Manage administrators, roles and permissions
An administrator is a person who signs in to the Raytha admin. What they can see and change comes only from the roles you give them, and each role is a named set of permissions. This page shows how to add an administrator, build a role, and what every permission allows.
How access works
Raytha has three layers. Keep them straight and the screens make sense.
- Administrators are people with an admin login. They are listed under People > Admins.
- Roles are named bundles of permissions. They are listed under People > Roles. An administrator can hold several roles and can do anything any of them allows.
- Permissions come in two kinds: eight system permissions that cover areas of the admin, and a Read / Edit / Configure grid for each content type.
Three roles exist from the first setup. Super Admin and Admin hold every system permission and full access to the Posts content type. Editor holds Manage Site Pages and Manage Media plus full access to Posts. You can edit Admin and Editor. You cannot edit or delete Super Admin.
Website visitors who sign in (public users) are a separate thing and have no admin roles. See Public users and user groups.
Add an administrator
You need the Manage Administrators permission. The people you add must have an email address that no other account in Raytha uses, because admins and public users share one list of addresses.
- Open People > Admins and click New admin.
- Enter First name, Last name and Email.
- Leave Email them a welcome message with a temporary password ticked if SMTP is working (see Set up SMTP and email). Clear it if you will hand the password over yourself.
- Under Roles, tick at least one role. An administrator with no roles can sign in but sees almost nothing.
- Click Create admin.
You land on the new administrator's page. If you cleared the welcome email, scroll to Reset password, enter a New password of at least 8 characters, enter it again under Confirm password, and click Reset password. Tick Email the new password if you want it sent.
Change, suspend or remove an administrator
Open the person from People > Admins. The page has these sections:
| Section | What it does |
|---|---|
| Details and Roles | Change the name, email and roles, then click Save changes. |
| Account access | Suspend blocks sign-in and keeps the account. Restore undoes it. Remove admin access removes every admin role and turns the person into a public website user; their content and history stay. |
| Impersonate | Super admins only. Signs you in as that administrator to see the admin the way they do. The session ends on its own after a time limit (60 minutes by default) and your actions are audited under both names. |
| Reset password | Sets a new password. Available only while the account is active. |
| API keys | Keys that sign in as this administrator. See Create an API key. |
| Delete admin | Deletes the account and its API keys. Audit history keeps the name. It cannot be undone. |
Create a role
- Open People > Roles and click New role.
- Enter a Label such as "Blog editor". The Developer name is filled in for you; it cannot be changed later.
- Under System permissions, tick the areas this role can manage.
- Under Content types, tick Read, Edit and Configure for each content type the role may use.
- Click Create role.
Then open an administrator and tick the new role. The Select all and Clear all buttons above each section save clicks.
System permissions
The checkboxes on a role use these labels. The table lists what each one opens in the admin, taken from the permission checks in the server.
| Permission | What it allows |
|---|---|
| Manage System Settings | Configuration (including SMTP), Authentication, Email templates, Email log, Webhooks, Functions, Maintenance (log retention and clearing logs) and Background tasks. It also includes every other permission; see below. |
| Manage Administrators | People > Admins, People > Roles and administrators' API keys. It also includes every other permission. |
| Manage Audit Logs | The Audit log page and the Recent activity panel on the dashboard. It does not include the Email log. |
| Manage Content Types | Create and delete content types, import and export schemas, manage Menus, and read, edit and configure every content type, including ones created later. |
| Manage Templates | Themes, web templates and widget templates. |
| Manage Users | People > Users and User groups, and impersonating a public user. |
| Manage Site Pages | Create, edit, publish and delete site pages, and preview their unpublished drafts. |
| Manage Media | Browse, upload and delete files in the media library. |
Important Manage System Settings and Manage Administrators each include every system permission, and the role form ticks all eight when you tick either one. This is deliberate. Functions run JavaScript with full access to the site, and authentication settings decide who can sign in, so whoever controls them can grant themselves anything. Treat both as "full admin".
Per-content-type access
Under Content types each content type has three columns:
| Column | Allows |
|---|---|
| Read | View items, views and exports of that content type. |
| Edit | Create, edit, publish, unpublish, delete and restore items; import from CSV; preview unpublished drafts on the public site. Includes Read. |
| Configure | Change the content type's settings, fields and views. Includes Read. It does not include deleting the content type; that needs Manage Content Types. |
If a role holds Manage Content Types, the grid is replaced by a note that it grants all three on every content type. Ticking Edit or Configure ticks Read for you and locks it.
What you can and cannot grant
Raytha stops anyone from raising their own access. These rules are enforced by the server, and the form greys things out so you see them coming.
- You can only give a role permissions you already hold. A checkbox you do not hold is disabled, and a role that grants something you lack shows "Grants permissions you do not have."
- You cannot change your own roles, suspend yourself, remove your own admin access or delete yourself. Ask another administrator.
- Only a super admin can assign, remove or manage the Super Admin role and accounts that hold it.
- You cannot edit, suspend, reset or delete an administrator who holds permissions you do not have.
- The last active Super Admin cannot be suspended or deleted.
- A role cannot be deleted while any administrator still holds it. Remove it from them first.
Gotchas
- Menu items missing for someone. The sidebar shows only what the person's roles allow. If a colleague cannot see Email log, they need Manage System Settings; Manage Audit Logs is not enough, even though the checkbox wording suggests otherwise.
- Menus need Manage Content Types, not Manage Site Pages, even though menus are used on pages.
- A suspended administrator's API keys stop working. The API answers "Api key is not connected to an active administrator" until you click Restore.
- Email addresses are unique across everyone. Admins and public users share one list, so creating an administrator with an address that already belongs to a public user fails with a message that the address is already in use. Use a different address, or delete the public user first.
- Changes apply to people who are already signed in. The server re-reads roles and the active flag on every request, so a suspended administrator loses access on their next click. Their sidebar can lag until they reload the page.