Team, Roles & RBAC PermissionsEssentialIntermediate

Team Management, Staff Roles & RBAC User Permissions

Invite staff members, assign 5-tier role-based access control (Owner, Admin, Manager, Staff, Member), configure Clerk organization RBAC, and manage member permissions.

6 min readUpdated 2026-09-19
In This Guide
  • Delegate daily operations (chat replies, packaging, catalog edits) without sharing master owner credentials.
  • Assign 5 granular role tiers: Owner, Admin, Manager, Staff, and Member / Moderator.
  • Enforce strict multi-tenant boundaries via tenantDb and Clerk organization JWT verification.
  • Instantly revoke access or alter user permissions with zero delay across active sessions.
Prerequisites

Before configuring this feature, confirm that your store meets the following requirements:

Store Ownership or Admin Role:You must be signed in with org:owner or org:admin privileges to view and manage team members.
Staff Email Address:A valid, active email address for each teammate you wish to invite.
conversora.io/admin/users-and-team
Users & permissions hub displaying active members, pending invitations, and granular role controls.
Click to enlarge

Users & permissions hub displaying active members, pending invitations, and granular role controls.

5-Tier Roles
Owner, Admin, Manager, Staff, and Member privilege sets.
Instant Invitation
Email invitations dispatched via Clerk with one-click acceptance.
Access Revocation
Instant session termination and membership severance.

1. Understanding the 5-Tier Role Hierarchy

Conversora provides 5 distinct operational role levels designed to fit standard retail organizational structures:

  • Owner (org:owner): Complete apex control over the store, organization billing, plan upgrades, and ownership transfers.
  • Admin (org:admin): Full operational authority over products, orders, settings, custom domains, payment gateways, and staff invitations. Cannot transfer store ownership.
  • Manager (org:manager): Oversees daily business operations, catalog publishing, marketing discounts, customer service, and performance analytics. Cannot alter gateway credentials or invite admins.
  • Staff (org:staff): Dedicated operational role for packaging and warehouse fulfillment teams. Can view and update order delivery statuses, pack parcels, and print invoices.
  • Member / Moderator (org:member): Read-only view of products, customer chats, and order queues. Ideal for junior trainees or external auditors.

2. Inviting a New Team Member

Inviting a teammate takes less than 30 seconds. Invitations are dispatched via email with secure, one-time acceptance links.

1

Open Users & Permissions

Navigate to Settings in the sidebar and select 'Users & permissions'.

Path:Admin Sidebar → Settings → Users & permissions
2

Click Invite User

Click the 'Invite User' button in the upper-right corner of the workspace.

Path:Users & Permissions Toolbar → Invite User Button
3

Specify Email & Role

Input the colleague's email address and select their appropriate role tier.

Path:Invite Modal → Email Input → Role Selector
4

Send Invitation

Click 'Send Invitation'. The recipient receives an immediate email invite, and their status appears under 'Pending Invites'.

Path:Invite Modal → Send Invitation
Pro Tip

Always follow the Principle of Least Privilege: assign the lowest role tier necessary for a teammate to complete their daily job.

3. Changing Roles and Revoking Access

You can change an existing team member's role at any time. When an employee departs, revoking their access immediately terminates their dashboard session.

1

Locate Teammate in Directory

Find the member in the Users table or use the search bar to locate them by name or email.

Path:Users Table → Search / Filter
2

Change Role or Remove

Click 'Change Role' to adjust their role tier, or click the action menu (...) and select 'Remove User'.

Path:User Row → Actions → Change Role / Remove User
3

Confirm Action

Confirm the dialog. The change takes effect instantaneously.

Path:Confirmation Modal → Confirm

Practical Business Scenarios

How leading merchants implement this functionality in daily operations:

Onboarding Part-Time Chat Support
Situation: A merchant needs two part-time support representatives to reply to customer Instagram and WhatsApp chats during peak evening hours.
Best practice: Invite them under the Manager or Staff role with chat assignments. They can view customer context and assist buyers, while payment keys and domain settings remain locked.
Warehouse Logistics Team
Situation: Packing staff need to print PDF invoices, see customer phone numbers for courier delivery, and mark parcels as Shipped.
Best practice: Assign the Staff role. Warehouse staff have full fulfillment access to manage orders and print shipping labels without visibility into business profit analytics.

Troubleshooting & Common Issues

Diagnose and resolve frequent failure points quickly:

Problem: Invited user reports they did not receive the invitation email
Why this occurs: Corporate spam filters may block external invitation links, or the user already has an active account under a different email.
Resolution: Ask the user to check their Spam/Junk folder. You can also revoke the pending invite and re-send it, or verify the exact spelling of their email.
Problem: Manager cannot access Payment Gateways or Custom Domains
Why this occurs: Security policy deliberately restricts sensitive financial and domain configurations to Owner and Admin roles.
Resolution: If this staff member is responsible for gateway setup, elevate their role to Admin in the Users & permissions hub.

Frequently Asked Questions

Can team members see each other's personal passwords?

No. Conversora never stores passwords. Teammates authenticate securely via Clerk with individual multi-factor authentication (MFA).

What happens when a team member is removed from the store?

Their active session is severed immediately, revoking access to all store data, orders, and customer records across all logged-in devices.