Roles and permissions matrix

Roles and permissions matrix.

Status: source-reviewed Section: Reference

Search documentation

Type to search.

Use this page to answer “what can this staff member actually see or change?” Start with their job, test the exact task with their account, and grant the smallest access that works.

GymCore access is layered. A WordPress role is a bundle of permissions. Engineers call each individual permission a capability. The four Staff Access checkboxes, older GymCore permissions, WooCommerce permissions, and GymCore AI persona/tool gates can all differ.

Built-in role defaults

WordPress role Main legacy GymCore defaults Staff Access defaults
Administrator All GymCore capabilities through administrator sync Manage Members, Manage Billing, View Reports, Manage Staff
Shop Manager WooCommerce management; legacy access varies by synced capability All four Staff Access permissions
Head Coach (gym_head_coach) Promote/view ranks, check in/view attendance, achievements, SMS, curriculum, announcements, briefings, sales, AI; can edit users Manage Members, View Reports, Manage Staff
Coach (gym_coach) Promote/view ranks, check in/view attendance, achievements, briefings, AI View Reports
Finance (gym_finance) Finance AI, manage_woocommerce, order capabilities Manage Billing, View Reports
Sales (gym_sales) Sales processing, leads, SMS, AI Manage Members

Defaults can be changed, and plugin-version capability sync may update role capabilities. Test effective access on the installed site.

Staff Access controls

Path: GymCore Admin > GymCore Settings > Staff Access.

Visible permission Capability
Manage Members gymcore_manage_members
Manage Billing gymcore_manage_billing
View Reports gymcore_view_reports
Manage Staff gymcore_manage_staff

The page can apply Gym Owner, Head Instructor, Staff Instructor, or Front Desk presets. Administrators always receive all four newer capabilities. Subscriber and Contributor are excluded from the configurable role table.

Capabilities used outside Staff Access

Task/surface Capability examples
Promotions/ranks gym_promote_student, gym_view_ranks
Attendance/kiosk gym_check_in_member, gym_view_attendance
SMS gym_send_sms
Curriculum/announcements gym_manage_curriculum, gym_manage_announcements
Sales/leads gym_process_sale, gym_manage_leads
Finance gymcore_view_billing; legacy gym_view_finance and inherited manage_woocommerce remain compatibility sources
Core Settings gymcore_manage_settings; administrators with manage_options also qualify
GymCore AI hub gym_view_ai_hub; manage_woocommerce remains an overview compatibility source, and individual destinations have additional policies
AI administration manage_options

GymCore AI persona defaults

Persona Gate
Sales Agent gym_process_sale
Coaching Agent gym_view_briefing
My Coach read
Finance gym_view_finance
Admin Agent manage_options

An administrator can override persona gates to read, gym_view_briefing, gym_process_sale, gym_view_finance, gym_use_gandalf, edit_posts, or manage_options. Each tool also declares its own capability. Persona visibility never proves every tool will run.

Least-privilege test

  1. Create or use a non-production staff test account with the target role.
  2. Apply only the intended Staff Access preset/permissions.
  3. Sign in as that user in a separate private browser session.
  4. Test menu visibility, record lists, direct URLs, REST actions, AI persona visibility, and one safe read tool.
  5. Confirm blocked actions return a clear denial rather than exposing data.
  6. Remove the test account or credentials after acceptance.

Never share an administrator account to work around a missing menu. Record access changes and re-test after plugin updates.

Need help?

Describe one problem and the installed versions. Never send passwords, license keys, API keys, payment details, or member records.

Contact GymCore