Skip to main content

Collaborator Roles, Permissions & Account Management

🔍 Problem Statement

Pelcro's current collaborator permission model has two key issues: (1) any collaborator can delete other collaborators, which should be restricted to the Account Owner only; and (2) several roles lack capabilities they need — Sales cannot create/edit plans or export data for quoting and reporting, and Customer Service cannot void or cancel invoices, slowing issue resolution.


💡 User Story

As a Pelcro Account Owner, I want collaborator deletion restricted to my role only, and I want the Sales and Customer Service roles to have the specific capabilities they need (plan management, data export, invoice voiding/cancellation), so that permissions match real operational responsibilities without over-granting destructive rights.


🎯 Definition of Done (DoD)

A feature is done when:

✔️ Given the updated permission matrix, when a collaborator attempts to delete another collaborator, then only the Account Owner succeeds — all other roles receive a clear 'permission denied' error in both the UI and API.
✔️ When a Sales collaborator is logged in, then they can create/edit plans and export customers, subscriptions, and invoices — but cannot access access control, product settings, or delete any object.
✔️ When a support is logged in, then they can void and cancel invoices and update customer info — but cannot access plans, access controls, or delete any object.

✔️ As an Account Owner or Admin, I want to see the last login timestamp for each collaborator, so that I can identify dormant or inactive accounts during periodic security and compliance reviews.
✔️ Admins retain all existing delete permissions except collaborator deletion.

Status: Planned8 comments

Log in to comment and vote

Comments8

  • mesim

    •

    Jun 12

    Allow the account owner to grant their own permissions to collaborators

    🔍 Problem Statement

    As a project manager, I want to be able to make changes to all Pelcro settings, including security settings. Currently, security settings such as fraud prevention and authentication are only visible to the account owner. As the technical project manager, I should be able to make changes without having to walk the non-technical stakeholder account owner through the process.

    💡 User Story

    As a project manager, I want to be able to assign granular roles to collaborators. There are currently four roles with predefined access to choose from. I would like to be able to create custom roles where I can select the specific access the collaborator needs, including access currently reserved to the account owner.

    🎯 Definition of Done (DoD)

    1. An account owner should be able to create other “super” administrators with the same access/permissions as themselves or custom roles that can include the same access/permissions as themselves.

    2. Given an administrator with the proper role created by the account owner, the administrator should be able to create custom roles for other collaborators. The roles should accept a custom name, and the administrator should be able to select individual access/permissions for that role.

    3. The options available for access/permissions for custom roles should include access/permissions that are currently reserved for the account owner (such as security settings)

  • Manish Patel

    •

    Apr 2

    •

    Merged request

    •

    2 votes

    Add ability to export Collaborator Accounts

    🔍 Problem Statement

    There is no way to export the list of collaborator accounts from Pelcro. Teams that need to audit access, report on team composition, or sync with external HR/IT systems must compile the data manually.


    💡 User Story

    As an Account Owner, I want to export the collaborator account list as a CSV, so that I can audit access and share team data with external systems without manual compilation.


    🎯 Definition of Done (DoD)

    A feature is done when:

    ✔️ Given the collaborator list, when an Account Owner clicks export, then a CSV file is downloaded containing all collaborator details (name, email, role, status, last login).

  • Manish Patel

    •

    Apr 2

    •

    Merged request

    •

    2 votes

    Add last login time to Collaborator accounts

    🔍 Problem Statement

    Pelcro does not track or display when a collaborator last logged in. Admins have no visibility into account activity, making it difficult to identify stale accounts or enforce security policies.


    💡 User Story

    As an Account Owner, I want to see the last login time for each collaborator, so that I can identify inactive accounts and maintain security hygiene.


    🎯 Definition of Done (DoD)

    A feature is done when:

    ✔️ Given the collaborator list, when an Account Owner views it, then each collaborator's last login timestamp is displayed — and the data is available via the API.

  • Manish Patel

    •

    Apr 2

    •

    Merged request

    •

    3 votes

    Make Collaborator accounts "inactive"

    🔍 Problem Statement

    There is no way to mark a collaborator account as inactive in Pelcro. When a team member leaves or changes roles, the only option is to delete the account entirely — losing audit history — or leave it active, creating a security risk.


    💡 User Story

    As an Account Owner, I want to set a collaborator account to inactive, so that their access is revoked without deleting the account or losing audit trail history.


    🎯 Definition of Done (DoD)

    A feature is done when:

    ✔️ Given a collaborator account, when the Account Owner sets it to inactive, then the collaborator can no longer log in or take actions — but their historical activity and audit records are preserved.

  • JeffMerrick

    •

    Apr 2

    •

    Merged request

    •

    4 votes

    Pelcro Collaborator Roles & Permissions

    🔍 Problem Statement

    As an Account Owner, Pelcro's collaborator roles lack granular permissions — the Admin role has unrestricted access to high-risk operations (deleting collaborators and customers, managing integrations and API keys, the import tool, and core account settings such as taxes, billing, ACH, identity and sites) while other roles lack capabilities they need for daily work. This creates security risks and operational friction.

    💡 User Story

    As an Account Owner, I want granular, role-based permissions across all collaborator roles, with destructive and account-level actions reserved for Owners, so that each team member has exactly the access they need — no more, no less.

    🎯 Definition of Done (DoD)

    • ✔ Given the updated permission model, when a collaborator attempts an action outside their role's permissions, then it is blocked with a clear error — and when they attempt an action within their role, then it succeeds.
    • ✔ Only Account Owners can delete collaborators, delete customers, create/edit/enable integrations, manage API keys, run the standard import tool, and change core account settings.
    • ✔ This change will impact UI / API — specifically the Collaborators page (Platform UI) and permission enforcement across the Core API.
    • ✔ Limitations: existing collaborators are mapped onto the new model at rollout; no custom per-collaborator permission sets in this scope.
    • Zamir

      •

      Nov 13, 2025

      was just adding this on. Currently there are only five collaborator roles in Pelcro backend. Admin is fine but the rest and not suitable. For example the next level down is support, but a support role cannot add products to ecommerce or refund ecom products. I would suggest if there is a way to decide what a user can have access to or action they can do.

    • Chris Gogos

      •

      Nov 27, 2025

      I would also like to add to this suggestion. In our use case we require a level above ‘Support’ so that our users can update a card for a customer and enter a payment. Currently we have opened up the admin role to users that shouldn’t have it, which is not good practice for many obvious reasons.

  • Manish Patel

    •

    Feb 7

    We need to re-think “Only Account Owner can delete collaborators”

    Currently on each account there is only one Owner. There are times when Collaborators need to be deleted in Bulk or even when needed individually, it happens more often when a collaborator’s invitation has expired and are in pending status beyond 7 days. In those cases, the only option is to delete the collaborator and re-add them and have Pelcro trigger another email with the activation link.

    The Collaborator Roles and Security is a much more involved, complex and deeper topic than what I can add in a single comment, but I suggest that , a faster/quicker solution “could” that on the Collaborator who is assigned the Administrator, has an additional flag which would indicates whether the collaborator can access Collaborators at all. This way, if the flag is set to NO, then this administrator can execute all other functions BUT not add nor delete collaborators. Again, I realize this is not a permanent fix nor should it be, but it could be a quick fix while security roles and permissions are thought through carefully.