Before assigning module-specific roles below, make sure your organization's account setup follows these platform-wide guidelines.
Use Single Sign-On (SSO) — recommended. SSO lets your team log in with your company's existing identity provider (e.g. Okta, Azure AD, Google Workspace) instead of a separate EventChain password. It's recommended because access is centrally managed: when someone joins or leaves the company, their EventChain access is automatically granted or revoked through the identity provider, and there's no extra password to manage, forget, or have phished.
Enforce SSO-only sign-up. SSO can be locked as the only path for adding new users, so no one can be added manually once it's turned on.
Allowed domains - also recommended. You can restrict sign-up and SSO login to a list of allowed email domains (e.g. only @yourcompany.com), so only people with a company email can join.
Audit logging — also recommended. All user actions are logged and can be ingested into your own logging or SIEM tooling, giving you a full audit trail of who did what and when.
If SSO isn't used. Only users with the Application Owner or Auditor role can add, edit, or remove other users' access. Any manual change made to a user is recorded on that user's profile — who made the change and when — so there's still a clear audit trail.
Access to the Commercial module is role-based, covering CRM records, catering and ticketing flows, finance approvals, and downstream distribution. Use this guide to understand each role before assigning access to a team member.
Venue Admin — Full access across the CRM structure and ownership grid, catering and ticketing flows, finance interactions, and downstream distribution. Can reassign contact or account ownership mabe event bulld and allocations.
Sales / Account Admin — Can manage their own assigned accounts where they designated as owner, Can view reports for their own accounts. Cannot reassign ownership of other accounts.
Catering / Service Admin - added as separate tenant that shares flows across tenants- no access to a tennants application data or actions.
Finance Admin — Can review and approve event-ids, integrations and logs.
Designer Admin - can only access the design centre.
Viewer/Reports — Read-only access to CRM records, catering and ticketing flows, and distribution reports. **In review due to AI reporting rebuild
A Commercial Admin assigns access from Settings > users by selecting a team member and choosing their Commercial module role. Changes take effect immediately, and a member's role can be changed or revoked at any time.