Staff Access settings reference

Staff Access settings reference.

Status: source-reviewed Section: Settings Reference

Search documentation

Type to search.

Exact menu path: GymCore Admin > GymCore Settings > Staff Access<br> Who can change it: an account with manage_options, normally a WordPress administrator.<br> Visible action: Save Role Permissions stores all role checkboxes. Preset buttons only change the unsaved form until this action is selected.

The complete role-to-four-capability map is stored in gym_core_rbac_role_caps. Use the visible table and presets; do not edit the serialized option directly.

These controls grant four GymCore capabilities; they do not replace WordPress roles or every separate menu gate. Record each role’s current checkboxes before changing access, and verify with a non-administrator test account.

Field reference

Role preset

  • Stored key/control: preset selector
  • Purpose: Copies one of Gym Owner, Head Instructor, Staff Instructor, Front Desk into the four visible permissions.
  • Type: Checkbox/select
  • Default: Current role map
  • Allowed values/range: Configured WordPress roles except subscriber/contributor
  • Dependencies: WordPress role and saved RBAC map.
  • Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities.
  • When to change it: Change with a named user test account and least privilege.
  • When to leave it alone: Do not assume this page controls every GymCore feature.
  • Security/privacy: Access-control change; administrators always retain the four caps.

Manage Members

  • Stored key/control: gymcore_manage_members
  • Purpose: Controls surfaces that check this newer RBAC capability.
  • Type: Checkbox/select
  • Default: Role preset/default
  • Allowed values/range: Configured WordPress roles except subscriber/contributor
  • Dependencies: WordPress role and saved RBAC map.
  • Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities.
  • When to change it: Change with a named user test account and least privilege.
  • When to leave it alone: Do not assume this page controls every GymCore feature.
  • Security/privacy: Access-control change; administrators always retain the four caps.

Manage Billing

  • Stored key/control: gymcore_manage_billing
  • Purpose: Controls surfaces that check this newer RBAC capability.
  • Type: Checkbox/select
  • Default: Role preset/default
  • Allowed values/range: Configured WordPress roles except subscriber/contributor
  • Dependencies: WordPress role and saved RBAC map.
  • Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities.
  • When to change it: Change with a named user test account and least privilege.
  • When to leave it alone: Do not assume this page controls every GymCore feature.
  • Security/privacy: Access-control change; administrators always retain the four caps.

View Reports

  • Stored key/control: gymcore_view_reports
  • Purpose: Controls surfaces that check this newer RBAC capability.
  • Type: Checkbox/select
  • Default: Role preset/default
  • Allowed values/range: Configured WordPress roles except subscriber/contributor
  • Dependencies: WordPress role and saved RBAC map.
  • Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities.
  • When to change it: Change with a named user test account and least privilege.
  • When to leave it alone: Do not assume this page controls every GymCore feature.
  • Security/privacy: Access-control change; administrators always retain the four caps.

Manage Staff

  • Stored key/control: gymcore_manage_staff
  • Purpose: Controls surfaces that check this newer RBAC capability.
  • Type: Checkbox/select
  • Default: Role preset/default
  • Allowed values/range: Configured WordPress roles except subscriber/contributor
  • Dependencies: WordPress role and saved RBAC map.
  • Side effects: Changes only four gymcore_* capabilities; many screens still use legacy gym_* or WordPress/WooCommerce capabilities.
  • When to change it: Change with a named user test account and least privilege.
  • When to leave it alone: Do not assume this page controls every GymCore feature.
  • Security/privacy: Access-control change; administrators always retain the four caps.

Verify a change

  1. Record the current four checkboxes for the role, make the smallest edit, and select Save Role Permissions.
  2. Reload Staff Access and confirm the role’s saved checkboxes.
  3. Sign in with a non-administrator test account assigned only to that role and open the exact menu and action being delegated.
  4. Confirm the account can perform only the intended actions. If access is too broad or still blocked by a separate WordPress, WooCommerce, or legacy gym_* gate, restore the prior checkboxes and select Save Role Permissions again.

Verified against: checked-out GymCore and GymCore AI source plus the 2026-07-13 feature/settings inventory.

Need help?

Describe one problem and the installed versions. Never send passwords, license keys, API keys, payment details, or member records.

Contact GymCore