Roles and permissions matrix.
Use this page to answer “what can this staff member actually see or change?” Start with their job, test the exact task with their account, and grant the smallest access that works.
GymCore access is layered. A WordPress role is a bundle of permissions. Engineers call each individual permission a capability. The four Staff Access checkboxes, older GymCore permissions, WooCommerce permissions, and GymCore AI persona/tool gates can all differ.
Built-in role defaults
| WordPress role | Main legacy GymCore defaults | Staff Access defaults |
|---|---|---|
| Administrator | All GymCore capabilities through administrator sync | Manage Members, Manage Billing, View Reports, Manage Staff |
| Shop Manager | WooCommerce management; legacy access varies by synced capability | All four Staff Access permissions |
Head Coach (gym_head_coach) |
Promote/view ranks, check in/view attendance, achievements, SMS, curriculum, announcements, briefings, sales, AI; can edit users | Manage Members, View Reports, Manage Staff |
Coach (gym_coach) |
Promote/view ranks, check in/view attendance, achievements, briefings, AI | View Reports |
Finance (gym_finance) |
Finance AI, manage_woocommerce, order capabilities |
Manage Billing, View Reports |
Sales (gym_sales) |
Sales processing, leads, SMS, AI | Manage Members |
Defaults can be changed, and plugin-version capability sync may update role capabilities. Test effective access on the installed site.
Staff Access controls
Path: GymCore Admin > GymCore Settings > Staff Access.
| Visible permission | Capability |
|---|---|
| Manage Members | gymcore_manage_members |
| Manage Billing | gymcore_manage_billing |
| View Reports | gymcore_view_reports |
| Manage Staff | gymcore_manage_staff |
The page can apply Gym Owner, Head Instructor, Staff Instructor, or Front Desk presets. Administrators always receive all four newer capabilities. Subscriber and Contributor are excluded from the configurable role table.
Capabilities used outside Staff Access
| Task/surface | Capability examples |
|---|---|
| Promotions/ranks | gym_promote_student, gym_view_ranks |
| Attendance/kiosk | gym_check_in_member, gym_view_attendance |
| SMS | gym_send_sms |
| Curriculum/announcements | gym_manage_curriculum, gym_manage_announcements |
| Sales/leads | gym_process_sale, gym_manage_leads |
| Finance | gymcore_view_billing; legacy gym_view_finance and inherited manage_woocommerce remain compatibility sources |
| Core Settings | gymcore_manage_settings; administrators with manage_options also qualify |
| GymCore AI hub | gym_view_ai_hub; manage_woocommerce remains an overview compatibility source, and individual destinations have additional policies |
| AI administration | manage_options |
GymCore AI persona defaults
| Persona | Gate |
|---|---|
| Sales Agent | gym_process_sale |
| Coaching Agent | gym_view_briefing |
| My Coach | read |
| Finance | gym_view_finance |
| Admin Agent | manage_options |
An administrator can override persona gates to read, gym_view_briefing, gym_process_sale, gym_view_finance, gym_use_gandalf, edit_posts, or manage_options. Each tool also declares its own capability. Persona visibility never proves every tool will run.
Least-privilege test
- Create or use a non-production staff test account with the target role.
- Apply only the intended Staff Access preset/permissions.
- Sign in as that user in a separate private browser session.
- Test menu visibility, record lists, direct URLs, REST actions, AI persona visibility, and one safe read tool.
- Confirm blocked actions return a clear denial rather than exposing data.
- Remove the test account or credentials after acceptance.
Never share an administrator account to work around a missing menu. Record access changes and re-test after plugin updates.
Related guides
Need help?
Describe one problem and the installed versions. Never send passwords, license keys, API keys, payment details, or member records.