Most organizations are not one person. The treasurer should see the money, whoever runs the events should run the events, and the new volunteer should not be able to delete a member by accident. Admins are how you do that: an address, a tick for each thing they look after, and nothing else. This note covers adding an admin, what each role reaches, passkeys, taking access away, and the log of who did what. If you have not opened the tool before, How to make edits on an Avistra website shows the sign-in.
Admins is for full admins only, and like everything that shows people's details it needs your passkey. How to set up a passkey on an Avistra website walks through it.
Where admins live
Choose the dots at the end of the bar in the lower right, then Admins. On the Dashboard it is also down the left, under Settings. The list shows every admin: their address, what they look after, and whether they have set up a passkey yet. An admin without one is marked, because until they add one they can look but change nothing.
What the roles are
Tick as many as somebody needs. They add up.
- Full. Everything, including admins, payment settings and exporting everyone. Ticking it ticks and locks the rest, because Full already holds them.
- Look at everything. Sees everything and changes nothing, unless a box below is ticked. Good for a board member who wants to keep an eye on things.
- Membership. People, membership and applications.
- Events. Events and their registrations.
- Store. Products and orders.
- Website. Pages and posts.
- Finance. Payments, refunds and reports.
The Dashboard only shows somebody the modules their roles reach, so an events admin opens the site and sees Events, not your members' payment history. A few things are Full only wherever they appear: deleting a person, downloading the whole list of people, the Stripe key, and admins themselves.
Adding an admin
Add an admin, at the top, asks for their address and what they can do.
- Type the address they will sign in with. It is also where their sign-in codes go.
- Tick what they look after.
- Save.
That is all. They sign in the way you do: their address, the code we email them, then a passkey they set up the first time. Nothing is sent to their inbox until they sign in themselves.
The addresses that were set up with your site are marked Set up with the site, and cannot be changed from this screen. Send us a support request to change one. You also cannot change your own roles, so nobody can quietly give themselves more.
Passkeys, and somebody who is locked out
Open an admin from the list and there are two things you can do for them.
- Reset their passkeys. For somebody who has lost their phone and their backup codes. They are signed out everywhere and set up a new passkey the next time they sign in. They are told by email.
- Sign them out everywhere. Ends every session they have, on every device, at once. Use it if a laptop goes missing.
Nobody at Avistra can get into your site by the front door either: there is no setting that turns the passkey off, for anyone.
Taking access away
Remove takes somebody's access away. They can no longer sign in to change anything, and their person record, their membership and their history all stay exactly as they are; only the key is taken back. The last full admin cannot be removed, so a site can never end up with nobody who can let anyone else in.
Somebody who only works the door
An events admin can hand the door to a volunteer for one event, without making them an admin at all. On the event, under its menu, Door volunteers takes an address and Send the check-in link. That person signs in with an emailed code and reaches that event's check-in page and nothing else: they see names and who has paid, and no members, no money and no other event. The pass ends when the event does, and never lasts more than a week. Remove takes it back sooner. How to sell tickets and check people in on an Avistra website covers the door itself.
The log of who did what
Audit log, at the foot of Admins, is the record: every sign-in, every change, every export, every refusal. Each line says when, who, what they did and what they did it to.
- Who narrows it to one admin's address.
- Kind narrows it to Viewed, Changed, Exported, Deleted, Signed in, Refused or Alerts.
- From and To narrow it to a period.
The log cannot be edited or deleted by anybody, including us, and it is kept for two years. It never holds a member's personal details; it says what was touched, not what the details were.
Who can do what
- Add, change and remove admins, and read the audit log: full admins.
- Everything else: whoever has the role for it.
- Everyone above read-only: needs a passkey, every time.
If you get stuck
Send it to us. Choose Support request in the bar and say what you need: somebody who cannot get in, an address to change, a role that is not reaching what you expected. How to submit a support request on an Avistra website shows how.