Dashboard roles and route access
This reference records ProtectedRoute level lists at the accepted source SHA. It does not report authenticated runtime results, API permission, sidebar entitlement, or deployed access.
A level in allowedLevels is only a client route gate. Sidebar parents, plan/add-on/feature flags, read-only types, page state, and API authorization can be stricter. GET/HEAD is not presumed safe and no route was opened.
Role names used in the Dashboard
| Role | Notes from the Dashboard UI |
|---|---|
| Administrator | The role used for the Dashboard's administrator-only routes. |
| City manager | Displayed in shared user lists and filters. |
| Business owner | Has access to selected operational and store routes. |
| User | Displayed in shared user lists and the role selector. |
| Professional | The role selector shows it when the appointments add-on is enabled. |
| Call center agent | The role selector shows it when the Enterprise plan is enabled. |
Selected route-level gates
| Dashboard area | Level 0 Administrator | Level 2 Business owner | Level 8 Professional | Level 9 Call center agent | Level 3 User | Other allowed levels |
|---|---|---|---|---|---|---|
| Users: Customers, Business owners, Call center agents, Administrators | Yes | — | — | — | — | — |
| Professionals | Yes | Yes | — | — | — | Level 5 |
| Orders, Deliveries, and All in one | Yes | Yes | — | — | — | Level 5 |
| Driver dashboard and Driver store status | Yes | — | — | — | — | Level 5 |
| Appointments, Schools, Messages, and core Stores routes | Yes | Yes | — | — | — | — |
| Profile | Yes | Yes | Yes | — | — | Level 5 |
| Most configuration, intelligence, marketing, product, and support routes | Yes | — | — | — | — | — |
An em dash means the role level is absent from that route's current allowedLevels list. Level 5 remains numeric because the reviewed shared selector does not provide a verified label for it.
Conditions that can change what appears
- Some role choices depend on plan or add-on configuration: Call center agent requires the Enterprise plan in the shared role selector, and Professional requires the appointments add-on.
- Individual page controls can depend on project configuration or enabled features. For example, user-detail tabs can expose Push tokens for Enterprise projects and School students when the school module is enabled.
- Customer details can expose Cash wallet and Points wallet only when their corresponding add-ons are enabled.
Default destinations
When an authenticated account opens the Dashboard root, the current routing logic sends Professional accounts to Profile and level-5 accounts to Orders. Read-only account-type flags also affect this default destination. This behavior does not by itself define every action that those accounts can take.
Boundaries and re-entry
This table must be invalidated on route, sidebar, role-map, plan/add-on/flag, or source-pin drift. Positive permission guidance requires immutable Dashboard/API serving receipts and synthetic role fixtures with PII, credentials, sessions, assignments, and writes blocked.