Horbit Docs

Team

Administrators, roles and the permissions that decide who can do what.

The team is the set of people who administer the workspace. Each holds an access into the tenant, and that access carries a role, which is a named bundle of permissions.

Roles and permissions
Roles are edited per tenant; each is a set of permissions.

Permissions

PermissionGrants
member:manageThe member register
affiliation:manageInstitutions
communication:manageCampaigns and events
publication:manage, publication:syncPublications and their syncing
contact:manageSegments and contact requests
certificate:manageTemplates and issuance
team-member:create, team-member:updateInviting and editing administrators
role-permission:create, role-permission:updateEditing roles themselves
tenant:manageTenant identity, branding, profile
smtp:manage, api-key:manage, wallet:manageSending, integrations, billing
stats:viewDashboard figures
settings:updateConfiguration

Events and campaigns deliberately share communication:manage rather than having separate permissions.

Modules and permissions are different gates

Turning a module off strips its permissions from the tenant's roles and blocks its endpoints. Turning it back on does not restore anyone's access automatically — roles are edited deliberately. A permission survives while any still-enabled module needs it, so switching off Events does not remove communication:manage from someone who also runs campaigns.

Team profiles

Separate from administrators, team profiles are the public-facing people page: the board, the secretariat, the organising committee. They are content, not access — a profile grants nothing.

Team profiles
Public profiles, independent of who can sign in.

Use cases

A volunteer who only sends email

Create a role with communication:manage alone. They see Campaigns and Events and nothing else — not the register, not billing.

Handing over the treasurer's job

Grant wallet:manage to the incoming treasurer, remove it from the outgoing one. Access is per person, so nothing is shared and nothing needs a password change.

On this page