Roles and navigation
SHM navigation is built from authority, ownership, feature policy, and installed services. Two users can sign in to the same server and correctly see different menus.
Where to find it: Documentation > Hosting Manager > Roles and navigation.
Available to: Anyone reading the public documentation. The related SHM action still follows the role stated on its page.
What this page does
This page explains the three role boundaries and why a missing menu item is often a policy decision rather than a display problem. Root controls the platform, resellers control delegated accounts, and account users control their own hosting resources.
Before you start
Never solve a permission problem by sharing broader credentials. First verify the signed-in identity, the selected account, reseller ownership, package, feature profile, and service availability.
Role matrix
| Role | Can manage | Cannot normally manage |
|---|---|---|
| Root | The server, all accounts, resellers, services, security, backups, configuration, license, updates, and root API. | Nothing outside the product's supported server scope; external registrars and third-party platforms remain separate. |
| Reseller | Owned accounts, approved packages and features, account DNS/SSL, logs, audit, ModSecurity, and account support workflows. | Unowned accounts, global services, root security, license, updates, firewall, or unrestricted server configuration. |
| Account user | Resources belonging to their own account and enabled by the plan. | Another account, reseller capacity, global services, or server-wide policy. |
Selected account context
Root and resellers can open an authorized account from List Accounts. The account menu then operates on that selected account; the breadcrumb and account identity are not decoration, so check them before editing a domain, mailbox, database, file, or application.
Why a menu item may be absent
- The feature profile does not include it.
- The account package or reseller policy does not permit it.
- The required server component is not enabled in Services.
- A conditional tool, such as phpMyAdmin or pgAdmin, has no usable database context yet.
- The signed-in reseller does not own the selected account.
AI Mode
Root and resellers can use the server AI workspace inside their own authority. Account AI appears only when it is enabled for that account. AI requests still pass through normal role, ownership, endpoint, and feature checks; a conversational interface is not a permission bypass.
How to use it
- Confirm the signed-in username and role.
- For account work, confirm the selected account and owner.
- Check the assigned package and feature profile.
- Check Services when a feature depends on an installed component.
- Use a broader role only when the task genuinely belongs to that broader scope.
Result and next check
The user sees only the navigation and resources allowed by the current role and account context. If a valid assignment changes, reload the account context and confirm the menu again.
Theme color