Domma CMS User Manual

Users & Roles

Updated by Darryl Waterhouse on 29 September 2026 4 min read

Users are stored as individual JSON files in content/users/. Passwords are hashed with bcrypt and never returned by the API. Manage accounts at System > Users and roles at System > Roles.

Roles

Roles are data, stored in the roles preset collection. Every site starts with three base roles, which cannot be deleted:

Role Level Access
Super Admin (super-admin) 0 Everything. The level-0 role holds every permission, including the ones plugins and built-in Tools add, whatever its permission list says.
Admin (admin) 1 Content, structure, collections, views, actions, users, settings, theme, plugins, API tokens and endpoints, notifications, the built-in Tools (Contacts, Notes, Todo, Analytics, SEO), and renaming or deleting any contact group. Plugins usually grant their own permissions to Admin when first switched on.
User (user) 2 Notifications only - a signed-in account with no admin rights of its own.

Admin is given the built-in Tools (Contacts, Notes, Todo, Analytics, SEO) once, the first time the site starts on a release that includes this (after 0.94.0). Untick one and it stays unticked. User is not given them - tick them for the roles that should have them.

Your own roles

Add roles with New role on the Roles screen. Each role has a level (lower is more senior) and a set of permissions, ticked in a matrix of resources and actions (View, Create, Edit, Delete, and extras such as Contacts > Manage groups). Permissions are grouped: Content, Structure, Data, Configuration, Tools, then Plugins.

  • Additional roles. A user has one primary role and can hold more. A permission check passes if any role they hold grants it.
  • Grants only add. A plugin that grants its permission to a role does it once. If you untick it afterwards it stays unticked.
  • Plugin roles. Some plugins bring roles of their own (the Blog's Blog Author and Blog Editor, for example). They appear on the Roles screen like any other and you can edit them; the plugin never overwrites your changes. Switching the plugin off keeps its roles; uninstalling it removes them and moves their users to user.

Confining a role to some screens

A role can be confined to a list of admin screens, with one of them as its home - useful for people who sign themselves up on the public site. A confined user sees only those screens in the sidebar, and the server refuses their calls to any plugin API whose screens they cannot open. A user is confined only when every role they hold is confined: one unconfined role lifts it. The level-0 role is never confined.

Who can see what: the role ladder

Pages, menu items, views and actions name the roles they are for. Two forms exist, and the page and menu editors offer both for every role:

You choose Stored as Who gets in
Candidate and above candidate Holders of that role and everyone on the same or a more senior level.
Candidate only =candidate Holders of that role only (primary or additional), plus the level-0 role. An ordinary admin does not pass - give them the role as an additional role if they need it.
Several roles [candidate, employer] Anyone who passes any one of them. Exact and ladder forms mix.
Private private The level-0 role only.

A role name the site does not have (a role since deleted, or a typo) admits only the level-0 role - never everyone. The collection and action editors flag such a role so you can fix it. A page a visitor may not see answers 403; a draft answers 404.

Managing users

You can only create, edit, delete or reset the password of a user whose role is less senior than yours (a higher level number) - an admin cannot manage another admin. You cannot give anyone a role more senior than your own.

Right-click a user (or use the row menu) to Send password reset email, Copy a reset link (for a site without email) or Withdraw the reset link. The account holder is emailed whenever their password changes.

Passwords and sign-in

The core rule is at least 8 characters. The free Security plugin, when switched on, adds stricter password rules, sign-in lockout and a log of every sign-in; Security Pro adds two-factor sign-in and a list of every signed-in session. "Forgot your password?" works only when the site can send email (Site Settings > Email); without it the sign-in screen tells the person to ask an administrator.

The admin panel uses JWT Bearer tokens, refreshed automatically. By default an access token lasts 15 minutes and a refresh token 7 days (config/auth.json). Each sign-in is a session kept on disk, so signing out holds even across a restart; changing a password signs out that account's other sessions.

Views & Actions

Building Views and Actions is controlled by the views and actions permissions. Super Admin and Admin hold both by default; the User role holds neither. Who may read a view or run an action is set on the view or action itself (its Access tab), using the role ladder above - any listed role is enough. Views work on every storage adapter; Actions need a MongoDB connection.

See also: Editions & Licences for what the free and Pro editions include, and Plugin guides for the roles and permissions each installed plugin adds.