Role Manager

Makaira ships with four default roles. Their names in the admin UI are Content Creator, Shop Manager, Administrator, and Owner. Internally they are stored as protected Makaira.* roles and cannot be edited or deleted.

Module access is decided by feature permissions (for example pageeditor.read). A user sees a dashboard tile when at least one of their assigned roles grants that permission. The tables below show the permission that gates each module and which default roles typically receive it.

Assign roles to people in User Management. Custom roles require the Role Manager module.

Typical default-role access

ModulePermissionContent CreatorShop ManagerAdministratorOwner
Page Editorpageeditor.read✅✅✅✅
Advertising Bannersbanner.read✅✅✅✅
Advertising Spacesplacement.read✅✅✅✅
Menu Editormenu.read-✅✅✅
A/B Testsabtesting.read-✅✅✅
Searchsearch.read-✅✅✅
Categoriescategories.read-✅✅✅
Ranking Mixrankingmix.read-✅✅✅
Personalizationpersonalization.read-✅✅✅
Recommendationsrecommendations.read-✅✅✅
Redirectsredirects.read-✅✅✅
Smart Bundlessmartbundle.read-✅✅✅
Streamsstreams.read-✅✅✅
Feedsproductfeeds.read-✅✅✅
Data Inspectordatainspector.read-✅✅✅
Category Mappingcategorymapping.read-✅✅✅
Trackingstatistics.read-✅✅✅
Index & Importerindices.read--✅✅
Settingssettings.read--✅✅
Storefront Settingsstorefront.read--✅✅
Component Editorcomponent.read--✅✅
Statisticstatistics.read--✅✅
Audit Logsauditlog.read--✅✅
User Managementusermanagement.read---✅
Role Managerusermanagement.read---✅
API Keyssecret.read---✅

Write access uses the matching .write permission (for example pageeditor.write). Granting write always requires the corresponding read permission.

Booked feature flags still apply: a role can grant abtesting.read, but the A/B Tests tile only appears if that module is booked on the instance.


The Role Manager lets you create up to five custom roles with their own feature permissions, including access to installed custom apps ({app-slug}.read). Custom role names must not contain -- or __ (those separators are reserved for SSO group notation).



Creating a custom role

When adding a new role you define the name and the grants for that role. After you save it, assign it to users in User Management.


Assigning a role

Open the user in User Management, choose the instance, and select the role (default or custom).

* The Role Manager (administration of custom roles) is only available when you book the Role Manager module.

Did this page help you?