Localess

Users & Permissions

Invite your team to Localess and control what each member can see and change with roles and fine-grained permissions.

Every person who signs in to the Localess admin UI is a user. A user's role decides whether they have full access or only the permissions granted to them. Roles and permissions apply to the whole installation — every space, not one space at a time.

Main Screen

Navigate to Admin → Users from the side menu. The entry is shown to admins and to users with the User Management permission.

The table lists every user with their email (a shield icon marks a verified address), name, whether the account is active, sign-in providers, role, and creation and update dates. For a custom user, hover the info icon next to the role to see their permissions; a lock icon marks a locked user. Search by email or name, or filter by Active.

ActionDescription
InviteCreate a new user — see Inviting Users
SyncCopy accounts and their roles from Firebase Authentication into the list. Use it when a user — one you just invited, or one created in the Firebase console — is missing or shows an outdated role
⋮ → EditChange the user's role, permissions and lock
⋮ → DeleteDelete the user and their sign-in account

Roles

RoleAccess
AdminEverything, in every space, including everything no permission covers
CustomOnly the permissions ticked for the user
NoneCan sign in, but can't open any space

Changes to a user's role or permissions apply when their sign-in session refreshes; signing out and back in applies them immediately.

Lock User

A custom user can also be locked. A locked user can't change their own password or other personal data on their profile page.

Permissions

Permissions are grouped as they appear in the invite and edit dialogs.

GroupPermissionGrants
AdministrationUser ManagementAdmin → Users: invite, edit and delete users — within the limits below
Space ManagementAdmin → Spaces to create, update and delete spaces, plus each space's Settings, access tokens and webhooks
Settings ManagementAdmin → Settings, the installation-wide settings
TranslationRead, Create, Update, DeleteView and edit translations. Update also covers regenerating the draft and auto-translating a locale
PublishPublish translations
Export, ImportRun translation export and import tasks. Any export or import permission also opens Tasks
SchemaRead, Create, Update, DeleteView and edit schemas
Export, ImportRun schema export and import tasks
ContentRead, Create, Update, DeleteView and edit content. Read also lets the user read schemas and assets, which content forms need
Publish and UnpublishPublish and unpublish content
Export, ImportRun content export and import tasks
AssetRead, Create, Update, DeleteView, upload, edit and delete assets. Create also covers importing from Unsplash
Export, ImportRun asset export and import tasks
Regenerate MetadataListed in the dialogs, but starting the task is reserved for admins — see Assets
DevelopmentOpen APIDevelopers → Open API, the API specification generated from the space's schemas
WebhooksDevelopers → Webhooks. Reading and editing webhooks also requires Space Management

AI translation of a content field needs both Translation Update and Content Update.

Inviting Users

Click Invite and fill in the form:

FieldRequiredDescription
Email✅The address the user signs in with
Password✅The initial password, at least 6 characters. Share it with the user yourself — Localess doesn't send an invitation email
Display Name—The name shown in the admin UI
Role—None, Custom, or Admin
Lock User—Shown for the Custom role — see Lock User
Permissions—Shown for the Custom role — tick each permission the user should have

User Management Limits

Admins can manage any user and grant anything. A custom user with User Management can manage only users they fully outrank:

  • not themselves
  • not an admin
  • not anyone holding a permission they don't hold themselves

For a user they can manage, they can set the role only to None or Custom — never Admin — and can grant only permissions they hold themselves. The ⋮ actions for any other user are disabled, with the tooltip "Only an admin can manage this user." The invite dialog applies the same limits: Admin isn't offered as a role, and permissions the inviter doesn't hold can't be ticked.

These limits are enforced on the server as well as in the UI, so user management can never be used to gain more access than the manager already has.

On this page