Guides/Team & Stores

How to Add Team Members and Set Permissions in Opencals

Stan|Jul 19, 2026
How to Add Team Members and Set Permissions in Opencals

Opencals lets you invite your whole team into the dashboard and control exactly what each person can see and change. This guide walks through adding a user, choosing the right role, linking a staff member, and — when the defaults aren't quite right — adjusting individual permissions with the permission matrix.

Add teammates under Users: enter a name and email, pick a role (Store owner, Manager, or Staff member), and save. Each role ships with sensible default permissions, so most teams never touch the matrix. When you need something specific, override any entity and action to Allow any, Allow own, or Deny on a single user — without changing their role.

Before you start

You need to be signed in as a Store owner to create users and change roles — Managers and Staff members can't. Decide up front whether the person needs a bookable profile: a user is a dashboard login with permissions, while a staff member is a bookable resource that appears on schedules. The two are separate, but a Staff member user can be linked to a staff profile so the same person logs in and takes bookings. If you haven't created their staff profile yet, see onboarding staff members.

Step 1 — Open the Users list

Go to Users from the dashboard. This lists everyone with a login to the current store, showing their Name, Email, Role, and Status. You can filter by name or by role, and each row is clickable to edit that user. Click Create User to add someone new.

app.opencals.com/users
Open

Users

Create User
Filter users...
NameEmailRoleStatus
Sarah Johnsonsarah@brightstudio.comStore ownerVerified
Lisa Chenlisa@brightstudio.comManagerVerified
Mike Alvarezmike@brightstudio.comStaff memberPending
Users — everyone with a dashboard login, their role, and email status.

The Status column tells you whether a user has verified their email. A newly invited user shows as pending until they click the verification link.

Step 2 — Enter the user's details and pick a role

Fill in Name and Email — both are required, and the email must be unique across your users. It's the address they'll log in with and where the invitation is sent. Then choose a Role.

app.opencals.com/users
Open

General info

Name *
Mike Alvarez
Email *
mike@brightstudio.com
Resend verification email
Role *
Staff member
Link to Staff member
Select staff member

Only shown for the Staff member role — links this login to a bookable staff profile.

Save
Create User — name, email and role. The user sets their own password from the invitation email.

There are three roles, each with a different default level of access:

1

Store owner

Full control of the store — create and manage users, change settings, access plans and billing, and manage everything else. A Store owner can't change their own role, which prevents accidental lockout.

2

Manager

Full create/read/update/delete on day-to-day work — appointments, products, schedules, staff members, locations, customers, orders, integrations, emails and more. Read-only on settings, tax settings, users, and plans.

3

Staff member

Read access across the store, plus the ability to create their own appointments, update their own appointments, and update their own staff profile and user account. Best for service providers who need dashboard access.

You don't set a password for the user. When you save, they receive an email invitation and set their own password on first login — or sign in with Google. If a user hasn't verified their email yet, the edit screen shows a Resend verification email button next to the address.

Users and staff members are different things

A user is a dashboard login governed by roles and permissions. A staff member is a bookable resource on your schedules. They're managed separately — but you can link them so one person both logs in and takes bookings. See the staff onboarding guide for the staff side.

When you pick the Staff member role, a Link to Staff member field appears. Select the staff profile this login belongs to. Linking connects the dashboard account to the bookable resource, so the same person can sign in and be assigned to appointments. Leave it unlinked only in the rare case where a staff-level login isn't a service provider — but then they can't be booked.

Step 4 — Fine-tune permissions

The role defaults cover most teams, so you can stop after saving. When someone needs more or less access than their role gives — say a Staff member who should be able to create products, or a Manager who shouldn't delete customers — open the user and use the User permissions matrix to override individual permissions without changing the role.

app.opencals.com/users
Open

User permissions

EntityCreateReadUpdateDelete
AppointmentsDefaultDefault Allow anyDefault
Products Allow anyDefaultDefaultDefault
CustomersDefaultDefaultDefault Deny
OrdersDefaultDefaultDefaultDefault
SettingsDefaultDefaultDefaultDefault
UsersDefaultDefaultDefaultDefault
Reset to defaultsSave
User permissions — override the role defaults per entity and action.

The matrix has one row per entity (Appointments, Products, Schedules, Staff members, Locations, Customers, Orders, Plans, Settings, Tax settings, Integrations, Emails, Images, Checkout questions, Feedback questions, Stores, Users, User permissions) and one column per actionCreate, Read, Update, Delete. Each cell picks how that action is handled:

1

Default

Fall back to the role's built-in permission. The label shows what the default resolves to, so you always see the effective access before you change anything.

2

Allow any

Grant this action on all records store-wide — e.g. update any appointment, not just the user's own.

3

Allow own

Grant this action only on the user's own records. Available for the entities that support ownership — Appointments, Staff members, and Users. Other entities show a plain Allow instead.

4

Deny

Explicitly block this action, overriding whatever the role would otherwise allow.

Any cell you change is marked as an override, so overrides stand out from role defaults at a glance. Click Save to apply them, or Reset to defaults to clear every override on this user and return to their role's defaults.

Start narrow, widen when needed

Assign the smallest role that fits, then grant extra access with an override on the single entity and action that's needed. It's easier to add one permission than to unwind an over-privileged account later. For a full history of who changed what, pair this with the audit log.

Step 5 — Manage account access and API keys

On their own account, a user can manage the login methods and integration keys tied to it. The edit screen shows an OAuth Providers card for connecting or removing Google sign-in, and an API Keys card for programmatic access.

app.opencals.com/users
Open

API Keys

Manage your API keys for programmatic access

Create New Key
No API keys found
API Keys — programmatic access, scoped per store, managed on your own account.

API keys are scoped per store and used for programmatic access to your data — useful for automations and custom integrations. You can't remove your only authentication method: if a user has no password set, they can't unlink their only OAuth provider until they add another way to sign in.

Frequently asked questions

Frequently Asked Questions

Keep going

Early Access — 3 Months Free

Ready to transform your service business?

Join 150+ businesses already using Opencals. Get 3 months completely free with all features unlocked.

No credit card required
Setup in 10 minutes
Cancel anytime