Role-Based Guides
SHM is role-aware. Root administrators, resellers, account users, support staff, and API users should not all receive the same operating surface.
Where to find it: Documentation > Hosting Manager > Role-Based Guides.
Available to: Anyone reading the public documentation. The related SHM action still follows the role stated on its page.
What this page does
This guide explains who should use each SHM role, what that role is normally responsible for, and which actions require extra care. It is written for customer onboarding, staff training, reseller enablement, and support escalation.
Before you start
Examples use placeholder accounts, domains, addresses, and credentials. Replace them deliberately, and never paste passwords, API keys, tokens, or private keys into tickets or shared notes.
Why use it — and when not to
Use Role-Based Guides to understand or plan the supported workflow. Do not treat an example as authorization or as proof of the current state on a particular SHM server.
Role Matrix
| Role | Can access | Should not do | Typical tasks | Security notes |
|---|---|---|---|---|
| Root administrator | Server dashboards, account provisioning, all accounts, services, firewall, security, packages, reseller controls, backups, logs, license, version/update pages, and full customer API scope. | Use root for routine customer self-service tasks when a narrower role is enough. | Configure platform policy, create packages, create accounts, manage services, troubleshoot incidents, review logs/audit, maintain backups, and govern API/security. | Protect with strong passwords, 2FA, IP restrictions where possible, careful API key handling, and change review for high-impact actions. |
| Reseller | Delegated account list, customer account workflows, allowed packages/features, and account-scoped support tools for owned customers. | Change server-wide services, global firewall policy, root-only settings, unrelated reseller accounts, or provider-level license/update state. | Create/manage downstream accounts, review usage, support customers, suspend/unsuspend according to policy, and escalate provider-level issues. | Keep reseller capacity, shell access, IP allocation, and package boundaries strict. |
| Account user / client | Own account dashboard, domains, DNS where allowed, mail, FTP, databases, files, SSL, cron, resource usage, logs, backups, security settings, and AI Assistant when enabled. | Manage other customers, server-wide configuration, provider firewall, package definitions, or global services. | Maintain website files, mailboxes, databases, SSL, DNS records, backups, resource checks, and support diagnosis. | Use strong credentials, avoid sharing passwords/API keys, and verify target domain/path before changing live website resources. |
| Support/operator | The pages needed for assigned support duties, usually logs, diagnostics, account dashboard, List Accounts, DNS, SSL, mail, databases, files, backups, and AI Assistant. | Perform destructive account deletion, broad package changes, or service restarts without authorization. | Investigate tickets, collect evidence, guide customers, apply safe fixes, and escalate with context. | Work from evidence, document changes, and use least privilege for daily operations. |
| API-only integration user | Documented customer-facing API endpoints allowed by the key role, scope, and source IP policy. | Use browser-only internal routes, private AI/channel worker routes, or broad root keys for narrow automation. | Billing/provisioning automation, support dashboards, monitoring checks, account updates, DNS/SSL/database workflows, and reporting. | Use scoped keys, IP allowlists, rotation, request logging, and safe placeholder handling in examples and tickets. |
| AI-assisted user | AI Assistant and AI Mode features allowed by the current role and feature policy. | Assume AI output has already changed infrastructure or bypasses permission rules. | Ask for diagnosis, repair guidance, configuration review, bug investigation, log interpretation, and next-step support recommendations. | Treat AI as guided assistance; verify actions in the relevant SHM page and do not paste secrets into prompts. |
Access Recommendations
- Use root only for platform-wide or emergency work.
- Use reseller accounts for delegated commercial operations.
- Use account users for customer self-service inside their hosting account.
- Use named support/operator identities instead of shared credentials.
- Use API-only users for automation and restrict them by role, ownership, and source IP.
- Review permissions after staff changes, reseller plan changes, customer handover, and incident response.
How to use it
- Identify whether the task is server-wide, reseller-scoped, or limited to one account.
- Open the page that owns the resource instead of using a nearby page with a similar name.
- Read the page-specific prerequisites and impact before changing anything.
- Verify the result in SHM and from the customer-facing service.
Result and next check
Reading this page changes nothing in SHM. Follow the linked workflow only after confirming the role, target, and expected impact.
Theme color