04·Hands-on·12 min

Users and roles

The Users section is where you decide who gets in and what they are once inside.

Roles

A role is a label on a user: customer, staff, admin. Define them on the Roles tab, mark one as the Default (assigned automatically on signup), and press Save Roles. Your app reads a user's role from their session, so pages can show the staff view to staff and nothing else to anyone else.

Roles answer "who is this person." What a paying customer can access is a separate question, answered by plans and features under Payments.

Signup rules

On Login & Signup, the Signup Rules tab controls the door:

  • Signups Open: turn off for invite-only apps.
  • Require Email Verification: no session until the address is confirmed.
  • Domain Allowlist: only company addresses, for example.
  • Blocklist: reject specific addresses or domains.

The Login Security tab sets session length (default 1 hour) and remember-me (default 30 days).

People

The People tab lists every user with their role, lets you invite someone with a preassigned role, and lets you disable an account.

Where DontCode fits

Roles, signup rules, verification emails, and sessions are enforced by the platform's auth service, not by code in your app. Change a rule and it applies to every login method at once, without a rebuild.

Go deeper

Check your understanding

  1. 1.A feature should only be available to paying customers. What should gate it?

  2. 2.What does the Default badge on a role mean?

Your task

Insight Project

Open Users, then Roles. Add at least one role, choose the default, and press Save Roles.