Users, Roles & Access
Manage users and roles, restrict pages, blocks and admin sections, and choose where users land after signing in.
Control who can sign in, what they can see on the site, and which parts of the admin they can use — all with roles.
How roles work
A role is a simple label, such as editor or member. Pages, blocks, admin
sections and data sources can each require roles, and a user needs any one
of the required roles to get access.
Roles don't inherit from each other: holding admin doesn't automatically
grant editor. Give a user every role they need. The built-in admin
account holds all of the default roles.
The default roles are admin, editor, author, moderator and user.
Add your own under Admin → Roles — for example reviewer or
premium-member. A role that's still assigned to someone can't be deleted.
Manage users
Go to Admin → Users.
- New User — enter a username, email, password and roles. Passwords need at least 8 characters, with an uppercase letter, a lowercase letter and a digit.
- Edit a user to change their roles or status. Set Inactive to block sign-in without deleting the account.
- Reset password — type a new one. The user is signed out of all their sessions.
Users can change their own password from their account page.
Restrict a page
In the page's Edit settings, choose a Required role — or use the Access column in the Pages list. Only users with that role can view the page.
Restrict a single block
Select a block in the builder and open Access in its properties. On public pages, the block is shown only to users with the selected role.
Example: a pricing page that everyone can see, with a "Download the
enterprise guide" block visible only to users with the customer role.
Restrict parts of the admin
Under Admin → Pages → Admin Pages, each admin section (Pages, Users, Settings, …) has a required role. Changing it hides the section's menu link and blocks its API for everyone without that role. Only global admins can change these.
Example: give your content team the editor role and set Pages and
Posts to require editor, while Users and Settings stay
admin-only.
Where users land after signing in
Admin → Settings → Login Redirects decides where each user goes after signing in. Rules are checked in order, and the first rule whose role the user holds wins; otherwise the Default path is used. A bookmarked admin link still takes priority.
Example: send admin and editor to /admin, and everyone else to
/account.