Manage staff access
Operator administrators can manage staff and roles. Staff navigation is generated from effective permissions, while server route guards remain the final authorization boundary.Create a staff account
The current staff form requires:- name;
- unique email;
- password of at least 8 characters (maximum 191);
- optional phone;
- optional role and individual permissions;
- optional NAS restriction;
- active/inactive status.
- Create a separate account for the person—never reuse the owner account.
- Assign the narrowest role that covers their job.
- Add individual grants only when the role is insufficient.
- Restrict the account to a NAS when its work is location/router-specific.
- Deliver the initial password securely and require a change after first sign-in.
- Have the user enable 2FA.
Permission model
Navigation areas such as Subscribers, Leads, Tickets, Active users, Packages, Routers, Equipment, Billing, Communications, and Analytics appear only when the user has the corresponding capability. Not seeing a row is expected when access is absent. Do not grant a broad role merely to reveal one menu. Update the role or individual permission deliberately and test using the staff account’s actual navigation.Sensitive staff actions
Removing staff, resetting passwords, and saving sensitive changes can require an action OTP. Follow the verification dialog; never ask the affected staff member to forward their sign-in OTP. Password reset generates a temporary password. Copy it only through a secure channel, then clear it from notes/chat and require the user to change it.Impersonation
Where authorized, impersonation lets an administrator view the workspace as a staff member for troubleshooting. The application displays an impersonation banner and provides a return action. Use impersonation to inspect permissions and UI state, not to perform routine work as the user. Record consequential actions, stop impersonating promptly, and never request the user’s password.Offboarding
- Disable or remove the staff account.
- Reassign open tickets and leads.
- Revoke API tokens created for the person’s integrations.
- Rotate webhook secrets, payment credentials, router credentials, or provider keys they controlled when appropriate.
- Review recent audit activity.
- Preserve records required for operations or compliance.
