Staff Access settings reference.
Exact menu path: GymCore Admin > GymCore Settings > Staff Access<br>
Who can change it: an account with manage_options, normally a WordPress administrator.<br>
Visible action: Save Role Permissions stores all role checkboxes. Preset buttons only change the unsaved form until this action is selected.
The complete role-to-four-capability map is stored in gym_core_rbac_role_caps. Use the visible table and presets; do not edit the serialized option directly.
These controls grant four GymCore capabilities; they do not replace WordPress roles or every separate menu gate. Record each role’s current checkboxes before changing access, and verify with a non-administrator test account.
Field reference
Role preset
- Stored key/control:
preset selector - Purpose: Copies one of Gym Owner, Head Instructor, Staff Instructor, Front Desk into the four visible permissions.
- Type: Checkbox/select
- Default: Current role map
- Allowed values/range: Configured WordPress roles except subscriber/contributor
- Dependencies: WordPress role and saved RBAC map.
- Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities.
- When to change it: Change with a named user test account and least privilege.
- When to leave it alone: Do not assume this page controls every GymCore feature.
- Security/privacy: Access-control change; administrators always retain the four caps.
Manage Members
- Stored key/control:
gymcore_manage_members - Purpose: Controls surfaces that check this newer RBAC capability.
- Type: Checkbox/select
- Default: Role preset/default
- Allowed values/range: Configured WordPress roles except subscriber/contributor
- Dependencies: WordPress role and saved RBAC map.
- Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities.
- When to change it: Change with a named user test account and least privilege.
- When to leave it alone: Do not assume this page controls every GymCore feature.
- Security/privacy: Access-control change; administrators always retain the four caps.
Manage Billing
- Stored key/control:
gymcore_manage_billing - Purpose: Controls surfaces that check this newer RBAC capability.
- Type: Checkbox/select
- Default: Role preset/default
- Allowed values/range: Configured WordPress roles except subscriber/contributor
- Dependencies: WordPress role and saved RBAC map.
- Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities.
- When to change it: Change with a named user test account and least privilege.
- When to leave it alone: Do not assume this page controls every GymCore feature.
- Security/privacy: Access-control change; administrators always retain the four caps.
View Reports
- Stored key/control:
gymcore_view_reports - Purpose: Controls surfaces that check this newer RBAC capability.
- Type: Checkbox/select
- Default: Role preset/default
- Allowed values/range: Configured WordPress roles except subscriber/contributor
- Dependencies: WordPress role and saved RBAC map.
- Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities.
- When to change it: Change with a named user test account and least privilege.
- When to leave it alone: Do not assume this page controls every GymCore feature.
- Security/privacy: Access-control change; administrators always retain the four caps.
Manage Staff
- Stored key/control:
gymcore_manage_staff - Purpose: Controls surfaces that check this newer RBAC capability.
- Type: Checkbox/select
- Default: Role preset/default
- Allowed values/range: Configured WordPress roles except subscriber/contributor
- Dependencies: WordPress role and saved RBAC map.
- Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities.
- When to change it: Change with a named user test account and least privilege.
- When to leave it alone: Do not assume this page controls every GymCore feature.
- Security/privacy: Access-control change; administrators always retain the four caps.
Verify a change
- Record the current four checkboxes for the role, make the smallest edit, and select Save Role Permissions.
- Reload Staff Access and confirm the role’s saved checkboxes.
- Sign in with a non-administrator test account assigned only to that role and open the exact menu and action being delegated.
- Confirm the account can perform only the intended actions. If access is too broad or still blocked by a separate WordPress, WooCommerce, or legacy
gym_*gate, restore the prior checkboxes and select Save Role Permissions again.
Related guides
Verified against: checked-out GymCore and GymCore AI source plus the 2026-07-13 feature/settings inventory.
Need help?
Describe one problem and the installed versions. Never send passwords, license keys, API keys, payment details, or member records.