Skip to content
Bookelio / Documentation
Guides by topic

Management and settings

Managing members, roles and access

Invite your team, assign suitable permissions, create custom roles and secure access for people and API keys.

On this page

Organisations, accounts and members

Your personal account lets you sign in. Your membership of an organisation gives you a role within that organisation. The data and permissions you see in the dashboard depend on the active organisation: always start by checking its name when you manage several organisations.

A team member is not a customer record. Customers make bookings and receive documents; members have management access and, depending on the configuration, can be assigned to places or activities as staff. Creating a customer record does not give that person access to the dashboard.

Inviting someone

  1. Open the member settings for the relevant organisation.
  2. Start a member invitation.
  3. Enter their exact email address and select the intended role.
  4. Confirm the creation of the invitation.
  5. If necessary, copy the link provided and send it directly to the invited person.
  6. Afterwards, check that they appear among the members once they have accepted.

A created invitation is not yet an accepted invitation. If the person cannot access the organisation, check the invited address, the account being used and whether the invitation is still valid. The invitation link is not for public sharing: it is used to join your organisation.

The member-management interface uses labels such as “Invite Member”, “Role” and “Invitation Link”. These refer to the invitation action, the assigned role and the link to share respectively. Some of these labels may remain in English even when another dashboard language is selected.

Understanding built-in roles

The built-in owner, admin and member roles retain Bookelio's historical behaviour and cannot be changed through the role editor. You can view their permissions.

Important: the built-in member role is not a read-only role. It retains broad business permissions. If someone should only view certain data or manage a restricted area, create a custom role and explicitly assign it rather than choosing member by default.

Permissions to administer the organisation, members, invitations, roles and keys are separate from business permissions such as managing customers or viewing invoices. Being able to use the schedule does not automatically mean being able to invite someone or grant them access.

Creating a custom role

  1. Open Settings, then Roles and Permissions.
  2. Choose to create a role.
  3. Enter a stable identifier, for example reception or training-follow-up.
  4. Tick the resources and actions that are actually needed in the grid.
  5. Save, then assign the role to the person from the member list.
  6. Check with them that the expected tasks work and that unnecessary data remains outside their access scope.

A custom role starts with no permissions. Granting read access to an area does not automatically allow creating, editing, deleting or sending within that area. Some operations have several effects: a registration that also creates a payment request may require more than just permission to view training courses.

Example: for someone responsible for viewing participants, start with the appropriate viewing permissions. Add attendance management or certificate sending separately if their tasks require it. Do not grant all financial permissions merely to make an error disappear without identifying its cause.

You cannot delegate more permissions than you hold yourself. An existing role's identifier remains fixed: to change its name, create the new role, reassign the members, then deal with the old role after checking where it is used.

Changing a role or removing a member

In the member list, the role selector lets you change another member's role if you are authorised to do so. Removal requires confirmation. Check the operational consequences before removing someone assigned to activities or bookings, and arrange their replacement.

Your own account row does not let you change your role or remove yourself through these actions. This prevents some accidental losses of access. Involve another authorised manager when your own membership needs to be changed.

A greyed-out or hidden action is not necessarily a display problem: it may indicate a limitation of your role or a safeguard specific to that person. Do not try to bypass it by sharing a colleague's account.

Securing your personal account

In My Account, you can update your name, request an email address change, change your password and manage passkeys when your device supports them. Follow the displayed confirmation steps when changing your email address.

For a password change, the form asks for the current password, the new password and its confirmation. Changing your password from this screen should not be interpreted as automatically ending all other sessions. If you suspect unauthorised access, notify your administrator so that all affected access can be addressed.

Daily booking summary preferences are also configured in My Account: whether it is enabled, the time and sending a test. These are your preferences as a member, not an automatic subscription for the whole team.

Managing API keys without sharing an account

API keys are for authorised integrations, not for a colleague to sign in as a person. Depending on your permissions, the API Keys page lets you create a named key and assign limited business permissions. Copy the new value to a secure location when you create it; do not put it in a public email, screenshot or documentation page.

Older keys may show a full-access indication. Restricting their permissions removes this exception without changing the key's value: coordinate this action with the person responsible for the integration to avoid interrupting its operation. New keys should not receive unlimited global access.

If a page remains inaccessible after a role change, refresh your session and check the active organisation. Give the administrator the exact task and displayed message; the troubleshooting guide helps distinguish a legitimate restriction from an error.