Roles, teams & permissions

The RBAC model — seven system roles, module permissions, data scope and teams.

d0pe ships a full role-based access model so you can bring on staff, buyers and external partners without any of them seeing more than they should. A fresh install seeds seven system roles; you can retune every one of them live, or clone them into your own.

The seven system roles

What a role controls

Teams

Teams form a tree. A team's lead is simply the user with the team_lead role on that team, so a team lead's team-scope automatically covers their buyers. Combined with data scope, this keeps each buying team's traffic and numbers walled off from the others.

Email notifications (optional)

People can register themselves — a traffic source or a partner fills in the public form and waits for you to approve them. Without email set up, nobody is told what you decided: you approve the account, they keep trying to log in, and both sides wait for the other. Configure SMTP under Settings · Mail and the CRM writes to them itself — address confirmation, approved, declined, and a traffic source's API guide with its credentials already filled in.

It is genuinely optional. A box with no SMTP behaves exactly as it always did, which is the right setup if you only ever add staff by hand.

Two things are worth knowing before you start. The mail goes out through your own server, never relayed through us, because otherwise your staff's and partners' addresses would end up on our side — the opposite of what running on-prem is for. And the sender must be on a domain you control: an address at d0pe.app is rejected, since your server isn't authorised to send as our domain and SPF/DKIM would push those messages to spam.

Least privilege by default: staff, buyers and partners each get exactly one honest view.