Set up access and apps

Users, roles and permissions

Get your own colleagues into the Cockpit — and keep them apart from your customers' buyers.

This page is about your team: the colleagues who work in the Cockpit. It is not about the people who buy from you.

The distinction that costs the most time. Your customers' buyers are managed under CRM › Contacts, per customer organization, with their own roles under CRM › Roles for who may see prices, order, and approve. That is a separate system with separate logins; see Contacts and roles. Nothing on this page affects a single buyer, and nothing on that page affects a single colleague.The same trap has a second door: Settings › Auth & Security is titled Auth & Security · Customers for a reason. Its password rules and session length apply to your buyers signing in to your storefront, not to your team.

Invite a colleague

  1. Go to Settings › Team, tab Members.
  2. Select Invite member.
  3. Fill in Given name, Family name, Email and Preferred language.
  4. Send it.

They receive an initialisation email, set their own password with the identity provider, and from then on sign in through single sign-on. You never see or set their password.

The member list shows a state for each person, Active, Invited, Suspended or Locked, and the filter chips above it narrow to each. An invitation that was never accepted sits at Invited; Resend invitation sends it again.

When somebody leaves

Two different actions, and the difference matters:

ActionWhat it doesUse it when
SuspendBlocks sign-in. The account stays.Someone is on parental leave, between contracts, or under investigation
Remove from organisationDeletes their identity-provider record. Permanent.Someone has left for good

Suspend is the safe default. Removal cannot be undone, and a removed person has to be invited again from scratch. Reactivate reverses a suspension.

Whichever you choose, do it the day the person leaves, not at the end of the month. Then check the Sessions tab: suspending an account does not end a session that is already open.

Roles today

Access to the Cockpit is a matter of membership. Somebody who is a member of your organisation in the identity provider can sign in; somebody who is not, cannot. Every colleague you invite gets the same Cockpit access.

Role editor: planned. There is no role column in Settings › Team and no permission editor. Changing what one colleague may do is a request to your revenexx contact rather than something you do yourself. The building blocks are already there: apps declare a permission vocabulary, and an app update lists New permissions you can assign when it adds to it. The screen that hands those permissions to individual people is what is still to come.Plan around it: the same access for everyone is fine for a five-person admin team, and it is not fine if you intended to give a working student read-only access to orders. If you need that separation now, say so before you invite the person.

Do not confuse this with CRM › Roles. That screen is real and works today, and it defines what your customers' buyers may do in your shop. It has nothing to do with Cockpit access.

Watch the sessions

Settings › Team › Sessions lists the active sign-ins for your whole organisation, not only your own devices. The columns are Device / Browser, Auth Factors (password, passkey, totp, sms otp, email otp, sso) and Activity & Expiration: when the session was last active and when it expires.

Terminate Session ends one. Do that for any session nobody can account for, and have the account it belongs to change its password afterwards. Reading this list once a month takes two minutes and is the cheapest security control you have.

What to check

After inviting someone, confirm they appear as Active rather than Invited within a day. An invitation sitting unaccepted usually means the mail was filtered. After removing someone, confirm they are gone from Members and have no row left in Sessions.

Next