What this section is for
Use Backoffice / Staff to manage the people who can sign in to Backoffice and to review what each account is allowed to do.
This section is relevant when a client manages its own support, payments, affiliate, content, risk, finance, or operations team. If all Backoffice accounts are created centrally by the platform team, the section can be hidden from client roles.
What operators can do
- search the staff inventory by name, email, or group
- open a read-only account view
- review stored permissions by category
- create Manager or Support accounts when authorized
- edit identity details, password, group, and delegated permissions
- export or import a permission template as JSON
- create restricted demo access when the root superadmin workflow is available
The visible Staff workflow does not provide delete or status-toggle actions. Status is informational on the list.
Create and edit
Create
- Enter Email, Password, First Name, Last Name, Username, Group, Role, and Permissions.
- The visible role choices are
ManagerandSupport. - Support creation also requires the correct parent administrator before permissions are configured.
- The server can reject a combination that exceeds the current administrator's hierarchy or delegated access, even if a control was visible.
Edit
- Role is read-only on the current edit form.
- Password is optional; leaving it unchanged keeps the current password.
- Parent context for Support is informational and is not a reassignment control.
- When operators edit their own account, the permission matrix is hidden. Another authorized administrator must review self-permissions.
How permissions work
- A role is not a complete access description. Use the Permissions tab to inspect stored access.
Rmeans Read,CCreate,UUpdate,DDelete, andTstatus toggle where a module supports it.- Some modules expose additional action codes.
- The form requires Read before another action in the same permission category can be selected.
- An administrator cannot delegate permissions beyond the access allowed by the server.
- Non-root users cannot assign or alter the privileged superadmin group.
Import and export
Export JSON downloads the current permission, group, and role template. It does not export a password.
Import JSON prepares local form values, filters unavailable permissions, and skips password data. Review the result and select Submit to save it.
Demo accounts
Create DEMO provisions real demo casino and Backoffice access and displays generated credentials. Execution is restricted to the root superadmin. A level-1 user can still see the button in the current UI and then be refused by the server.
Store generated credentials securely. The casino and Backoffice records are created through separate steps, so a partial failure requires an account check before retrying.
Troubleshooting
If create or edit fails, check:
- duplicate email or username
- required field format and password rules
- selected role, group, and Support parent
- whether the current administrator may manage the target account
- whether imported permissions are available to the current administrator
- whether a Support create already produced an account before an error appeared
The current Support create flow can issue a second create attempt after the support-scoped request. If an error or duplicate message appears, check the Staff list before retrying.
Staff Activity is separate
Backoffice / Staff Activity is a read-only activity journal with its own StaffActivity: R access. It does not create accounts or change Staff permissions.
Access recommendation
Give Staff create/update access only to owners, senior managers, heads of operations, or designated access administrators. Ordinary support, payments, content, and affiliate users should not be able to change another person's access.