Quick answer
User access has three layers:
- Organization membership: the user belongs to your org.
- Role: what they are allowed to do.
- Site access: where they can work, for multi-site orgs.
For paid-plan features and capacity limits such as users, sites, wine cards and AI chat limits, see Tier entitlements and plan limits.
Who can manage users
- User-management actions are restricted to members with user-management rights, typically Owner and Admin.
- Owner-level members are protected. Only owner-level authority can transfer ownership or remove the last owner.
- Assigning site access requires site-management permission.
Core tasks
Invite a member
Send an organization invite by email and assign a role. The assignable roles are Owner, Admin, Manager, Staff and Viewer.
Resend or revoke pending invites
Pending invitations can be resent or revoked from the invitation list.
Change a member role
Role updates are available for onboarded members. Role reassignment in Account Settings follows the canonical role set above.
Role to permissions matrix
Use this matrix when changing member roles in Account Settings.
| Action | Owner | Admin | Manager | Staff | Viewer |
|---|---|---|---|---|---|
| View organization data | Yes | Yes | Yes | Yes | Yes |
| Manage members and invitations | Yes | Yes | No | No | No |
| Assign organization roles | Yes | Yes (bounded, no owner transfer or removal) | No | No | No |
| Manage organization settings | Yes | Yes | No | No | No |
| View billing and subscription details | Yes | Yes | No | No | No |
| Manage billing and subscription changes | Yes | No | No | No | No |
| Transfer ownership | Yes | No | No | No | No |
| Delete organization | Yes | No | No | No | No |
| View WineHub inventory | Yes | Yes | Yes | Yes, assigned sites only | Yes, assigned sites only |
| View public selling prices | Yes | Yes | Yes | Yes, assigned sites only | Yes, assigned sites only |
| View purchase prices, lot costs, margins or pricing rules | Yes | Yes | Yes | No | No |
| Add or edit WineHub catalogue records | Yes | Yes | Yes | Yes, assigned sites only | No |
| Make operational stock adjustments, including purchase intake, sale, found or lost, waste, sample, and same-site stock allocation to storage units or configured rows | Yes | Yes | Yes | Yes, assigned sites only | No |
| Inter-site transfer, select lots, or manage lot-cost stock actions | Yes | Yes | Yes | No | No |
| Manage wine cards | Yes | Yes | Yes | Yes, assigned sites only | No |
| Export wine card PDFs | Yes | Yes | Yes | Yes, assigned sites only | No |
| Manage suppliers | Yes | Yes | Yes | No | No |
| Manage wine clubs | Yes | Yes | Yes | No | No |
| Browse the services marketplace | Yes | Yes | Yes | No | No |
Notes:
- Staff and Viewer require explicit site access. With no site assigned they see a no-site-access page and can request venue access from an Owner or Admin.
- Manager, Staff and Viewer access can still be limited by site access assignments.
- Viewer is read-only for WineHub and wine cards. A Viewer cannot add, edit, duplicate, delete, publish, export PDFs or adjust inventory.
- Staff is operationally bounded. Staff can work on WineHub catalogue data, make assigned-site stock movements such as purchase intake, sale, found or lost, waste, sample and same-site stock allocation, and manage wine cards for assigned sites. Staff cannot access existing purchase prices, lot costs, pricing rules, inter-site transfers, suppliers, wine clubs, services, replenishment settings, API tokens, billing or user management.
- Public selling prices can be visible to Staff and Viewer because they are customer-facing wine card data. Purchase prices, lot costs, market prices, margins and pricing rules stay restricted.
- Roles define authority. Plan limits such as users, sites and wine cards are managed separately.
Configure site access
- Assign accessible sites per member in multi-site orgs.
- Owners keep full-site access by design.
- At least one site must remain selected for non-owner members.
Handle access requests
Pending access requests can be approved or rejected. After approval the user moves into the normal organization membership flow.
Remove a member, or leave an org
- Admins can remove other members.
- A user cannot remove themselves from the member list. Use the leave-organization action instead.
- Safety checks prevent leaving or removing the last required owner-level admin.
Pending onboarding state
Some invited users exist in identity provider records but have not completed onboarding yet. In that state they appear as pending, and role or site access operations can be limited until onboarding completes.