Staff roles & permissions
As your team grows, not everyone needs — or should have — access to everything. CIQRA controls this with roles and permissions, so each person can do their job without being handed the keys to the whole store. This is a conceptual overview of how that access model works.
Roles and permissions, briefly
Section titled “Roles and permissions, briefly”- A permission is a single scoped capability — the ability to work in one area of the product.
- A role is a named bundle of permissions that you assign to a staff member, so you grant access by role rather than one capability at a time.
Together they decide what a given teammate sees and can act on when they sign in.
Access is scoped by area
Section titled “Access is scoped by area”Permissions in CIQRA are scoped to areas of the product, so access can be as broad or as narrow as each person needs. Those areas include:
- Catalog — products, collections and related management.
- Orders — processing, fulfilment and returns.
- Customers — the customer list and profiles.
- Analytics — reports and store performance.
- CMS — content pages, blog and menus.
- Settings — store-level configuration.
Because access is scoped, someone who handles fulfilment can be given order-related capabilities without also gaining the ability to change settings, and an analyst can read reports without touching your catalog.
Why this matters
Section titled “Why this matters”- Least privilege. People get the access their role needs and no more, which limits the blast radius of a mistake or a compromised account.
- Clarity. Staff see the parts of the admin that are relevant to them, which keeps the dashboard focused.
- Accountability. Individual accounts with scoped roles mean actions can be attributed to a person. Access is logged — see Your account & sessions.