← All guides

    Team and plan

    Managing users and access

    Control who can enter your organization, what role they hold, and which sites they can work in, with the full role-to-permissions matrix.

    Quick answer

    User access has three layers:

    1. Organization membership: the user belongs to your org.
    2. Role: what they are allowed to do.
    3. Site access: where they can work, for multi-site orgs.

    For paid-plan features and capacity limits such as users, sites, wine cards and AI chat limits, see Tier entitlements and plan limits.

    Who can manage users

    • User-management actions are restricted to members with user-management rights, typically Owner and Admin.
    • Owner-level members are protected. Only owner-level authority can transfer ownership or remove the last owner.
    • Assigning site access requires site-management permission.

    Core tasks

    Invite a member

    Send an organization invite by email and assign a role. The assignable roles are Owner, Admin, Manager, Staff and Viewer.

    Resend or revoke pending invites

    Pending invitations can be resent or revoked from the invitation list.

    Change a member role

    Role updates are available for onboarded members. Role reassignment in Account Settings follows the canonical role set above.

    Role to permissions matrix

    Use this matrix when changing member roles in Account Settings.

    ActionOwnerAdminManagerStaffViewer
    View organization dataYesYesYesYesYes
    Manage members and invitationsYesYesNoNoNo
    Assign organization rolesYesYes (bounded, no owner transfer or removal)NoNoNo
    Manage organization settingsYesYesNoNoNo
    View billing and subscription detailsYesYesNoNoNo
    Manage billing and subscription changesYesNoNoNoNo
    Transfer ownershipYesNoNoNoNo
    Delete organizationYesNoNoNoNo
    View WineHub inventoryYesYesYesYes, assigned sites onlyYes, assigned sites only
    View public selling pricesYesYesYesYes, assigned sites onlyYes, assigned sites only
    View purchase prices, lot costs, margins or pricing rulesYesYesYesNoNo
    Add or edit WineHub catalogue recordsYesYesYesYes, assigned sites onlyNo
    Make operational stock adjustments, including purchase intake, sale, found or lost, waste, sample, and same-site stock allocation to storage units or configured rowsYesYesYesYes, assigned sites onlyNo
    Inter-site transfer, select lots, or manage lot-cost stock actionsYesYesYesNoNo
    Manage wine cardsYesYesYesYes, assigned sites onlyNo
    Export wine card PDFsYesYesYesYes, assigned sites onlyNo
    Manage suppliersYesYesYesNoNo
    Manage wine clubsYesYesYesNoNo
    Browse the services marketplaceYesYesYesNoNo

    Notes:

    • Staff and Viewer require explicit site access. With no site assigned they see a no-site-access page and can request venue access from an Owner or Admin.
    • Manager, Staff and Viewer access can still be limited by site access assignments.
    • Viewer is read-only for WineHub and wine cards. A Viewer cannot add, edit, duplicate, delete, publish, export PDFs or adjust inventory.
    • Staff is operationally bounded. Staff can work on WineHub catalogue data, make assigned-site stock movements such as purchase intake, sale, found or lost, waste, sample and same-site stock allocation, and manage wine cards for assigned sites. Staff cannot access existing purchase prices, lot costs, pricing rules, inter-site transfers, suppliers, wine clubs, services, replenishment settings, API tokens, billing or user management.
    • Public selling prices can be visible to Staff and Viewer because they are customer-facing wine card data. Purchase prices, lot costs, market prices, margins and pricing rules stay restricted.
    • Roles define authority. Plan limits such as users, sites and wine cards are managed separately.

    Configure site access

    • Assign accessible sites per member in multi-site orgs.
    • Owners keep full-site access by design.
    • At least one site must remain selected for non-owner members.

    Handle access requests

    Pending access requests can be approved or rejected. After approval the user moves into the normal organization membership flow.

    Remove a member, or leave an org

    • Admins can remove other members.
    • A user cannot remove themselves from the member list. Use the leave-organization action instead.
    • Safety checks prevent leaving or removing the last required owner-level admin.

    Pending onboarding state

    Some invited users exist in identity provider records but have not completed onboarding yet. In that state they appear as pending, and role or site access operations can be limited until onboarding completes.

    Related guides