Documentation / Users, Roles, and Access / Role-Based Access

Role-Based Access

Practical PanelConfig guidance for Role-Based Access, with safe workflow, clear records, and operational review notes.

Role-Based Access explains how this part of PanelConfig should be used in a production hosting operation. It focuses on practical decisions, audit visibility, and safe execution rather than marketing language. Security actions should be auditable and reversible where possible; avoid making firewall or WAF changes without a recovery path.

Usage

Use this guide when you are configuring, reviewing, or troubleshooting role-based access for a hosting provider, agency, reseller, or customer account. It is useful during initial setup, operational handover, incident review, and routine maintenance.

Workflow

  1. Open the related PanelConfig page: PCAdmin > Users, Audit & Logins, Settings.
  2. Confirm the account, domain, user, or server context before changing anything. In provider environments, many records have similar names.
  3. Review current status, ownership, package limits, and any pending jobs before making a change.
  4. Make the smallest safe change first. For destructive or customer-visible operations, keep a ticket or internal note with the reason.
  5. Re-check the page, job queue, audit log, and any affected service status after the operation completes.

Checklist

CheckWhy it matters
OwnershipPrevents changes on the wrong customer, reseller, or hosting account.
Current statusAvoids repeating an action that is already pending, suspended, queued, failed, or completed.
Limits and dependenciesShows whether package limits, DNS state, storage, service health, or credentials affect the result.
Audit trailGives support and operations teams a reliable record of who changed what and why.

Related

PCAdmin: PCAdmin > Users, Audit & Logins, Settings

PCUser: PCUser > Profile and Security

Related PCCLI: php cli/pc users:list

Records

Typical records involved: users, roles, permissions, role_permissions, user_roles, password_resets, email_verifications, login_history, audit_logs. Some actions only read these records, while write actions may update status fields, create queue records, write audit entries, or refresh timestamps. For integration-ready areas, do not assume an external provider action has completed until the local job and provider-side evidence agree.

Notes

Security and audit notes: use least-privilege access, avoid sharing raw credentials, keep customer-impacting changes tied to a reason, and review Audit Logs or Login History when an action affects authentication, access, DNS, mail flow, backups, SSL, firewall, WAF, or account status.

Troubleshooting

  • If the page is empty, confirm the related database table exists and that the user role has permission to view the module.
  • If a change appears stuck, check Jobs, Job Logs, and Services before repeating the operation.
  • If an external dependency is involved, verify it independently: DNS propagation, ACME challenge visibility, remote backup storage, mail DNS records, or provider API state.
  • If the result is sensitive or customer-visible, capture the exact timestamp, account id, domain, and operator before escalating.

Example

php cli/pc users:list

Related

php cli/pc firewall:list, php cli/pc security:overview

← Reseller Concepts Login History →