> ## Documentation Index
> Fetch the complete documentation index at: https://andcze.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Team and permissions

> Invite collaborators to your shop panel and decide precisely who can do what.

<Frame caption="The Team section in the shop panel">
  <img src="https://mintcdn.com/andcze/6Qp9zwUm8VUzRssf/images/panel/team.png?fit=max&auto=format&n=6Qp9zwUm8VUzRssf&q=85&s=fc22e8e084ce9e0783c2535202e8a780" alt="A list of team members with their access level" width="1280" height="720" data-path="images/panel/team.png" />
</Frame>

Running a shop is rarely a one-person job. Someone helps handle orders, someone else adds products or answers players' questions. The **Team** section lets you invite these people to the panel and decide exactly what each of them can do — without handing over full control of your shop. That way you never have to share your account password. Every collaborator logs in to their own account and sees only what you allow them to.

## Why you need a team

<Columns cols={3}>
  <Card title="Security" icon="shield-check">
    No one needs your password. Everyone has their own account and only the permissions you grant them.
  </Card>

  <Card title="Shared workload" icon="users">
    One person looks after products, another handles orders, and you keep an eye on the whole thing.
  </Card>

  <Card title="Full control" icon="sliders-horizontal">
    At any moment you can change a collaborator's level of access or take it away entirely.
  </Card>
</Columns>

## Two main access levels

The simplest way to think about permissions is as two levels: people who **can only look**, and people who **can make changes**.

<Columns cols={2}>
  <Card title="View only" icon="eye">
    The person sees the shop, products, orders and statistics, but can't change anything. Perfect for someone who only needs to glance at the numbers or follow sales — for example a partner who wants visibility, or someone learning how to run the shop.
  </Card>

  <Card title="Full access" icon="crown">
    The person can do everything: add and remove products, handle orders, change settings, and even manage other team members. This level is for a trusted co-owner — treat it like having a second host of the shop.
  </Card>
</Columns>

<Note>
  Between these two extremes you can set any level in between — for example someone who handles orders but doesn't touch the shop settings. That's what **permission templates** are for, which we describe below.
</Note>

### Ready-made permission templates

So you don't have to set everything up from scratch, when inviting someone you pick one of the ready-made templates. It's a convenient starting point that you can fine-tune afterwards.

<AccordionGroup>
  <Accordion title="Full access" icon="crown">
    All permissions in the shop. For trusted co-owners who should do literally everything you can do.
  </Accordion>

  <Accordion title="Administration" icon="shield-check">
    Managing the entire shop — products, orders, settings, payments and the team — except deleting the shop itself and removing the owner's access.
  </Accordion>

  <Accordion title="Sales and orders" icon="shopping-cart">
    Handling products, orders, discount codes and vouchers. No access to shop settings. Good for someone running the catalog and sales.
  </Accordion>

  <Accordion title="Support" icon="life-buoy">
    Viewing and handling orders and player data, without the ability to edit the catalog. Ideal for someone answering players' questions about their purchases.
  </Accordion>

  <Accordion title="View only" icon="eye">
    Reading the shop, products, orders and statistics. Without making any changes at all.
  </Accordion>

  <Accordion title="Custom" icon="sliders-horizontal">
    You start from scratch and tick exactly the permissions you need.
  </Accordion>
</AccordionGroup>

### Exact permissions (for advanced users)

Below the templates you'll find a table of **exact permissions**. Each row is one area of the shop (e.g. Products, Orders, Payments, Statistics), and each column is a type of action:

<Columns cols={2}>
  <Card title="Read">
    The person can browse a given area, but can't make changes.
  </Card>

  <Card title="Write">
    The person can add and edit items in a given area.
  </Card>

  <Card title="Delete">
    The person can delete items in a given area.
  </Card>

  <Card title="Manage">
    Full control over the area — reading, writing and deleting all at once.
  </Card>
</Columns>

<Tip>
  You don't have to study the whole table. Start with the template that fits best, then optionally untick or add individual boxes. At the very bottom you always see the **"This person will be able to"** section, which sums up in plain language exactly what the collaborator gets. Read it before you send the invitation.
</Tip>

## Inviting via an invite link

The handiest way to add someone to your team is an **invite link**. You create it once, set the permissions, and then simply send the link to the person — over Discord, a message or email.

