Skip to main content
Tools

Panel Access & RBAC

Roles, permissions and club panel users

9
Sections
1
Panels
Service Overview

Panel access controls who on your staff can sign in to Club Panel and what they can see or change — via roles, permission matrix, and staff user accounts. Proper RBAC prevents finance mistakes, data leaks, and accidental production changes by junior staff.

Separate from member accounts — staff users use club panel login with mobile/OTP or password per club policy. Group admins are a special scope limited to one member group.

1
Section 1 of 9

Core concepts

ConceptMeaning
**Staff user**Person with club panel login tied to club.
**Role**Named bundle of permissions (e.g. Finance, Support).
**Permission**Atomic right: view / create / update / delete on a module.
**Module**Feature area matching menu: Customers, Wallets, Events, …
**Group admin scope**Role variant restricted to one member group.
**Owner**Super role — full club access; limit count.
Previous sectionNext section
2
Club PanelSection 2 of 9

Introduction

**Menu:** Club Panel → Settings → Panel access

Hub for roles, staff list, and permission overview.

Prerequisites

  1. You hold Owner or Panel access manage permission.
  2. Club onboarding complete — know which modules you purchased.

Page layout

  • Tabs: Staff users, Roles, Permission matrix (read-only grid).
  • Help text linking to this documentation.

Principles

  • Least privilege — start narrow, expand as trust grows.
  • Separation of duties — wallet approve ≠ wallet configure.
  • Offboarding — deactivate staff same day they leave.
3
Section 3 of 9

Permission matrix

**Menu:** Club Panel → Settings → Panel access → Permission matrix**

Rows = modules; columns = view / create / update / delete (where applicable).

Module examples

ModuleTypical finance roleTypical support role
CustomersViewView, update status
WalletsView, updateView only
EventsViewView, update check-in
Panel accessNoneNone
App BuilderNoneNone
AcceptorsViewView

Step-by-step — read matrix

  1. Open Permission matrix.
  2. Compare Support vs Manager columns for sensitive modules.
  3. Before creating role, mark required cells on paper.
  4. After role edit, re-open matrix to verify save.
4
Section 4 of 9

Role management

**Menu:** Club Panel → Settings → Panel access → Roles**

Step-by-step — create role

  1. New role — name staff will recognize ("Level 1 Support").
  2. Clone from template if available (Support, Finance, Marketing).
  3. Toggle permissions module by module — avoid blanket all-on.
  4. Save role — appears in staff user assignment dropdown.
  5. Document role in internal wiki with intended use.

Step-by-step — edit role

  1. Open role — changes affect all assigned staff immediately.
  2. Remove delete on Customers/Wallets unless managers only.
  3. Test with dummy staff account before revoking owner paths from yourself.

Built-in roles (typical)

RoleIntent
**Owner**Full access including panel access and billing
**Manager**Operations minus dangerous deletes
**Support**Tickets, customers read/update
**Group admin**Single group pending + content
5
Section 5 of 9

Staff users

**Menu:** Club Panel → Settings → Panel access → Staff users**

Page layout

  • Table: name, mobile, roles, last login, active.
  • Add staff — link existing person or invite new.

Step-by-step — onboard staff

  1. Add staff user.
  2. Enter mobile — must receive OTP for first login.
  3. Assign one or more roles — prefer single role for clarity.
  4. Set Active — inactive blocks login instantly.
  5. Tell staff to bookmark Club Panel URL and use secure device.
  6. First login: verify they see expected menu items only.

Step-by-step — offboard

  1. Set staff Inactive — do not delete if audit trail needed.
  2. Remove from Group admin assignments on groups.
  3. Rotate shared credentials if any were shared (discourage shared logins).
6
Section 6 of 9

Group admin scope

What group admin can do

  • View group dashboard (pending members, codes).
  • Approve/reject group join requests.
  • Manage group content shortcuts if enabled.

What group admin cannot do

  • Club-wide customers, acceptors, wallets, panel access.
  • Other groups' data.

Step-by-step — assign group admin

  1. Create or clone Group admin role in Roles.
  2. Create Staff user for community volunteer.
  3. Open Member groups → group → Admins tab → assign user.
  4. Volunteer logs in — lands on group dashboard not full Overview.
7
Section 7 of 9

Practical scenarios

Scenario — hire support agent

  1. Clone Support role.
  2. Remove wallet update if agents only ticket.
  3. Add staff user with mobile.
  4. Test: can open Support and Customers, cannot open Panel access.

Scenario — external accountant

  1. Custom role: Wallets view, Reports export, no customer delete.
  2. Time-bound: deactivate after audit season.

Scenario — marketing contractor

  1. Role: Content + Notifications + App Builder view/update.
  2. No finance modules.

Scenario — founder retains control

  1. Two owners max — primary and backup.
  2. Day-to-day Manager role for ops lead.
  3. Quarterly access review export staff list.
8
Section 8 of 9

Troubleshooting

SymptomCheck
Menu item missingRole lacks view on module OR option not on subscription
403 on saveUpdate permission missing — not view
Group admin sees whole clubWrong role template assigned
OTP not receivedMobile typo or inactive user
9
Section 9 of 9

Summary for support

  • Staff ≠ members — separate login and roles.
  • Permission matrix is source of truth for module × action.
  • Group admin = delegated community ops for one group only.
  • Deactivate staff immediately on departure — do not share Owner account.
Previous sectionNext section