@extends('layouts.portal') @section('title', 'Team & roles') @section('subtitle', 'Who can open which part of the back office. Every change is written to the audit log.') @section('content') @php $roleLabels = collect(config('rbac.roles'))->map(fn ($r) => $r[0]); @endphp

Add a team member

@csrf

They get a set-password email. Two-factor authentication is required before they can use the back office.

Roles

@foreach(config('rbac.roles') as $k => [$label, $desc])
{{ $label }} — {{ $desc }}
@endforeach

Back-office team ({{ $staff->count() }})

@foreach($staff as $m) @endforeach
NameRole & status2FALast sign-inChange
{{ $m->name }}@if($m->id === auth()->id()) you@endif
{{ $m->email }}
{{ $m->roleLabel() }} @if($m->isSuspended())Suspended@endif @if($m->hasTwoFactor())On@elseNot set up@endif {{ $m->last_login_at?->diffForHumans() ?? 'Never' }} @if($m->id !== auth()->id() && (! $m->isSuperAdmin() || auth()->user()->isSuperAdmin()))
@csrf @method('PUT')
@if($canEdit && $m->hasTwoFactor())
@csrf
@endif @endif

Permission matrix

@if($canEdit)
@csrf
@endif
@csrf @method('PUT')
@foreach($roles as $r)@endforeach @foreach($modules as $mod => [$label, $group]) @foreach($roles as $r) @endforeach @endforeach
Module{{ $roleLabels[$r] }}
{{ $label }}
{{ $group }}
@if($r === 'super_admin')all @else @foreach(['view' => 'V', 'manage' => 'M'] as $act => $short) @endforeach @endif
@if($canEdit)
V = view, M = create / edit / send / delete. Only a Super Admin can change this.
@endif
@endsection