Choose a role that matches a teammate’s responsibilities, limit which admin pages they can open, and check that the resulting access is right for their work.
Cedros has two separate controls: an organization role governs membership and team-management responsibilities, while Manage Permissions controls access to pages in an individual site’s admin. A page being visible does not guarantee permission to perform every action on it.
Before changing access
Confirm the person, organization, and site first. A role change in your Cedros customer portal applies to the account selected there; do not assume it changes every separately managed site’s team.
You need authorization to manage that team or site. Organization role changes require an owner or administrator with the necessary permissions. Saving admin page restrictions requires the site’s manage users permission. If you can open Manage Permissions but see a message that access is managed by an owner, ask an authorized owner to make the change.
Agree on the tasks the person needs to perform—for example, reviewing articles, sending campaigns, or managing other teammates. Record their current role and any page restrictions before changing them so you can restore the intended setup if needed.
If the person has not joined yet, start with Inviting teammates and accepting invitations. Page permissions do not create an account or accept an invitation for them.
Choose an organization role
The standard team invitation and Portal role controls offer Member and Administrator. An organization can also have an Owner.
Member
Use Member for teammates who do not need to administer the organization’s membership. Under the standard organization permissions, members can view organization, member, and invitation information but cannot manage the team.
Member is not a universal “read-only” setting for every Cedros product. Editing, publishing, billing, and other tools have their own permission checks. Confirm the tasks the person can actually perform on the relevant site.
Administrator
Use Administrator for someone trusted to manage the organization and its team. Standard administrators can invite people and change non-owner members’ roles, subject to the permissions available in that account. Owner-only operations remain separate.
Owners and administrators are not limited by ordinary admin page restrictions. If someone only needs one additional page, granting Administrator is a much broader change than naming them in that page’s access rule.
Owner
Owner is the organization’s highest built-in role. It includes owner-only responsibilities such as deleting the organization. Only an owner can change another owner’s role or grant owner status, and Cedros protects the last owner from removal or demotion.
The standard Portal Change a member role form offers Member and Administrator; it is not an ownership-transfer form. If ownership needs to change, ask the current owner or support for the supported process for your account.
Change an existing teammate’s role
Use these steps when your customer portal exposes team-management actions. On cedros.ai, open Portal Team, or choose Team from the portal account menu.
- Sign in and confirm the account or organization whose membership you intend to change.
- Open Team and find Team actions.
- Expand Change a member role.
- Choose the correct Team member, then choose Member or Administrator in Role. Recheck the person before submitting.
- Select Update role and wait for Member role updated.
- Review the team information, then ask the teammate to reload the relevant interface and check their intended access.
You cannot change your own organization role through this operation. Ask another authorized administrator or owner to handle it; changing an owner’s role requires another owner. Do not remove and reinvite yourself as a workaround.
If the portal is read-only or the action is missing, use an authorized account for the same organization or ask its owner. The site’s Manage Permissions page edits page restrictions, not organization roles.
Changing Administrator to Member can reduce access to team-management operations, but it does not remove the person from the organization. It also does not automatically create page restrictions: unrestricted pages remain unrestricted, subject to the site’s other access checks.
Restrict an admin page or section
In your site admin, open Users → Team → Manage Permissions. The Restricted pages list shows exceptions to the default: admin pages are open to teammates who otherwise have admin access until restricted here.
“Open” means no additional page restriction. It does not make an admin page public or grant an ordinary website visitor admin access.
- Select Restrict a page.
- In Page, choose a specific page or a whole section. Search by page name, route, or section if needed. An All of [section] choice applies the same rule to the restrictable pages currently in that section.
- Under Who can still open it, choose Admins only or Admins and specific people.
- If you choose specific people, use Add a person to find and select each teammate who should keep access. Check the names under People who keep access.
- Review the selected page or section and the people listed. Select Restrict page and wait for the dialog to close successfully.
- Confirm that Restricted pages shows the intended page or section and the correct Who can open it summary.
