Available Permissions (ACL)
Understand how the Access Control List (ACL) works in Open Loyalty and explore the available permissions that define what admins can view and modify within the system.
Overview
The ACL (Access Control List) controls what an admin can view and modify in the Admin Panel.
Permissions are assigned per resource and come in two levels:
View: read-only access.
Modify: create, edit, delete, and run actions.
Anything not granted is hidden or disabled. Some API calls can return 403 when access is missing.
Where you manage permissions
You add these permissions in Settings → Roles when creating or editing a role. See Roles.
Common requirements and dependencies
Always grant View → Stores for new roles. Without it, the Admin Panel may not work.
Common dependencies:
Segments often needs Members to view members inside segments.
Transactions often needs Members for member-level transaction views and matching.
Issued rewards often needs Members to open linked member profiles.
Exports/imports require access to the underlying resources you export/import.
Permission catalog
Use the sections below as a reference when building roles.
Default role
A role can be marked as Default. When enabled, it is assigned automatically to new admins created via SSO login.
Last updated
Was this helpful?

