FluxBilling
Settings

Staff & Permissions

Create staff accounts, understand the three roles and the Super Admin switch, grant permissions through departments, and manage two-factor and session security for your team.

Updated · 2026-09-03

What this article covers

Everyone who signs into the admin panel does so with an account that carries a Role. What that person can actually see and do is decided by three things working together: the role on their account, the departments they belong to, and the permissions those departments carry. This article explains how to create a staff account, what each role and each permission grants, how the module switches interact with permissions, and how two-factor and session security apply to staff.

Departments themselves — creating them, their icons, mailboxes and ticket routing — are covered in Departments. This article is about the people attached to them.

The three roles

Every account has exactly one role, set on the account’s own page under Clients.

Account roles
RoleWhat it does
ClientA customer. Signs into the client portal only. This is the role every self-registered account starts with.
StaffAn internal account that is not a customer and does not sign into the admin panel — the sign-in form answers “Access denied. Admin privileges required.” It exists so a person can be recorded internally, for example as the author of an admin signature or as a notification recipient, without being given the panel. Give it to nobody who needs to work in the panel.
AdminThe working staff role, and the only role that can sign into the admin panel. An Admin sees exactly the areas granted by the departments they belong to. Almost every colleague you add should be an Admin.

Note: An account whose role is Admin must have the status Active to sign in. If the account is suspended or inactive, sign-in is refused with a message telling the person to contact a super administrator. Set the account back to Active from its own page to restore access.

Super Admin

On top of the Admin role there is a single switch, Super Admin, described in the panel as Bypass all restrictions. A Super Admin sees every navigation entry, every settings tab and every page regardless of departments or permissions, and is the only role that can:

  • change any account’s role, or edit an Admin, Staff or Super Admin account at all;
  • open Settings → Departments and Settings → Admin Signatures;
  • create, edit and delete departments, assign people to them, and set department permissions;
  • reset the two-factor authentication of another Admin or Staff account;
  • export a plugin, and open the data-import tools for other billing or datacenter systems.

A Super Admin account cannot be deleted and cannot be selected for bulk deletion — its checkbox on the Clients list is greyed out. Keep at least two Super Admins so that one locked-out or departed person never leaves the panel unmanageable.

Create a staff account

There is no separate invitation flow for staff. You create the account and then promote it.

  1. Open Clients from the sidebar and click Add Client.
  2. Fill in First Name, Last Name and Email. Address and company fields are optional for a colleague.
  3. Set a Password of at least 8 characters, or click Generate to have one produced for you.
  4. Decide whether to leave Send welcome email with login credentials ticked. Tick it if you want the person to receive their sign-in details by email; untick it if you will hand the password over another way.
  5. Click Create Client.
  6. Open the new account from the Clients list, click Edit, change Role from Client to Admin, and save.
  7. With the role now Admin, a Departments panel appears in the right-hand column of the account page. Tick the departments this person belongs to. This is what grants their permissions.

You can also promote an existing account the same way — step 6 onwards. To find your existing staff quickly, use the Admins only filter button above the Clients table; accounts with the Admin role also carry an Admin badge in the list.

Tip: An Admin with no departments has no permissions at all and will see almost nothing beyond the dashboard. If a new colleague reports an empty panel, their department membership is the first thing to check.

How permissions are granted

Permissions are not set per person. They are set per department, and a person inherits the combined permissions of every department they belong to.

  • Open Settings → Departments, click Permissions on a department card, tick what that department may do, and click Save Permissions. Ticking a category header selects or clears the whole group at once; a partly-selected category shows a dash.
  • Click Admins on the same card (or use the Departments panel on the person’s account page) to decide who belongs to it.
  • A person in two departments gets the union of both permission sets — permissions add up, they never subtract.
  • Permissions from a department that has been switched to Inactive do not count. Deactivating a department silently removes its permissions from everyone in it.
  • Changes take effect on the person’s next request. Ask them to reload the panel if a newly granted area does not appear.

The permission catalogue

These are all the permissions on offer, grouped exactly as the Manage Permissions window groups them.

