Admin Tools
User roster management, role permissions, and roster integrations
Admin tools in Danvas handle user accounts, role permissions, location access, and employee sync. Three roles are available: admin (full access), manager (location-scoped operational oversight), and member (end-user staff). Only users with the admin role can access the full admin surface; location managers get a location-scoped subset.
User Management
Admins can view, invite, update, deactivate/reactivate, and unlink team members from Admin → Users. Managers can view and manage only member accounts within their location scope: they may invite member accounts, update profile/access fields within that scope, manage pending invitations, and deactivate/reactivate eligible accounts. Managers cannot administer admin targets or assign the admin role, unlink Employee records, impersonate users, or use admin-only security, activity/audit, and compensation operations; the server enforces these boundaries.
User List
Navigate to Admin → Users to see all members in your scope:
- Name: The user's display name and profile picture.
- Email: The user's registered email address.
- Role: The user's role permission (
admin,manager, ormember). - Locations: The locations the user is authorized to access (filtered to a manager's scope if you are a manager).
- Status: The account's lifecycle state — see below.
A search box at the top filters the roster by name, email, or location. Click a user's row to open the account drawer: Profile, Access, Employee, Activity, and Audit tabs, plus a danger zone. Which tabs you see depends on what you are allowed to do with that account, so a manager sees fewer than an admin.
Account Status
| Status | Meaning |
|---|---|
| Invited | You have staged their role and locations; they have not signed in yet. |
| Active | They can sign in and use Danvas. |
| Deactivated | Sign-in is blocked. Their role and locations are kept, so reactivating restores access unchanged. |
| Provider deleted | Their sign-in no longer exists at the identity provider, though their history here is preserved. Reactivating will not bring it back — the identity has to be reconciled first. |
| Reconciliation required | The account and the identity provider disagree. It cannot sign in until that is resolved. |
A non-active account explains its own state at the top of the drawer, including what it rules out — password recovery and impersonation both refuse a provider-deleted account, for example.
Roles and Permissions
Danvas uses role-based access control (RBAC) to enforce security boundaries.
The role hierarchy is admin > manager > member. Managers are additionally horizontally restricted by their assigned locationIds — server actions enforce that scope, not the navigation.
interface User {
id: string;
clerkId: string; // Clerk auth ID
email: string;
firstName: string;
lastName: string;
imageUrl?: string;
teamId: string; // Organization scope
role: 'admin' | 'manager' | 'member';
locationIds: string[]; // Assigned locations
status: 'invited' | 'active' | 'deactivated'
| 'provider_deleted' | 'reconciliation_required';
isActive: boolean; // Compatibility projection of `status`, not a second switch
createdAt: Date;
updatedAt: Date;
}status is the account's real state; isActive only ever mirrors it (true
exactly when status is active). Only active grants access.
Admin
- Full Access: Access to all restaurant locations, billing details, and platform settings.
- Roster Control: Can invite, deactivate, reactivate, or change the role of any user in the system.
- Auditing: Can view organization-wide analytics, report compliance, and the full system audit logs.
- Administrative Utilities: Can trigger system-wide push alerts and manage custom integrations such as Slack routes. Coupon campaigns use the shared manager/admin workspace below.
Manager
- Location-Scoped Access: Can only see data and users for restaurant locations assigned to them.
- Staff Control: Can edit, deactivate, and reactivate standard staff (Members) who share at least one location with them.
- Restricted Access: Managers cannot view, edit, or modify other Managers or Admins. They also cannot promote any user to the "Manager" or "Admin" role.
- Auditing: Can view reports, daily lineup cards, compliance trackers, and analytics for their locations.
- Operational Oversight: Can view the schedule synced from 7shifts, review shift reports, and acknowledge incidents. Schedule edits and publication occur in 7shifts, not in Danvas.
Coupon campaign scope
The general role summary does not grant unrestricted Coupon authority. In
/coupons, unrestricted administrators cover their team, while location-scoped
administrators and managers follow authorized restaurant scope. A campaign can
be edited/published only when every existing and requested restaurant is in scope;
partial visibility remains read-only. Members have no campaign-management access,
although the separate authenticated legacy staff-confirmation route can admit an
authorized staff member. Navigation and a role label do not bypass server checks.
See Coupons for campaign operation and Contacts for masked reads, authorized reveal/export, and the separately recorded Contact-profile reveal scope limitation.
Member (Staff)
- Staff Access: File shift reports, complete checklists, view scheduled shifts, and check the daily lineup card.
- No Admin Surface: Members have no access to admin tools or location configurations.
- Interactions: Can participate in chat, receive notifications, and acknowledge line-up cards.
Navigation
The sidebar is organized into five manager-facing sections plus Administration (admin-only):
| Section | Roles | Contents |
|---|---|---|
| Today | All | Shift Console (dashboard), Tasks, Schedule, Calendar, Operations Feed (inbox), Report Incident, Forms |
| Service Day | Manager/Admin | Setup (Service Day composer), Line-Up, Checklist Setup |
| Review | Manager/Admin | Shift Reports (submit, manager reports, activity, workspace), Incidents, Announcements, Task History (compliance) |
| Team | Manager/Admin | Users, Employees, Invite Member |
| Insights | Manager/Admin | Analytics, Optimization |
| Administration | Admin only | Locations & Scheduling, Platform Operations, Analytics Settings, Marketing, Platform (Slack, Whistleblower, Audit Log) |
Navigation visibility is controlled by getVisibleSections which enforces the same server-side guards as the page actions — if you can see it, you can open it.
