Team and roles
Invite people to help run your storefront, choose what each one can do, and suspend or remove access — all from Settings → Team & roles.
Published
Where your team lives
Settings → Team & roles answers one question: who can get into your kitchen, and what they can do. The table has three columns — Person, Role and Status — with the team seats meter above it and the invite button in the header.
Every row is a person who has already joined. An invitation you sent this morning is not on the roster yet; it appears once they accept and sign in for the first time.
Search matches a teammate’s name, email or username, and the chips narrow the table to Active, Suspended or the people whose email is still unconfirmed.
Invite a teammate
Invite teammate asks for two things — the email address they will sign in with, and what they can do — and then states the consequence before you send it:
- they get one email with a link to join, and that link expires in 7 days;
- they join in the role you picked;
- the seat is held from the moment you send, not from the moment they accept.
If the address is already on your team, the panel says so and offers you their row instead of sending a second invitation. If the invitation was created but the email could not be delivered, invite the same address again — that replaces the first invitation and sends a fresh link.
There is no way to join a storefront from the outside. An emailed invitation is the only door in.
Team seats
The meter above the table is your plan’s team seat allowance and how much of it is in use. An active teammate uses a seat; a suspended one does not, which is the difference that makes Suspend access useful when someone stops for the season.
At the limit, the invite panel warns rather than blocks: it says the invitation puts you over your plan’s limit, and lets you send it anyway. If it is refused because there is no seat left, nothing was sent and no seat was taken — suspend or remove somebody to free one.
Roles, and what they reach
Roles → in the header opens the roles table (Role · Description · Permissions · Members), which is where roles are compared side by side rather than one at a time.
Your storefront starts with a single role, Admin, which holds everything and carries
a System badge: it cannot be renamed, edited or deleted. Every other role in the table
is one your team built.
Opening a role opens its editor, with the permissions grouped by what they reach. From there you can:
- create a role with New role, or start from an existing one with Duplicate as new role;
- see who holds a role — the Members count opens the roster filtered to that role;
- delete a role with Delete role…. If people hold it, the confirm makes you choose the role they move to first, and describes the change from that choice.
A new storefront has only Admin to invite people into, so if your first teammate should not be able to do everything, build their role before you send the invitation.
Some access is structural, and no role can withhold it: reading the team and reading the roles come with being on the team at all. Editing a role only ever changes what it adds on top of that floor — it can never take the floor away.
Change someone’s role
Change role… opens a picker pre-selected to the role they hold today, and states what the change does — the permissions they gain, or the ones they lose — before you commit it. Choosing the role they already hold says so and does nothing.
Your own row does not offer it — you cannot change your own role from here — and neither does a teammate holding more than one role, because saving one role back would silently drop the other. Editing a role you hold asks before it saves, since the change applies to you the moment you do.
Suspend, reactivate or remove access
Suspend access… is the reversible one. The person cannot sign in from that moment, the devices they are already signed in on are signed out, their history, orders and messages stay exactly as they are, and the seat is released. Reactivate puts them straight back — no confirm, because turning access back on is the safe direction — and only asks when it would put you over your seat limit.
Remove from team… is the permanent one. They lose all access immediately, their devices are signed out, and there is no undo — though you can invite them again later, which is why the confirm says so before you press the button.
A member’s record also carries the smaller repairs: resend an email confirmation, mark an address confirmed yourself, reset two-factor, and sign out one device or every device.