<Steps>
  <Step title="Click “Invite”">
    In the header of the Team section, press the **Invite** button. The link creation window will open.
  </Step>

  <Step title="Choose the permissions">
    Pick a template (**View only** is set by default) and, if needed, fine-tune the exact permissions. Check the summary at the bottom.
  </Step>

  <Step title="Set how long it lasts">
    Decide how long the link should stay valid: **24 hours**, **7 days**, **30 days** or **no time limit**. After that, the link stops working.
  </Step>

  <Step title="Set the number of uses">
    Specify how many people can use the link: **1 person**, **5**, **10**, **25** or **no limit**. Once the limit runs out, the link stops working on its own.
  </Step>

  <Step title="Create and copy the link">
    Press **Create link**, then **Copy**. Send the ready link to the person you want to invite. You can also create another link right away with different permissions.
  </Step>
</Steps>

<Info>
  One link can have different permissions than another. For example, you can create a "View only" link for observers and a separate "Sales and orders" link for your support staff — and send each to a different group.
</Info>

### What the invited person sees

When someone clicks your link, they'll see a page with the name of your shop and the access level they're set to receive. After logging in (or creating an account), they **send a request to join** — they don't enter the panel right away. The decision is yours, when you approve that request. This way you can be sure that only the right person joins.

## Active invite links

All the links you've issued that are still working appear in the **Active invite links** list. For each one you'll find:

<Columns cols={2}>
  <Card title="Access level">
    A label showing which permissions the person using this link will receive.
  </Card>

  <Card title="Usage">
    How many times the link has already been used and how many uses remain (or a note that it has no limit).
  </Card>

  <Card title="Expiry">
    The date the link expires, or a "no time limit" note.
  </Card>

  <Card title="Actions">
    At any time you can **copy** the link again or **delete** it.
  </Card>
</Columns>

<Warning>
  If someone unauthorized could have seen the link (for example it ended up in a public Discord channel), **delete** it right away. A deleted link stops working immediately and no one new will be able to join the team through it.
</Warning>

## Join requests

When someone comes in through an invite link, their request appears at the top of the page in the **Join requests** section, highlighted in color so it catches your eye. For each request you can see who wants to join (name, email, photo) and which access level they'll receive.

<Steps>
  <Step title="Check who is asking for access">
    Make sure you recognize the person and that it really is someone you want to let into the panel.
  </Step>

  <Step title="Approve or reject">
    Click **Approve** to add the person to the team with the assigned permissions, or **reject** the request if it's a mistake or you don't know the person.
  </Step>
</Steps>

<Tip>
  Only approve requests you're expecting. If you see a request from someone you didn't invite, it's safer to reject it and find out where that person got the link.
</Tip>

## Team members list

At the bottom of the page there's a table with everyone who has access to the shop. For each of them you'll see:

* **User** — name, email address and profile photo (if they have one).
* **Access** — a short label describing the permission level, e.g. "Full access", "Sales and orders" or "View only".
* **Added** — the date the person joined the team.

If you don't have any collaborators yet, you'll see a message here encouraging you to invite your first person.

### Editing and revoking access

For each team member (except the owner) you have two options:

<Columns cols={2}>
  <Card title="Edit" icon="pencil">
    Opens the same permissions view as when inviting. You can change the template or individual boxes — for example promote someone from "View only" to "Sales and orders", or restrict their access the other way around.
  </Card>

  <Card title="Remove" icon="trash-2">
    Completely revokes the person's access to the shop. After confirmation, they'll no longer see the panel. This is the step to take when someone stops working with you.
  </Card>
</Columns>

<Note>
  Permission changes take effect right away. If you take away someone's access to an area, they'll stop seeing it the next time they open that section.
</Note>

## The shop owner

The person who created the shop is its **owner**. Next to their name in the list there's a clear **Owner** label. It's a special role:

<Columns cols={2}>
  <Card title="Always full access" icon="crown">
    The owner has all permissions automatically — they can't be limited or edited.
  </Card>

  <Card title="Can't be removed" icon="lock">
    The owner can't be removed from the team or have their access revoked. It's a safeguard that ensures the shop is never left without a host.
  </Card>
</Columns>

<Info>
  Only the owner and people with permission to manage the team see the buttons for inviting, approving requests and editing members. Someone with "View only" access will see the team list but won't be able to change anything in it.
</Info>

## The older way: inviting by email

Besides links, there's also an older way to invite people — by entering the person's **email address**. It works similarly, but it requires you to know the exact email tied to their account. Invite links are more convenient and more flexible, which is why we recommend using those.

## Security best practices

<Tip>
  * **Grant as little as needed** — if someone is only meant to handle orders, don't give them full access. Start with a narrower template and widen it only when it turns out to be necessary.
  * **Full access only for trusted people** — the "Full access" and "Administration" levels let people change settings and manage the team. Grant them only to people you trust as you trust yourself.
  * **Short, limited links** — for a single invitation, set the link to **1 person** and a short validity period. That lowers the chance of it falling into the wrong hands.
  * **Delete used and unneeded links** — once someone has joined, delete the link if you don't plan to invite more people on the same terms.
  * **Approve only people you know** — reject requests from people you don't recognize. Every approval is real access to your shop.
  * **Check the list from time to time** — look over the members list and revoke access from people who no longer work with you.
</Tip>

<Warning>
  Full access means someone can change shop settings, payment details, and even delete products. Before you grant it, make sure you fully trust the person. When in doubt, pick a narrower template — you can always widen permissions later.
</Warning>