User Actions
Invite User
Admins and managers invite people through a four-step dialog. Click Invite User at the top of the Users table.
- Person. Say who this is before anything else: an existing employee already on the roster, or a non-employee account (an owner, a contractor, an integration user). Choosing "existing employee" opens a search over roster entries that do not yet have an account — pick one and their name, email, phone, and locations fill in for you. This choice is what decides whether the account links to an Employee record; Danvas does not guess it from the email you type.
- Identity. Confirm first name, last name, email, and phone (optional). The email is where the invitation goes and becomes the sign-in address.
- Access. Select the role permission (
admin,manager, ormember) and the primary location and authorized locations. A manager can invite only thememberrole and can assign only locations in their own scope; admins can choose any supported role and team location. - Review. Danvas states what Send will actually do — send a new invitation, resend an existing one, or nothing, because the address is already an active account, belongs to a different sign-in, or the roster entry is already linked. In those last cases Send is disabled rather than left to fail, and the review says which one applies.
Click Send and the invitee receives an email with a sign-up link.
The account is staged with the role and locations you chose and shows as Invited until they accept — signing in is what promotes it, and the role you set is preserved exactly.
If a submission is refused, the dialog keeps everything you entered — the person, the access set, and the reason — so you can correct one field instead of starting over.
Resend or Withdraw an Invitation
Open the account drawer for an Invited account. An Invitation section sits above the danger zone with two actions — this is the only section a still-unclaimed account shows there, since impersonation needs an active sign-in and deactivate/reactivate does not apply to an account nobody has signed into yet.
- Resend sends a new link to the same email with the role and locations
you staged unchanged. It reissues the invitation rather than creating a
second account, logging
user.invitation_resent. - Withdraw cancels the link and frees the email to be invited again. Any roster entry the invitation was linked to keeps its record — withdrawing only removes the outstanding sign-up, not the person's history.
Both actions refuse once the invitation has been accepted — at that point it is a real account, and resending would mail a dead link while withdrawing would delete someone's access under a cleanup action's name.
Update Role and Locations
Open the Access tab in the account drawer. Role, accessible locations, and primary location are edited together and applied by a single Save — there is no autosave, so nothing is written until you commit, and the whole change lands or none of it does.
- Admins can change any user's role or assigned locations.
- Managers can only change roles for Members (cannot promote to manager/admin) and can only assign locations that they themselves manage. A location outside your scope stays assigned to the user and is shown greyed out — you cannot remove it, and it will not silently disappear.
If the save is refused, the reason appears as a notification and your edits stay on screen, so you can correct them rather than retype them.
[!WARNING] Admin Guard: The system will block you from deactivating or demoting the last active Admin. You must promote another user to Admin first before deactivating the original account.
Deactivate / Reactivate User
Deactivating a user account revokes their login access immediately. Their historical reports, audit logs, and shift histories are preserved, as are their role and locations.
- Open the account drawer and use the danger zone at the bottom, or the row menu in the table.
- Click Deactivate User; to restore access, click Reactivate User.
Reactivation only applies to accounts you deactivated. It cannot recover an account whose provider identity was deleted — those need identity reconciliation, and the drawer says so.
Toast Employee Sync
On Admin → Employees, select Sync Toast Roster to queue a team-wide Toast employee synchronization. The request runs through Dagster; the page shows whether it is queued, running, completed, or failed. When it completes, the employee list refreshes. The button syncs Toast roster data only. It does not create Danvas user accounts or send invitations.
7shifts employee observations are ingested by the platform-owned Dagster workflow. 7shifts schedule synchronization remains a separate TypeScript/Vercel writer; it is not controlled by the Toast roster button.
Create or invite Danvas user accounts separately through the user-management flow. Roster membership is not login access, and matching email alone never grants access. Linking an existing account to an employee is also a separate identity action.
Unlink Employee
From a user's details sheet, use Unlink Employee to sever the link to workspace analytics mappings. This does not deactivate the account; deactivate the user separately if sign-in access must be blocked.
Role Mappings & Overrides
External tools (like Toast POS or 7shifts) use varying names for job roles. Danvas resolves these to internal canonical roles (e.g., MOD, Server, BOH/Kitchen) to drive dashboard styling, compliance seeding, and shift tasks.
If an external role is incorrectly resolved, Admins can set team-scoped custom overrides:
- Navigate to Administration → Role Mappings (
/admin/role-mappings). - Search and filter by role name or location.
- Select an override for the role (e.g., mapping a custom job name directly to a canonical job).
- To remove an override and return to the default automatic mapping, click Reset Override.
Overrides take immediate precedence in scheduling lookups. These actions write to the audit trail log.
Audit Logging
All administrative actions are logged to ensure system accountability:
user.invited: A new user was invited via email.user.invitation_resent: An invitation email was resent to a pending user.user.created: A user account was created directly.user.deactivated: A user account was suspended.user.reactivated: A deactivated user account was restored.user.role_changed: A user's access was changed. A save from the Access tab logs the previous and new role, accessible locations, and primary location as one entry.user.locations_updated: A user's location list was modified on its own.user.profile_updated: A user's profile image or fields were updated.user.employee_mapped: A user was linked to a Toast/7shifts employee record.user.employee_unlinked: A user was unlinked from their Toast/7shifts record.user.impersonated: An admin logged in as this user.seven_shifts_role_map.canonical_override_updated: A 7shifts role override was added or modified.seven_shifts_role_map.canonical_override_reset: A 7shifts role override was removed.
Admins can search and filter the system-wide log at Admin → Audit Log. A user's individual audit history can be exported as a CSV from the Audit tab of their account drawer.