> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tokensupply.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Accounts and roles

> How signing in works, and how roles and permissions decide what each teammate can do inside a store.

Your account is your personal identity on the platform. Roles then decide what you are allowed to do inside each store you belong to.

## Your account and signing in

You sign in once with your account, using your password, a one-time code sent to your email, or your Google or Discord account. New accounts confirm their email with a 6-digit code before they can sign in. From there you reach every store you own or have joined. Your account carries your name, your photo, and your sign-in details, and it stays the same no matter which store you are working in.

<Note>
  The account you sign in to for the admin app is separate from the accounts your buyers use. Buyers never sign in to manage your store, and delivery pages open without any login at all.
</Note>

## Roles decide what you can do

Inside a store, every teammate has a role. The role sets what that person can see and change. This lets you bring in help without handing over full control of your store. The built-in roles are Owner, Admin, Support, and Vendor, and a role belongs to one store: the same person can be an Admin in one store and Support in another.

<Steps>
  <Step title="The owner has full control">
    Whoever creates a store owns it. The owner can manage everything, including the team and billing.
  </Step>

  <Step title="Admins manage the store">
    Admins can run day-to-day operations across products, orders, and settings. Only the owner can make someone an Admin.
  </Step>

  <Step title="Focused roles do specific jobs">
    A support teammate, for example, can handle tickets without touching your catalog or billing.
  </Step>

  <Step title="Vendors work in their own portal">
    Vendors who supply you get the Vendor role. They work in the Vendor Portal on their offers, the purchase orders you send them, and their tickets.
  </Step>

  <Step title="Custom roles fit your team">
    You can build your own roles and choose, area by area, whether a person can view, manage, or not see it at all.
  </Step>
</Steps>

<Note>
  An invite is tied to the email address it was sent to. Only someone signed in with that email can accept it, so a forwarded link cannot give anyone else access.
</Note>

## Permissions are enforced everywhere

A role is not just a label in the app. When a teammate tries to do something, our servers check their permissions before allowing it. If their role does not include an area, the app hides the controls for it and the action is refused even if they try to reach it another way.

<Tip>
  Give each teammate the smallest role that lets them do their job. You can always widen it later, and it keeps sensitive areas like billing and inventory protected.
</Tip>

<CardGroup cols={2}>
  <Card title="Your account" icon="users" href="/guides/getting-started/your-account">
    Manage your sign-in, profile, and security.
  </Card>

  <Card title="Team and roles" icon="users" href="/guides/getting-started/team-and-roles">
    Invite teammates and assign roles.
  </Card>

  <Card title="Stores and multi-tenancy" icon="store" href="/how-it-works/stores-and-multi-tenancy">
    How one account works across several stores.
  </Card>

  <Card title="Security and your data" icon="shield" href="/how-it-works/security-and-data">
    How access and data are kept safe.
  </Card>
</CardGroup>
