Skip to main content

Users & roles

Collector uses configurable role-based access control: you build roles from a catalog of granular permissions, then assign roles to staff users. Treasurers, secretaries, and data clerks each see exactly what their job needs — no more, no less.

How it fits together

  • Permission — a single capability from a fixed catalog (e.g. view members, record payments, manage products, generate reports).
  • Role — a named bundle of permissions that you create. Examples: Treasurer, Secretary, Data clerk, Auditor (view-only).
  • User — a staff login, assigned one or more roles. A user's abilities are the union of all their roles' permissions.

A default Admin role with every permission, plus the initial admin user, are created when the system is first set up.

Managing staff users

The permission catalog

AreaPermissions
Membersview, create, edit, delete
Productsmanage products, manage payment rules
Paymentsrecord, view
Obligationsview
Reportsgenerate, view
Notificationsconfigure, send
Administrationmanage roles, manage users, organization settings

Creating a role

Under Admin → Roles:

  1. New role, give it a name that matches the job (Treasurer).
  2. Tick the permissions the job needs.
  3. Save — the role is immediately assignable.

Building a role from the permission catalog

Suggested starting roles

RolePermissions to include
TreasurerMembers view · Payments record/view · Obligations view · Reports generate/view
SecretaryMembers view/create/edit · Obligations view
Data clerkMembers view · Payments record
AuditorView-only: members, payments, obligations, reports

Creating a user

Under Admin → Users:

  1. New user — username, name, email, initial password.
  2. Assign one or more roles.
  3. Share the credentials; the user should change their password at first sign-in (from their user page).

Deactivate users who leave rather than deleting them — their name stays attached to the payments they recorded, keeping the audit trail intact.

Everything is audited

Every payment records who recorded it; configuration changes record who made them and when. Combined with numbered receipts, this is your accountability story for the annual audit: any figure in a report can be traced to who entered it and when.

Least privilege

Resist giving everyone the Admin role for convenience. The audit trail is far more useful when record payments belongs to two named treasurers than when ten people share full access.