Roles and permissions
What each role can see and do, and how to assign them without over-granting access.
5 min readSecurity & Data
Access in BeMetrix is role-based. Roles are stored separately from profiles and are checked on the server for every request, so hiding a menu item is never the only thing standing between someone and your data.
The roles
- Owner — full access, including billing and account deletion.
- Admin — everything operational: team, schedule, finance, payouts. No billing ownership.
- Operator / staff — day-to-day work: schedule, shift completion, and the finance areas you allow.
- Salesperson — recruiting and deals, with their own workspace and notifications.
- Creator — their own shifts, earnings, payouts and profile only.
Assigning a role
Set the role when inviting a person, or change it later from their member page. Changes take effect on their next request — no re-invite needed.
Principles worth following
- Give the narrowest role that lets someone do their job.
- Keep the number of owners and admins small.
- Review roles when people change responsibilities, not once a year.
Creators never see studio totals
A creator account is scoped to itself by design: their schedule, their earnings, their payouts. This is enforced server-side, not by hiding buttons.