Settings, Clients and Invoices
PermissionWhat it grants
View SettingsOpens the Settings area, and with it the Blog, Campaigns and Newsletter sidebar entries. Departments and Admin Signatures stay hidden — those two tabs are Super Admin only.
Edit SettingsSaving changes in the settings area, including company details, billing rules and appearance.
View ClientsOpens the Clients list and client detail pages, the client statistics on the dashboard, and the Resellers area.
Edit ClientsCreating and editing customer accounts, suspending and reactivating them, resetting a customer password, managing their team members, notes, saved keys and currency, and the reseller administration screens.
Delete ClientsDeleting and terminating customer accounts, including bulk deletion.
Impersonate ClientsThe Login as Client button, which opens the client portal as that customer. It is a separate permission because it mints a live session for another account. Admin accounts can never be impersonated.
View InvoicesOpens Invoices and the Reports area.
Edit InvoicesCreating and editing invoices and proformas, marking documents paid, recording payments and refunds.
Delete InvoicesDeleting and cancelling billing documents.
Orders, Services and Products
PermissionWhat it grants
View OrdersOpens the Orders list and order detail pages.
Edit OrdersPlacing orders on a customer’s behalf, accepting, cancelling and reworking existing orders.
View ServicesOpens the Services list and service detail pages.
Edit ServicesChanging a service, running its power and management actions, suspending, unsuspending and terminating it.
View ProductsOpens the Products area, including categories and options.
Edit ProductsCreating and editing products, prices, options and order-page configuration.
Tickets
PermissionWhat it grants
View TicketsOpens the Tickets area. Only tickets in the departments the person belongs to are listed — a Super Admin sees every department.
Reply to TicketsPosting a reply or an internal note on a ticket.
Manage TicketsChanging status, priority, assignee and department, merging and closing tickets, and the ticket administration actions.
Infrastructure
PermissionWhat it grants
View LocationsOpens Locations, datacenters and racks. Only appears when the Locations module is enabled.
Edit LocationsCreating and editing locations, datacenters, racks and deployment templates.
View InventoryOpens Inventory and the bare-metal machine views. Only appears when the Inventory module is enabled.
Edit InventoryAdding and editing machines, and driving bare-metal power and provisioning actions.
View IPAMOpens IPAM and switch inventory. Only appears when the IPAM module is enabled.
Edit IPAMCreating and editing subnets, addresses and their allocations.
View VPS ClustersOpens the virtualisation module — clusters, nodes, pools, plans, instances and jobs. Only appears when the VPS module is enabled.
Edit VPS ClustersCreating and changing clusters, nodes, pools and plans, and running actions against virtual machines.
View Game NodesOpens the game-hosting tabs inside the same module. Only appears when the Game Hosting module is enabled.
Edit Game NodesCreating and changing game nodes, plans and servers, and running actions against them.

Note: The virtualisation and game-hosting sections share one sidebar entry. It appears if the person holds either View VPS Clusters or View Game Nodes, and it is hidden only when both modules are switched off. IP Transit and Monitoring have no permission of their own and are visible to Super Admins only.

Permissions and the module switches

Permissions and module switches are two independent gates, and a section appears only when both allow it.

  • Module switches are company-wide. They live under Settings → General in the feature list and decide whether a whole area exists in your installation at all — Resellers, Blog, Locations, Inventory, IPAM, Colocation, IP Transit, virtualisation, the task board, the customer API and Monitoring.
  • Permissions are per department and decide which of the remaining areas each person reaches.

Consequences worth knowing:

  • Granting View Inventory while the Inventory module is switched off changes nothing — the section stays hidden for everyone, Super Admins included.
  • Inventory, IPAM, Colocation, IP Transit and virtualisation additionally depend on Locations. Switching Locations off hides all of them, whatever their own switches say.
  • Switching a module back on immediately restores the section for everyone who already holds its permission. No permission changes are needed.

See Settings: General for the module list itself.

Two-factor authentication for staff

Two-factor authentication is configured company-wide under Settings → Security, not per person. Two methods can be offered:

  • Authenticator app — a six-digit code from an authenticator app or password manager.
  • Email verification — a six-digit code emailed at sign-in, with a code lifetime, an attempt limit and a resend cooldown you can set.

