Roles and permissions

Your platform (or the merchant view) gives each of a merchant's users one of four roles. The roles are designed around who the user is: the people who run the business, and the people who look after its customers. Picture an insurance company with a call centre of two hundred agents. An agent needs to do everything a customer might ask for, but should not be able to change how the business's money flows or how its screens read. That line is the difference between Support and Admin.

Admin

Runs the business's setup in Shuttle. Everything Support can do, plus control of money flows (refunds, captures, voids, correcting a payment's status or the account it belongs to), payment processors and routing, the terms and wallet settings of the merchant account, screen wording, and team membership.

Support

Services customers. Creates and edits customer accounts and their saved payment methods, manages their contracts (amend, suspend, resume, end, change the payment method, take an owed payment), takes or saves a payment where the merchant allows phone payments, writes notes, and links duplicate accounts. Support cannot refund, capture or void, cannot change providers or routing, and cannot change screen wording.

Support (read-only)

Sees what Support sees, and changes nothing. For staff who answer questions but do not act on them.

Payment Links Only

Creates and manages payment links and can look up the accounts they were sent to. Nothing else. Only offered to merchants using payment links.

Alignment

The roles describe the intent. A few actions that belong to Support are still limited to Admin today; they are listed below under "Intended for Support" and are being brought into line over time, without you needing to change anything.

What each role can do

Admin and Support

Accounts (people and companies)

Saved payment methods

Notes and attachments

Intended for Support, Admin only today

Contracts (recurring and scheduled agreements)

Charges (contract instalments)

Payments, refunds, captures and voids

Admin only

Payments, refunds, captures and voids

Branded localisation strings

Payment gateways (provider connections)

Workflows (fraud screening connections)

Legal entity routes (which provider serves each payment method at checkout)

Instance (merchant account settings: terms, wallets, merchant details)

Performed by the customer, not by a role

Contracts (recurring and scheduled agreements)

Granular permissions

Clients that manage permissions directly can grant the underlying keys instead of a role. Each role is a fixed set:

  • Admin: everything
  • Support: account, division_view, team_view, application_view, bolt_user_view, vendor_lead_view, payment_link
  • Support (read-only): account_view, division_view, team_view, application_view, bolt_user_view, vendor_lead_view, payment_link
  • Payment Links Only: payment_link, account_list

Every rules page names the roles that can perform its operation, then the keys the server checks.


Did this page help you?