later is a moment's work; explaining why somebody deleted a customer is not.
Restrict them to branches, if it applies
Somebody who works at one shop does not need the others. This is separate from their role and applies on top of it.
The four standard roles
Owner
Can do everything an Admin can do and also manage account plan and remove the account.
Admin
Can read, create, update and delete customers and manage the account including locations, users and all settings.
Editor
Can read, create, update and delete customers but cannot change settings.
Reader
Can only read customer data and cannot create, update or delete customers or change settings.
These are starting points rather than fixed categories. Each one is created for your organisation with a set of permissions already ticked, and you can change what any of them means.
Permissions
Underneath the roles sit 111 individual permissions, grouped into 22 categories:
Accounts, Analytics, API keys, Display settings, Audit entries, Customers, Customer notes, Input fields, Labels, Locations, Messages, Plan, Report runs, Report templates, Resources, Roles, Services, Surveys, Survey answers, Users, Visits, Webhooks.
Account settingsRoles & Permissions lists them, with a comparison across your roles so you can see at a glance where two of them differ.
Needs the permission roles.update (update roles & permissions). Owners and Admins have every permission by default.
Not every permission gates something yet
The list is the full intended taxonomy, and some entries correspond to features that are not built. Ticking one of those changes nothing rather than doing something unexpected. The ones that matter today are customers, visits, locations, messages, reports, services, resources, users, roles, plan, API keys and webhooks.
Custom roles
Where none of the four fits, create your own and tick exactly what it should include. A common case: somebody who runs the waitlist all day and should never touch settings, billing or the team.
Roles are per organisation, so changing what “Editor” means changes it for your business only.
Restricting somebody to branches
A branch restriction narrows a role rather than replacing it. Somebody restricted to Camden sees Camden's waitlist, Camden's appointments and Camden's figures — and in the account view, their “whole business” is the branches they hold.
What it covers
- The waitlist and appointments they can see and act on.
- Overview and analytics figures.
- Which branches they can subscribe to alerts for — a notification rule can never widen their reach.
What it does not cover
The customer directory is organisation-wide, because a customer belongs to the business rather than to a branch — so somebody who can view customers can view all of them. Services and resources are likewise organisation-level, and somebody with permission to edit them can edit them for every branch.
Owners
The Owner role is the only one that can manage the plan and delete the account, and assigning it is itself a separate permission.
An organisation must always have an owner
Removing the last Owner, or demoting them, is refused. Promote somebody else first. It is worth having two Owners at any business where one person going on holiday should not stop the plan being changed.
Removing somebody
Removing a member revokes their access immediately. What they did stays in the audit log, and any visits they handled stay attached to the customers rather than to them.
An invitation that has not been accepted can be withdrawn, which is what to do about a mistyped address.
Personal settings
Each member has their own profile page. A number of the fields there are not yet stored — the page says so itself — so treat it as a place to check your name and email rather than a full profile.