ZeroPress Logo ZeroPress Studio Docs

Access Control

Roles & Capabilities

Studio assigns each account exactly one fixed system role: Administrator, Editor, or Author. A capability names a bounded product operation; possessing a capability does not bypass resource ownership, service availability, database lifecycle, same-origin, CSRF, or reauthentication checks.

Capability matrix

Capability Administrator Editor Author
audit.read Yes — —
users.manage Yes — —
authors.manage Yes — —
media.read Yes Yes Yes
media.manage Yes Yes —
taxonomies.manage Yes Yes —
posts.contribute Yes Yes Yes
posts.manage Yes Yes —
pages.manage Yes Yes —
menus.manage Yes Yes —
widgets.manage Yes Yes —
comments.manage Yes Yes —
forms.manage Yes Yes —
newsletters.manage Yes — —
newsletters.export Yes — —
imports.manage Yes — —
settings.manage Yes — —
publish.manage Yes — —

What the capabilities mean

Capability Permitted work
audit.read Read and filter major administrative activity and connection details in Audit Log
users.manage Invite users, reissue or cancel invitations, and manage account role, status, access recovery, and deletion workflows
authors.manage Create and manage public Author profiles and their optional account links
media.read Read and preview existing Media and collections for bounded selectors such as the Post editor
media.manage Open the Media workspace and create, upload, edit, organize, move, or delete Media metadata and managed objects through supported workflows
taxonomies.manage Manage Categories and Tags
posts.contribute Enter the Post workspace and use the Post create, edit, autosave, revision, and lifecycle APIs within the account’s Post scope
posts.manage Manage Posts across all Authors and use the all-Post filters and assignment controls
pages.manage Create and manage Pages
menus.manage Create and manage navigation menus and menu items
widgets.manage Create and manage Widget areas and Widget items
comments.manage Read, author, reply to, moderate, trash, and delete comments through Studio
forms.manage Manage Forms, submissions, and supported notification operations
newsletters.manage Manage Newsletter runtime configuration, fields, subscriptions, and suppressions
newsletters.export Export Newsletter subscription data through the dedicated export boundary
imports.manage Run the Studio WordPress WXR import workflow
settings.manage Manage site, output, URL, branding, custom-code, Edge, mail, and other administrative settings
publish.manage Prepare, copy, and download validated Preview Data; compare and publish it to the connected GitHub file

Role behavior

Administrator

An Administrator receives every Studio capability. This is the only role that can manage accounts and public Author profiles, configure the site and service settings, run imports, manage Newsletters, publish site data, or read Audit Log.

Administrator does not mean infrastructure superuser. Site modes, database lifecycle, Worker bindings, public Edge feature gates, and the protected Maintenance & Recovery boundary remain independently enforced.

Editor

An Editor can manage all Posts and Pages, existing Media, Categories and Tags, Menus, Widgets, comments, and Forms. Editors can assign existing public Author profiles to Posts, but cannot create or alter those profiles because authors.manage remains Administrator-only.

Editors cannot manage users, site settings, imports, Newsletters, site publishing, or Audit Log.

Author

An Author receives posts.contribute and media.read only. Post access is not available until an Administrator links the account to one public Author profile. After linking, the Author can create and manage only Posts owned by that profile and cannot transfer a Post to another Author.

media.read lets an Author find, preview, and select existing Media while editing an owned Post. It does not grant access to the Media management workspace and does not permit upload, registration, metadata changes, collection changes, or deletion.

Authors cannot manage Pages, public Author profiles, taxonomies, Menus, Widgets, comments, Forms, Newsletters, users, settings, imports, or Preview Data export.

Capability is necessary but not always sufficient

  • Comments, Forms, and Newsletters also depend on Studio Edge integration and the corresponding Edge database and runtime configuration.
  • Managed Media upload and preview depend on the required R2 binding and Media delivery configuration.
  • Preview Data export can fail closed when required Edge target projection is pending or inconsistent.
  • Mutations still require an authenticated session, exact same-origin request, CSRF proof, and any operation-specific password or MFA step-up.
  • Maintenance & Recovery uses its own operator boundary rather than this role matrix.

These additional checks can reduce access. They never grant a capability that the account’s role does not have.

For authentication policies and infrastructure restrictions, see Authentication and Cloudflare Access.