Two separate switches make it mandatory: Require 2FA for clients and Require 2FA for admins/staff. The second one covers every Admin and Staff account, including your own. Turning it on asks you to confirm in a window headed Require 2FA for all admins? before it is saved.

Several guards exist so the mandate can never lock your company out:

  • You cannot make two-factor mandatory unless at least one method is enabled. Otherwise saving fails with “Enable at least one 2FA method (email or authenticator app) before making it mandatory.”
  • If the emailed code is the only enabled method, the mandate is refused unless codes can actually be sent right now — outgoing email switched on, the event enabled and a template attached. The error explains which of those is missing.
  • You cannot make it mandatory for administrators unless you have already enrolled your own authenticator, or the authenticator method is enabled so everyone is walked through enrolment at their next sign-in. The refusal reads “Set up your own authenticator app first, or enable the authenticator method, before making 2FA mandatory for administrators.”

What staff see once it is mandatory

At the next sign-in, a person who has no second factor is taken through enrolment before they reach the panel: they scan a code with their authenticator app (or copy the key into a password manager), type the six digits back to confirm, and are then shown a one-time list of recovery codes. The codes are shown once and cannot be retrieved later, so they must be copied and stored before continuing. On later sign-ins the panel asks for the six-digit code; an authenticator user can switch the field to use a recovery code instead, and each recovery code works once.

Recovering a locked-out colleague

Open their account under Clients and click Reset 2FA. A badge next to the button reads 2FA on or 2FA off, and the button stays available in both states because it also clears a half-finished enrolment. The confirmation window explains that the reset removes the second factor and invalidates every recovery code they hold, leaving them signing in with their password alone until they enrol again, and offers an optional Reason that is written to the activity log.

Warning: Only a Super Admin can reset the two-factor of an Admin or Staff account; other admins see the button disabled with “Only a super admin can reset an admin or staff account.” You cannot reset your own from here. Verify who you are speaking to out of band — a callback or a channel that is not their email — before you reset anyone.

Session and sign-in security for staff

  • Your own sessions. Each staff member manages their own sign-ins under Account → Sessions, which lists the device, address and age of each session, marks the current one, and offers Revoke per session and Revoke All. Revoking signs that device out on its next request. See Account.
  • Password changes end every session. When anyone changes their own password, all of their sessions are ended, including the one they are using, and they are asked to sign in again.
  • Resetting someone else’s password. Use Reset Password on their account page. Only a Super Admin may do this to an Admin or Staff account.
  • Sign-in protection. The sign-in form can be protected by the challenge configured under Settings → Security, which can be applied to login, registration, or both. Address-level blocking is configured under Settings: IP Ban, and the trusted-proxy fields on the same Security page decide which address is recorded when the panel sits behind a proxy or CDN — getting those wrong makes every entry in the logs show the proxy’s address instead of the visitor’s.
  • Audit trail. Role changes, department changes, password and two-factor resets, suspensions and deletions are all recorded with the acting person and the target. See Activity Log. Each customer account also carries its own sign-in history on its detail page.

Common problems

What to check when access is wrong
SymptomWhat to check
Sign-in is refused with “Access denied. Admin privileges required.”The account’s role is Client or Staff. Only Admin opens the admin panel.
A colleague signs in but the sidebar is nearly emptyThey are an Admin with no departments, or with departments that carry no permissions.
They see the section but every action is refusedThey hold the view permission but not the matching edit permission.
A whole area is missing for everyone, including Super AdminsIts module is switched off under Settings → General, or its parent Locations module is.
They cannot see any ticketsTickets are filtered by department. Add them to the department that owns those tickets.
Sign-in is refused with a message about the account not being activeThe Admin account’s status is suspended or inactive. Set it back to Active.
Settings tabs are missing for an admin who has View SettingsDepartments and Admin Signatures are Super Admin only, and some tabs belong to modules that are switched off.

Related

Settings: Departments, Settings: Security, Settings: General, Clients, Client Details, Admin Signatures, Activity Log, Account.