Browse Start Here

Start Here

Roles and access at a glance

Compare Viewer, Admin, and Superadmin access, choose the least privileged role for each task, and understand how managed SSO roles map into the CMS.

4 min readUpdated 8 Aug 2026

Outcome

You can choose the least privileged CMS role for a task, recognise a normal access boundary, and ask the correct administrator for a safe change.

Access

This guide applies to signed-in Viewer, Admin, and Superadmin users. A role controls the maximum access available; plans, installed plugins, site state, and individual feature rules can narrow it further.

Compare the CMS roles

RoleUse it forTypical boundary
ViewerRead-only access to permitted admin information.Cannot perform Admin or Superadmin changes.
AdminNormal site content and operational work, including creating, editing, previewing, publishing, and unpublishing pages.Cannot use restricted site-wide or destructive controls.
SuperadminAll Admin work plus protected administration such as CMS users, backups and restore, storage credentials, and selected permanent deletes.Highest CMS role; use only when the task requires it.

Permissions are cumulative: Admin includes Viewer permissions, and Superadmin includes Admin and Viewer permissions. Viewer is a signed-in CMS role. It is not the same as an ordinary public visitor or a community Public user.

Role is not the only requirement

A missing screen or button does not always mean the role is wrong. Before requesting broader access, check:

  • the role required by the specific task;
  • whether the site's plan includes the feature;
  • whether the required plugin is installed and loaded;
  • whether the current record state makes the action available; and
  • whether a managed account must be changed in the BlockNinja account portal.

Search anything, Satoru, plugins, and connected MCP clients inherit the signed-in person's access. They do not bypass the role boundary.

Managed SSO role mapping

Account portal roleCMS role after managed sign-in
OwnerSuperadmin
AdminSuperadmin
EditorAdmin
ViewerViewer

SSO identities are managed in the BlockNinja account portal. Do not create a duplicate local account as a shortcut.

Choose the safest role

  1. Write down the exact task, such as review a page, publish content, manage users, or preview a restore.
  2. Start with the lowest role that supports that task.
  3. For a standalone local user, a Superadmin opens Administration, then Users, and chooses Viewer, Admin, or Superadmin in Send Invite.
  4. For a managed SSO user, change the account role in the BlockNinja account portal.
  5. Have the person sign in again and verify only the required task.

Do not capture or publish the Users table as evidence. It can contain names, email addresses, sign-in type, status, and recent activity.

Check the result

  • A Viewer can inspect permitted read-only information but cannot complete an Admin or Superadmin change.
  • An Admin can complete an ordinary page draft and publication task but cannot use Superadmin-only user or backup controls.
  • A Superadmin can open Users and see Viewer, Admin, and Superadmin as role choices without sending an invitation.
  • A managed SSO user receives the expected CMS role after signing in again.

Undo or recover

  • If a role is broader than needed, reduce it at the identity's owning surface and verify the person's required task again.
  • If access was removed by mistake, restore the previous role instead of creating a second account.
  • Deactivation is reversible. Permanent deletion is not; do not use deletion to correct a role.
  • If the action remains unavailable, restore the original role while checking the plan, plugin, site state, and feature requirement.

If it does not work

  • If Users is missing, the signed-in person may not be a Superadmin.
  • If a managed SSO user cannot be edited in the CMS, make the change in the BlockNinja account portal.
  • If a role change appears ineffective, sign out and sign in again before escalating.
  • If one control remains absent, record the exact screen, task, visible message, and time. Exclude personal data and identifiers.

Next

  • Sign in and tour the admin.
  • Find anything with the command palette.
  • Invite and manage CMS users.

Related guides