# Permissions per team member: decide exactly who can do what — MijnEvent

  [Home](https://mijnevent.nl/en) / [Blog](https://mijnevent.nl/en/blog) / Permissions per team member: decide exactly who can do what   management team security 

# Permissions per team member: decide exactly who can do what

 Under Management → Team you set per team member what they can see and do: per section, per module, with separate sensitive permissions and — if you want — limited to a single event. Five templates give you a head start.

 [Jasper Koers](https://mijnevent.nl/en/author/jasper-koers) · 11 August 2026 · 4 min read 

  ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/rechten-per-teamlid-instellen.webp)  Photo: [Yvette de Wit](https://unsplash.com/@yvettedewit?utm_source=MijnEvent&utm_medium=referral) / [Unsplash](https://unsplash.com/?utm_source=MijnEvent&utm_medium=referral)     In short

- Under Management → Team → Permissions you set per team member what they can do: None, View or Manage, per section and per active module.
- Sensitive actions — refunds, erasing or exporting personal data, publishing, Mollie and the pricing plan — are separate switches you enable deliberately.
- With event access you limit a team member to one or a few events: lists, figures and exports then only show those events.
- New team members start with the Read-only template; the owner always has full access and everything is enforced server-side.

  A bar volunteer who accidentally issues a refund. An intern exporting the full attendee list. As long as everyone with dashboard access can do everything, every team member is a risk — not out of malice, but because one wrong click is enough. That's why the MijnEvent dashboard now works with permissions per team member: you decide who sees what, and who may do what.

# Five templates to start from

When you invite a new team member you pick a permission template right away: **Full management**, **Events**, **Finance**, **Marketing &amp; content** or **Read-only**. If you pick nothing, the new member starts with Read-only — looking around is fine, touching anything is not.

![When inviting you pick a permission template right away](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/inline/rechten-uitnodigen.webp)

A template is a starting point, not a straitjacket. After inviting you adjust everything per user; the label in the team list then changes to "Custom", so you can tell at a glance who has a standard profile and who has tailored access.

![The team list shows a permissions badge per member; the owner has a lock](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/inline/rechten-teamlijst.webp)

# The matrix: None, View or Manage

Click **Permissions** next to a team member and the permissions panel slides open. Every section of the dashboard — events, orders, invoices, gift cards, statistics, team, GDPR requests, settings, branding and the activity log — has three levels: **None** (invisible), **View** (read, change nothing) or **Manage** (everything).

![The permissions panel: None, View or Manage per section](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/inline/rechten-paneel-matrix.webp)

Below the core sections you'll find your active modules, with exactly the same three levels. A module that is enabled for your organisation is no longer automatically open to the whole team.

# Sensitive actions are enabled deliberately

Some actions deserve their own threshold, even for team members who can otherwise do a lot: issuing refunds, erasing or exporting personal data (GDPR), publishing events (which starts a payment), managing the Mollie connection and switching pricing plans. These live as separate switches in a highlighted block — and a switch only becomes available once the related section is at least set to View.

The same principle applies inside modules. Being able to see the city-card administration does not mean you can run a payout round or download the SEPA file for the bank: that is its own sub-permission. Sending mass mailings, starting an evacuation, paying out food-truck settlements and settling deposits are separate sub-permissions too.

![Modules with their sub-permissions and event access at the bottom of the panel](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/inline/rechten-paneel-modules.webp)

# Access to a single event

Working with a production lead per festival or a treasurer per edition? Then limit **event access**: instead of "all events" you select the events this team member may work on. Lists, orders, statistics, exports, attendee mailings and Terugblik then only show those events — even the revenue figures on the dashboard only count their own events. Organisation-wide sections such as settings and branding sit outside that restriction; you control those with the matrix.

# No permission? Then it's not there

The navigation only shows what a team member has permission for. Anyone who opens a direct link anyway — or just lost a permission — gets a clear message and lands on the first page that is allowed:

![Without permission: a clear message and back to a page that is allowed](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/inline/rechten-geen-toegang.webp)

More important than what the screen shows: the server checks every request itself. Even someone who bypasses the screens and calls the API directly gets no further than their permissions.

# Extra locks on the most dangerous actions

Three actions ask for more than a permission alone. Downloading a SEPA payment file, permanently erasing personal data and disconnecting Mollie require a **fresh two-factor code** — right before the action, even when you are already logged in. And city-card payout rounds follow the **four-eyes principle**: whoever creates the round cannot mark it as sent themselves; a second team member with payout permissions does that.

Every permission change is also written to the [activity log](/en/blog/the-activity-log-who-did-what), including exactly what changed. That log used to be owner-only; it is now an assignable permission as well — though deliberately part of no template, so the owner always grants it explicitly.

This way your team grows without handing out access you'd rather keep to yourself. Start broad or start narrow — adjusting is always two clicks.

   Frequently asked questions

## Frequently asked questions

## What can a new team member do by default?

  When inviting you pick a template; without a choice a new team member starts with Read-only. They can look around wherever you granted View, but change nothing.

## Can I change the owner's permissions?

  No. The owner always has full access — that's why the row shows a lock. An organisation can never lock itself out.

## What does a team member see of sections they have no permission for?

  Nothing: those sections disappear from the navigation. Anyone opening a direct link gets a clear message and lands on the first page they do have access to. The server refuses the request as well — what the screen shows is comfort, the control lives on the server.

## Does this apply to the organizer app too?

  Yes. On login the app receives the same permissions and the same event access, and the server enforces them on every request.

## Who may complete a city-card payout batch?

  Someone other than the person who created it: preparing and settling are deliberately separated (the four-eyes principle). Only the owner may do both, so one-person organisations stay workable.

  [    Back to blog ](https://mijnevent.nl/en/blog) 

  MijnEvent

## Read more

 [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/deelnemersgegevens-uitvragen-na-de-ticketverkoop.webp) attendee details 

 MijnEvent · 17 August 2026 · 13 min read

## The tickets are sold — and half your attendees are still a blank

Dietary needs, company names, weights: the details you only need after the sale rarely arrive on their own. Here is how to collect them without making eighteen phone calls.

 ](https://mijnevent.nl/en/blog/collecting-attendee-details-after-the-ticket-sale) [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/van-ideal-naar-wero-wat-verandert-er-voor-je-ticketverkoop.webp) payments 

 MijnEvent · 17 August 2026 · 7 min read

## From October your iDEAL payments run on Wero: what organisers need to know

In July the Dutch Payments Association announced the next step in the move from iDEAL to Wero. Your visitors will not notice a thing, and you probably will not either — but there are three things worth checking now.

 ](https://mijnevent.nl/en/blog/ideal-becomes-wero-what-changes-for-ticket-sales) [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/controleur-worden-app-installeren-en-testen.webp) steward 

 Jasper Koers · 15 August 2026 · 6 min read

## Scanning at the gate: install the app, prepare and test it together

You have been asked to scan tickets. Four steps get you ready: install the app, sign in with the code from your e-mail, download the event for offline use and test with a colleague that the same ticket really does turn red on the second phone.

 ](https://mijnevent.nl/en/blog/steward-at-the-gate-install-prepare-and-test) 

   MijnEvent

## Ready to get started?

Create a free account and sell your first tickets today.

 [Start free](https://mijnevent.nl/registreer) [Pricing](https://mijnevent.nl/en/pricing)
