Roles and permissions
Your platform (or the merchant view) gives each of a merchant's users one of four roles. The roles are designed around who the user is: the people who run the business, and the people who look after its customers. Picture an insurance company with a call centre of two hundred agents. An agent needs to do everything a customer might ask for, but should not be able to change how the business's money flows or how its screens read. That line is the difference between Support and Admin.
Admin
Runs the business's setup in Shuttle. Everything Support can do, plus control of money flows (refunds, captures, voids, correcting a payment's status or the account it belongs to), payment processors and routing, the terms and wallet settings of the merchant account, screen wording, and team membership.
Support
Services customers. Creates and edits customer accounts and their saved payment methods, manages their contracts (amend, suspend, resume, end, change the payment method, take an owed payment), takes or saves a payment where the merchant allows phone payments, writes notes, and links duplicate accounts. Support cannot refund, capture or void, cannot change providers or routing, and cannot change screen wording.
Support (read-only)
Sees what Support sees, and changes nothing. For staff who answer questions but do not act on them.
Payment Links Only
Creates and manages payment links and can look up the accounts they were sent to. Nothing else. Only offered to merchants using payment links.
Alignment
The roles describe the intent. A few actions that belong to Support are still limited to Admin today; they are listed below under "Intended for Support" and are being brought into line over time, without you needing to change anything.
What each role can do
Admin and Support
Accounts (people and companies)
Saved payment methods
Notes and attachments
Intended for Support, Admin only today
Contracts (recurring and scheduled agreements)
- Amend a contract's terms
- Amend a scheduled contract's instalments
- Change the payment method on a contract
- Collect a contract's arrears now
- Move the next charge
- Reschedule the next payment
- Resume a contract
- Suspend a contract
- Terminate a contract
Charges (contract instalments)
Payments, refunds, captures and voids
Admin only
Payments, refunds, captures and voids
- Attribute an unattributed payment
- Capture an authorised payment
- Mark an unresolved payment approved or declined
- Refund a payment
- Undo an offline refund
- Void an authorisation
Branded localisation strings
Payment gateways (provider connections)
- Connect a payment processor
- Disconnect a provider
- Dismiss an archived provider's notice
- Reconnect a provider
- Restore an archived provider
- Update a provider's settings
Workflows (fraud screening connections)
Legal entity routes (which provider serves each payment method at checkout)
- Restrict a payment method by transaction amount
- Route a payment method to a provider
- Stop offering a payment method
Instance (merchant account settings: terms, wallets, merchant details)
- Accept Shuttle's terms for the instance
- Enable wallet support for the instance
- Set the merchant name and country
Performed by the customer, not by a role
Contracts (recurring and scheduled agreements)
Granular permissions
Clients that manage permissions directly can grant the underlying keys instead of a role. Each role is a fixed set:
- Admin: everything
- Support:
account,division_view,team_view,application_view,bolt_user_view,vendor_lead_view,payment_link - Support (read-only):
account_view,division_view,team_view,application_view,bolt_user_view,vendor_lead_view,payment_link - Payment Links Only:
payment_link,account_list
Every rules page names the roles that can perform its operation, then the keys the server checks.
Updated 10 minutes ago