Admins only keeps access for owners and administrators. Admins and specific people also keeps access for the people you name. If you name nobody, it behaves like Admins only.
For example, to keep a particular admin page available to administrators and one non-admin teammate, select that page, choose Admins and specific people, and add that teammate. They still need permission to perform their tasks on that page.
Dashboard, Site settings, Account, and Manage Permissions are protected from these page restrictions. Their individual actions still enforce their own permissions. You cannot use this screen to lock an owner or administrator out of those controls.
Whole-section changes apply to the pages present when you save. Review access again after enabling features or installing extensions that add pages; a new page does not automatically inherit an older section restriction.
Edit or remove a page restriction
Several pages with the same rule may appear as one section row. Check the row’s page count: All N pages and N of M pages have different scopes. Editing that row changes every page it covers.
Change who keeps access
Open the restriction, or choose Edit access from its actions menu. Change the access option, add people, or use the remove button on a person’s name. Select Save access, then check the saved summary.
To give one page a different rule within a grouped section, use Restrict a page, choose that individual page, and save its new access choices. The list will regroup pages according to their resulting rules.
Removing someone from a named-person list only removes that explicit page grant. It does not remove their organization membership, and an owner or administrator still retains access through their role.
Open the page to the wider team again
Choose Remove restriction from the row’s actions menu, read which page or pages it affects, and confirm Remove restriction.
Removing a restriction expands access. The affected pages become available to teammates who otherwise have access to the admin. To stop a particular person opening a page while keeping the restriction, edit the people allowed instead.
After removal, the restriction should disappear from the list. If no restrictions remain, the screen shows No pages are restricted.
Check the result with the affected teammate
Your own owner or administrator view cannot prove that a non-admin restriction works, because those roles bypass it. Ask the teammate to check from their own account; do not ask for their password.
After the saved change:
- Confirm they are on the intended site and in the correct organization, then have them reload the admin.
- For a page they should be able to open, confirm it is available and that the intended task is permitted. Use a harmless action or draft where possible.
- For a restricted page they should no longer open, confirm it is absent from their sidebar and that opening its saved address does not provide access.
- Check a page they still need, so you know a whole-section change did not remove more access than intended.
If the results differ from your plan, review the person’s role and the saved rule before widening access. A successful role or page-rule save confirms the change was stored; it is not a substitute for checking the teammate’s actual workflow.
Troubleshooting
The person can still open a restricted page
Check whether they are an owner or administrator, whether their name remains on the allowed list, and whether you changed the correct site and page. A grouped row might cover only some of a section’s pages. Have them reload after the change.
If a non-admin account still has unexpected access after these checks, contact support with the page address, organization, expected access, and time of the change.
The page opens, but an action is unavailable
Page access and permission to take an action are separate. An allowed person may still lack publishing, billing, team-management, or another required permission. Ask the owner to review the specific task and its permissions. Repeatedly removing the page restriction will not supply a missing action permission.
A person is missing or marked as no longer on the team
Confirm that the person accepted their invitation and belongs to the relevant team. To select a person, the site needs Cedros Login enabled and that person listed on its team. Deactivated people are not offered as new grants.
If the directory cannot be read, names may be missing even while saved rules remain in place. Use Try again or reload; do not treat an Unknown person label alone as proof that someone has left. When the directory has resolved and a grant is marked no longer on the team, review it with the owner and remove the outdated entry through Edit access.
Saving fails or the role change is rejected
Keep the error text and check your current organization and permissions. For role changes, remember the self-change and owner protections. Reload the roster if someone else may have changed the same membership.
For page restrictions, Cedros couldn't save this change. Your current rules are unchanged. Try again. means you should not assume the new rule took effect. Retry once the cause is resolved, then reopen the saved restriction and verify it.
For unresolved problems, see Getting help and reporting a problem. Include the site, organization, page or action, intended role or access, and exact error. Do not send passwords, invitation tokens, or MFA recovery codes.