Assign and verify staff access.
Purpose
Give each staff member the smallest role and GymCore permission set needed for their work, then verify both allowed and forbidden screens with that role.
Audience and access
For: Gym owners and WordPress administrators responsible for staff access<br>
Access needed: gymcore_manage_staff, or the administrator fallback manage_options, to view or save GymCore Settings > Staff Access<br>
Open: GymCore Admin > GymCore Settings > Staff Access
Before you start
- Use an individual WordPress account for each staff member; never share an owner account.
- List the exact tasks, records, locations, and end date the person needs.
- Keep a separate administrator available for recovery and prepare a non-production test account for the target role.
- Review the complete permissions reference because Staff Access controls only four newer permissions, not every GymCore, WordPress, or WooCommerce check.
Exact steps
Safe stop: Configure and test the target role on staging first; stop before applying Save Role Permissions on production until the approved task list and recovery administrator are confirmed.
-
Open Users > All Users, edit the staff account, and choose the closest role: Administrator, Shop manager, Head Coach, Coach, Finance Admin, or Sales. Save the user.
Expected: The user profile reloads with the selected role. Do not choose Administrator solely to make a missing GymCore menu appear.
-
Open GymCore Admin > GymCore Settings > Staff Access.
Expected: A matrix lists WordPress roles against Manage Members, Manage Billing, View Reports, and Manage Staff. Administrator checkboxes are selected and disabled because administrators always receive all four.
-
For each role, select only the four permissions required by the approved task list. Use the preset buttons only when the complete preset matches the role; the current preset control asks for the role slug.
Expected: The matrix reflects the intended grants before anything is saved. Presets change the visible checkboxes only until the form is submitted.
-
Select Save Role Permissions.
Expected: WordPress reports Role permissions saved. The saved map applies to every user with each edited role.
-
Sign in to staging with the target test account and open every required menu and action. Then try at least one member, billing, report, staff, credential, and communication screen that should be forbidden.
Expected: Required work is available and forbidden work is denied. A hidden menu alone is not proof of denial; test the action or direct page with the least-privilege account.
-
Compare any unexpected access with the complete permissions reference and the screen’s source-backed capability.
Expected: Legacy
gym_*,manage_options,manage_woocommerce,edit_posts,edit_users, and other checks explain access that the four-column matrix does not control. -
Reopen Staff Access with the administrator and compare the saved matrix with the approved access record.
Expected: The source configuration matches the approval, the test account has the intended role, and no extra capability was added merely to bypass a product defect.
Expected result
Each staff account has one appropriate role, the four Staff Access permissions match the approved task list, and staging verifies both required and forbidden behavior.
Defaults and limits
| Role | Factory default in the four-column matrix |
|---|---|
| Administrator | All four; cannot be cleared on this screen |
| Shop manager | Manage Members, Manage Billing, View Reports, Manage Staff |
| Head Coach | Manage Members, View Reports, Manage Staff |
| Coach | View Reports |
| Finance Admin | Manage Billing, View Reports |
| Sales | Manage Members |
The four permissions are gymcore_manage_members, gymcore_manage_billing, gymcore_view_reports, and gymcore_manage_staff. These technical names are useful for an access review, but owners should decide access by job task and data sensitivity first.
Side effects and privacy
Saving a role row affects every account assigned to that role. Access can expose member identities, attendance, billing, reports, staff records, credentials, or outbound communication. Role changes take effect on capability checks immediately, although a user may need to reload or sign in again to see menu changes.
Recover by symptom
Staff Access is missing
The Settings destination requires gymcore_manage_staff, or the administrator fallback manage_options. Use an approved access owner; do not grant broad access to the affected staff member just so they can edit their own permissions.
A required menu is still missing after save
Look up that menu/action’s actual capability. The screen may use a legacy gym_*, WordPress, or WooCommerce permission outside the four-column matrix. Grant only the exact approved capability through a supported role path.
A staff member can see too much
Remove the unnecessary grant, select Save Role Permissions, end active sessions if the risk warrants it, and retest the direct page/action. Review all users assigned to the changed role.
A custom GymCore role disappears after deactivation
Current deactivation removes Head Coach, Coach, Finance Admin, and Sales roles. Reactivate GymCore with an administrator, then verify role assignments and permissions before staff resume work.
A preset changes the wrong role
Do not save. Restore the intended checkboxes manually or reload the page, then apply the preset only after entering the exact role slug shown in the permissions reference.
Related guides
- Roles permissions matrix
- Review AI action history
- Choose AI personas and access
- Collect diagnostics and contact support
Source review: checked-out gym-core roles, capability, and settings PHP on 2026-07-13. Role behavior still requires installed-version testing with non-administrator accounts.
Need help?
Describe one problem and the installed versions. Never send passwords, license keys, API keys, payment details, or member records.