Users and permissions
Every user on the account has one of three permission levels: Full Access, Developer or Billing. A Full Access user adds, changes and removes users; a user is added by email address and sets their own password from the link we send.
What each level can do#
| Full Access | Developer | Billing | |
|---|---|---|---|
| The CDN section: zones, hostnames, settings, purges and statistics | Yes | Yes | No |
| The API key and API access | Yes | Yes | No |
| Billing: the card, the agreement, invoices and payments | Yes | No | Yes |
| Account Details: company, address, VAT number | Yes | No | Yes |
| Email contacts: who receives Billing, Technical, Account and Abuse emails | Yes | No | Yes |
| Enforce 2FA for All Users | Yes | No | No |
| Add, change and remove users | Yes | View only | View only |
| Their own profile, password and two-factor authentication | Yes | Yes | Yes |
| Support: the documentation search, writing to the team, the support PIN | Yes | Yes | Yes |
An overdue invoice shows a banner to every user: with a link to pay for those who can, and a note to ask whoever handles billing for those who cannot.
The rules#
- One email address is one user across CacheGenie: an address already on any account cannot be added to another.
- A new user cannot sign in until they have set a password from their welcome email.
- Changing a user's level signs that user out everywhere. Removing a user ends their sessions, cancels any reset link they hold, and emails them.
- You cannot change your own level or remove yourself.
- Every user is listed under Email contacts, and the Users page says what each one receives. A user who is the only person ticked for a kind of email cannot be removed until someone else is ticked for it.
- Your own signed-in sessions are listed under Users; revoking one signs that browser out at its next request.
- Our team can help a user who cannot sign in: after checking the account's support PIN, they can send a sign-in link, switch off two-factor authentication after a lost device, sign the user out everywhere, clear a lockout, or correct their email address, which then has to be confirmed from the new inbox. The user is emailed about a sign-in link, a two-factor reset and an address change, and every change our team makes on your account is recorded.