Create, edit and remove users
The user is the sign-in. Removing one is how access ends; leaving a disabled account around is how it does not.
Users & Roles decides who may sign in and what they may do once they have. Roles are built from the 335 named permissions, and viewing a role is permissioned separately from changing one.
Who may sign in, and what they may do once they have.
The user is the sign-in. Removing one is how access ends; leaving a disabled account around is how it does not.
Every permission has a name and a meaning. Start from the smallest role that lets somebody work, and add on request — the reverse process never happens.
Viewing and editing roles are separate rights, so a manager can check what their team can do without being able to widen it.
The capability list this guide is written against, unabridged. Nothing above adds to it.
Users & Roles on the Administration pageThe modules Users & Roles hands work to, or takes it from. Most problems that look like one module are a handover between two.