Users, administrators and permissions
The difference between customers and administrators, linked accounts, messages, subscribers, and safe permission assignment.
On this page
Nodera distinguishes between a customer profile on the public website and an administrator account. One person can have both, but each serves a different purpose. This separation protects customers and web content from unwanted rights allocation.
Two types of accounts
| Account | Used for | Where to manage it |
|---|---|---|
| Customer Profile | web login, profile, orders, licenses and customer service | Users |
| Administrator | access to administration and work in enabled modules | owner section for administrators or Authorizations |
The customer's login via Google, Discord or Steam does not automatically make them an administrator.
What you see with the user
In the user list you can search for a profile and check basic information, email verification and available links. Provider icons help to distinguish through which services the user can log in. Display private data only to the extent necessary to fulfill the request.
Linked identities and merging profiles
Google, Discord and Steam are login methods attached to the profile. The link must not be silently transferred to another person. If the customer ended up with two profiles, they must first prove access to both and the administrator should use the supported merge procedure. Manual rewriting of external identifiers will often make the problem worse.
Administrator permissions
In Permissions, assign only the modules and actions that a person needs for their work. The right to read the list is not the same as the right to change, publish or take a sensitive action.
- Select the correct administrator account.
- Specify the sites and modules for which they are responsible.
- Enable the smallest range needed.
- Have the administrator log out and log in again if the menu has not been restored.
- Remove unnecessary rights after changing the work role.
News and subscribers
The User messages screen is used for communication determined by the customer profile. The Subscribers module manages the list of subscriptions. It's a different audience: a customer account doesn't have to be a subscriber, and a subscriber doesn't have to have a customer account.
The admin list should not display the content of private messages as a substitute for an approved communication process.
Profile of the administrator
In My profile, the administrator checks his own data and supported social connections. Changing the profile is not intended to replace the owner of a foreign identity or to bypass access control.
When the user does not have access
- Verify that they are using the correct Google, Discord or Steam account.
- Distinguish if he needs customer service or administration.
- Check email, license and authorization status.
- If profiles are duplicated, do not delete anything; continue through a ticket and safe merge.