Users & Permissions
Invite your team to Localess and control what each member can see and change with roles and fine-grained permissions.
Every person who signs in to the Localess admin UI is a user. A user's role decides whether they have full access or only the permissions granted to them. Roles and permissions apply to the whole installation — every space, not one space at a time.
Main Screen
Navigate to Admin → Users from the side menu. The entry is shown to admins and to users with the User Management permission.
The table lists every user with their email (a shield icon marks a verified address), name, whether the account is active, sign-in providers, role, and creation and update dates. For a custom user, hover the info icon next to the role to see their permissions; a lock icon marks a locked user. Search by email or name, or filter by Active.
| Action | Description |
|---|---|
| Invite | Create a new user — see Inviting Users |
| Sync | Copy accounts and their roles from Firebase Authentication into the list. Use it when a user — one you just invited, or one created in the Firebase console — is missing or shows an outdated role |
| ⋮ → Edit | Change the user's role, permissions and lock |
| ⋮ → Delete | Delete the user and their sign-in account |
Roles
| Role | Access |
|---|---|
| Admin | Everything, in every space, including everything no permission covers |
| Custom | Only the permissions ticked for the user |
| None | Can sign in, but can't open any space |
Changes to a user's role or permissions apply when their sign-in session refreshes; signing out and back in applies them immediately.
Lock User
A custom user can also be locked. A locked user can't change their own password or other personal data on their profile page.
Permissions
Permissions are grouped as they appear in the invite and edit dialogs.
| Group | Permission | Grants |
|---|---|---|
| Administration | User Management | Admin → Users: invite, edit and delete users — within the limits below |
| Space Management | Admin → Spaces to create, update and delete spaces, plus each space's Settings, access tokens and webhooks | |
| Settings Management | Admin → Settings, the installation-wide settings | |
| Translation | Read, Create, Update, Delete | View and edit translations. Update also covers regenerating the draft and auto-translating a locale |
| Publish | Publish translations | |
| Export, Import | Run translation export and import tasks. Any export or import permission also opens Tasks | |
| Schema | Read, Create, Update, Delete | View and edit schemas |
| Export, Import | Run schema export and import tasks | |
| Content | Read, Create, Update, Delete | View and edit content. Read also lets the user read schemas and assets, which content forms need |
| Publish and Unpublish | Publish and unpublish content | |
| Export, Import | Run content export and import tasks | |
| Asset | Read, Create, Update, Delete | View, upload, edit and delete assets. Create also covers importing from Unsplash |
| Export, Import | Run asset export and import tasks | |
| Regenerate Metadata | Listed in the dialogs, but starting the task is reserved for admins — see Assets | |
| Development | Open API | Developers → Open API, the API specification generated from the space's schemas |
| Webhooks | Developers → Webhooks. Reading and editing webhooks also requires Space Management |
AI translation of a content field needs both Translation Update and Content Update.
Inviting Users
Click Invite and fill in the form:
| Field | Required | Description |
|---|---|---|
| ✅ | The address the user signs in with | |
| Password | ✅ | The initial password, at least 6 characters. Share it with the user yourself — Localess doesn't send an invitation email |
| Display Name | — | The name shown in the admin UI |
| Role | — | None, Custom, or Admin |
| Lock User | — | Shown for the Custom role — see Lock User |
| Permissions | — | Shown for the Custom role — tick each permission the user should have |
User Management Limits
Admins can manage any user and grant anything. A custom user with User Management can manage only users they fully outrank:
- not themselves
- not an admin
- not anyone holding a permission they don't hold themselves
For a user they can manage, they can set the role only to None or Custom — never Admin — and can grant only permissions they hold themselves. The ⋮ actions for any other user are disabled, with the tooltip "Only an admin can manage this user." The invite dialog applies the same limits: Admin isn't offered as a role, and permissions the inviter doesn't hold can't be ticked.
These limits are enforced on the server as well as in the UI, so user management can never be used to gain more access than the manager already has.
Webhooks
Receive real-time HTTP notifications when content, translations, or assets change in Localess — and trigger downstream systems automatically.
Access Tokens
Create per-space API tokens that grant your apps, servers and the CLI exactly the access they need — published or draft content and translations, or development tools.