Skip to main content

Permissions and access control

SRVZr uses account-scoped access control. A person signs in as a global user, then accesses one or more SRVZr business accounts. The permissions assigned to that person can be different for each account.

This means “the user has permission” is incomplete. The useful question is: does this user have this permission for the active SRVZr account?

Account-scoped access

Switching the active SRVZr account can change which settings, records, and actions are available to the same signed-in person.

SRVZr permission editor grouped into profile, analytics, inventory, and event access
The permission editor groups access by work area so an administrator can grant only what a teammate needs.

How access works​

When someone opens a page or tries an action, SRVZr considers:

  1. Sign-in , the person must be signed in.
  2. Account membership , the person must belong to the active SRVZr account.
  3. Ownership or administration , the account owner has full account-management access.
  4. Granted permissions , other members receive the specific access granted to them.
  5. Feature access , the page or action checks the permission it needs.

Membership alone does not imply unrestricted access. Likewise, one permission on one SRVZr account does not grant that permission on every account the person can access.

Administrators and delegated managers​

Profile administrator​

The profile administrator is the owner or administrator of the active SRVZr account.

Administrators can:

  • Edit SRVZr profile details.
  • Change the account owner.
  • Add and remove team members.
  • Open and edit the permission set for a team member.
  • Save permission changes.
  • Manage the full account-access surface.

Account Manager permission​

An Account Manager has broad administrative access to the active business, including its feature and financial permissions. The app derives these permissions from the role, including for existing memberships. Grant this role only to someone trusted to administer the business.

Edit SRVZr Details permission​

Edit SRVZr Details allows a delegated user to edit the business profile without making them the account owner or administrator. This is useful for an operations lead who maintains the business name, contact details, logo, theme color, or public visibility but should not manage the team.

Permission catalog​

The current permission editor groups permissions by domain.

SRVZr Profile​

PermissionAllows
Account ManagerManage team members, remove non-admin members, and edit their permissions.
Edit SRVZr DetailsEdit the SRVZr account profile: name, logo, contact information, and visibility.
VNTR SettingsAccess and modify VNTR event settings.

Analytics​

PermissionAllows
View Terminal SalesAccess the Terminal Sales analytics module.

Inventory​

PermissionAllows
Manual Inventory AdjustmentAdd or remove stock manually for restocking, damage, corrections, or other adjustments.
View Inventory AnalyticsView inventory analytics such as stock levels, sales trends, and revenue metrics.

VNTR event viewing and analytics​

PermissionAllows
View Event Ticket InfoView event ticket details.
View Event Amount SoldView ticket sales counts and amount-sold metrics.
View Event AnalyticsAccess event analytics dashboards and reports.

Financial​

PermissionAllows
Manage PayoutsView payout history and create payouts to linked bank accounts.
View PaymentsAccess the business-wide Payments page and transaction details.
Refund PaymentsIssue full or partial refunds for Stripe card payments.

Edit a member’s permissions​

  1. Open Settings.
  2. Select the SRVZr tab.
  3. Confirm the correct active account in the header.
  4. Find the person under Current Team Members.
  5. Select the edit/permissions action on their member tile.
  6. Review the categories and permission descriptions.
  7. Select only the capabilities required for the person’s job.
  8. Select Save Permissions.

The member tile shows a permission count, which is a quick signal that a custom set exists. It does not describe the sensitivity of those permissions; open the editor when auditing access.

The account owner or an Account Manager can edit and save permissions for the active business. Check permission-preview mode when evaluating the access a member will actually see.

After a permission change​

After selecting Save Permissions, the new access applies to the selected team member for the active SRVZr account. Ask the member to refresh their page or sign in again if a page still looks unchanged.

Permissions do not automatically carry over to another SRVZr account. Review access separately whenever a person works across multiple businesses.

Least-privilege patterns​

Use a permission set that matches the person’s responsibility:

Job patternSuggested access
Business profile maintainerEdit SRVZr Details only.
Business administratorAccount Manager only when broad business and financial administration is intended.
Inventory operatorManual Inventory Adjustment; add View Inventory Analytics if they review stock metrics.
Finance operatorView Payments; add Refund Payments only for people authorized to move money.
Finance administratorManage Payouts plus the specific payment permissions required by the workflow.
Event analystThe minimum VNTR viewing or analytics permissions needed for the report.

Use individual permissions for a limited role. Account Manager grants broad business access, rather than a limited team-coordinator permission.

Auditing and troubleshooting​

When someone cannot see or change a feature:

  1. Confirm they are signed in with the expected user account.
  2. Confirm they are viewing the intended SRVZr account.
  3. Confirm they are listed under Current Team Members.
  4. Check whether they are the owner/profile administrator.
  5. Open their permission editor and verify the exact permission label.
  6. Ask them to refresh their session if the permission was just changed.
  7. If the user still sees stale access, sign out and back in, then retry.

When someone has too much access, remove the unnecessary permission from the active account’s entry rather than removing unrelated accounts or deleting the global User record.

Security notes​

  • Do not share invitation QR codes or links beyond the intended team.
  • Revoke unused invitations.
  • Treat Refund Payments and Manage Payouts as financial controls.
  • Review Account Manager assignments because they grant broad business access and can affect other users’ access.
  • Test permission-sensitive workflows using a real account with the same delegated permissions as the intended operator.
  • Document why elevated permissions were granted and who owns the review.