# Permissions per team member: decide exactly who can do what

  [Home](https://mijnevent.nl/en) / [Blog](https://mijnevent.nl/en/blog) / Permissions per team member: decide exactly who can do what   management team security 

# Permissions per team member: decide exactly who can do what

 Under Management → Team you set per team member what they can see and do: per section, per module, with separate sensitive permissions and — if you want — limited to a single event. Five templates give you a head start.

 [Jasper Koers](https://mijnevent.nl/en/author/jasper-koers) · 11 August 2026 · 4 min read 

  ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/rechten-per-teamlid-instellen.webp)  Photo: [Yvette de Wit](https://unsplash.com/@yvettedewit?utm_source=MijnEvent&utm_medium=referral) / [Unsplash](https://unsplash.com/?utm_source=MijnEvent&utm_medium=referral)     In short

- Under Management → Team → Permissions you set per team member what they can do: None, View or Manage, per section and per active module.
- Sensitive actions — refunds, erasing or exporting personal data, publishing, Mollie and the pricing plan — are separate switches you enable deliberately.
- With event access you limit a team member to one or a few events: lists, figures and exports then only show those events.
- New team members start with the Read-only template; the owner always has full access and everything is enforced server-side.

  A bar volunteer who accidentally issues a refund. An intern exporting the full attendee list. As long as everyone with dashboard access can do everything, every team member is a risk — not out of malice, but because one wrong click is enough. That's why the MijnEvent dashboard now works with permissions per team member: you decide who sees what, and who may do what.

# Five templates to start from

When you invite a new team member you pick a permission template right away: **Full management**, **Events**, **Finance**, **Marketing &amp; content** or **Read-only**. If you pick nothing, the new member starts with Read-only — looking around is fine, touching anything is not.

![When inviting you pick a permission template right away](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/inline/rechten-uitnodigen.webp)

A template is a starting point, not a straitjacket. After inviting you adjust everything per user; the label in the team list then changes to "Custom", so you can tell at a glance who has a standard profile and who has tailored access.

![The team list shows a permissions badge per member; the owner has a lock](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/inline/rechten-teamlijst.webp)

# The matrix: None, View or Manage

Click **Permissions** next to a team member and the permissions panel slides open. Every section of the dashboard — events, orders, invoices, gift cards, statistics, team, GDPR requests, settings, branding and the activity log — has three levels: **None** (invisible), **View** (read, change nothing) or **Manage** (everything).

![The permissions panel: None, View or Manage per section](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/inline/rechten-paneel-matrix.webp)

Below the core sections you'll find your active modules, with exactly the same three levels. A module that is enabled for your organisation is no longer automatically open to the whole team.

# Sensitive actions are enabled deliberately

Some actions deserve their own threshold, even for team members who can otherwise do a lot: issuing refunds, erasing or exporting personal data (GDPR), publishing events (which starts a payment), managing the Mollie connection and switching pricing plans. These live as separate switches in a highlighted block — and a switch only becomes available once the related section is at least set to View.

The same principle applies inside modules. Being able to see the city-card administration does not mean you can run a payout round or download the SEPA file for the bank: that is its own sub-permission. Sending mass mailings, starting an evacuation, paying out food-truck settlements and settling deposits are separate sub-permissions too.

![Modules with their sub-permissions and event access at the bottom of the panel](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/inline/rechten-paneel-modules.webp)

# Access to a single event

Working with a production lead per festival or a treasurer per edition? Then limit **event access**: instead of "all events" you select the events this team member may work on. Lists, orders, statistics, exports, attendee mailings and Terugblik then only show those events — even the revenue figures on the dashboard only count their own events. Organisation-wide sections such as settings and branding sit outside that restriction; you control those with the matrix.

# No permission? Then it's not there

The navigation only shows what a team member has permission for. Anyone who opens a direct link anyway — or just lost a permission — gets a clear message and lands on the first page that is allowed:

![Without permission: a clear message and back to a page that is allowed](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/inline/rechten-geen-toegang.webp)

More important than what the screen shows: the server checks every request itself. Even someone who bypasses the screens and calls the API directly gets no further than their permissions.

# Extra locks on the most dangerous actions

Three actions ask for more than a permission alone. Downloading a SEPA payment file, permanently erasing personal data and disconnecting Mollie require a **fresh two-factor code** — right before the action, even when you are already logged in. And city-card payout rounds follow the **four-eyes principle**: whoever creates the round cannot mark it as sent themselves; a second team member with payout permissions does that.

Every permission change is also written to the [activity log](/en/blog/the-activity-log-who-did-what), including exactly what changed. That log used to be owner-only; it is now an assignable permission as well — though deliberately part of no template, so the owner always grants it explicitly.

This way your team grows without handing out access you'd rather keep to yourself. Start broad or start narrow — adjusting is always two clicks.

   Frequently asked questions

## Frequently asked questions

## What can a new team member do by default?

  When inviting you pick a template; without a choice a new team member starts with Read-only. They can look around wherever you granted View, but change nothing.

## Can I change the owner's permissions?

  No. The owner always has full access — that's why the row shows a lock. An organisation can never lock itself out.

## What does a team member see of sections they have no permission for?

  Nothing: those sections disappear from the navigation. Anyone opening a direct link gets a clear message and lands on the first page they do have access to. The server refuses the request as well — what the screen shows is comfort, the control lives on the server.

## Does this apply to the organizer app too?

  Yes. On login the app receives the same permissions and the same event access, and the server enforces them on every request.

## Who may complete a city-card payout batch?

  Someone other than the person who created it: preparing and settling are deliberately separated (the four-eyes principle). Only the owner may do both, so one-person organisations stay workable.

  [    Back to blog ](https://mijnevent.nl/en/blog) 

  MijnEvent

## Read more

 [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/evenement-2027-aanmelden-evenementenkalender.webp) permits 

 MijnEvent · 28 September 2026 · 6 min read

## Planning an event in the Netherlands in 2027? Many towns want it on their calendar by 1 October

This week, a string of Dutch municipalities close registration for their 2027 events calendar. It isn't a permit application, but it is where your date gets locked in — and latecomers go to the back of the queue with police and emergency services.

 ](https://mijnevent.nl/en/blog/event-2027-municipal-events-calendar-deadline) [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/besloten-ticketverkoop-met-toegangscode.webp) private sales 

 Jasper Koers · 22 September 2026 · 5 min read

## Private ticket sales: an event that can only be ordered with a code

The staff party, the tickets for sponsors, the group booking of a travel company: you want to handle them online, but not among your regular events. With an access code the event cannot be found, and only the people you invite can order.

 ](https://mijnevent.nl/en/blog/private-ticket-sales-with-an-access-code) [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/rustige-ticketshop-event-groepen-en-ticketgroepen.webp) ticket shop 

 Jasper Koers · 22 September 2026 · 6 min read

## Many events, still a calm ticket shop

Three festival days, camping, parking and a row of separate events: your ticket shop quickly turns into a long list of prices. With event groups, collapsed ticket groups and a notice in the right place, your visitor chooses step by step.

 ](https://mijnevent.nl/en/blog/calm-ticket-shop-event-groups-and-ticket-groups) 

   MijnEvent

## Ready to get started?

Create a free account and sell your first tickets today.

 [Start free](https://mijnevent.nl/registreer) [Pricing](https://mijnevent.nl/en/pricing)
