Skip to content

Sign in, roles, and administrator access

New staging website. These steps apply to https://beti.worldyogaalliance.org/admin and its protected pages. The legacy Django admin is separate; see the legacy inventory.

Use this guide for the new staging administrator workspace at https://beti.worldyogaalliance.org/admin. You need an active WYA administrator account. A normal member account is deliberately rejected: the login page says Member accounts cannot access this area. Ask an authorized superuser to create or enable an administrator account when you do not have one. Never share a password or access token in a support note.

The administrator workspace has its own session and the visible signed-in block shows the administrator’s display name and email. It is separate from the member sign-in at /auth/login.

  1. Open the staging /admin route. If there is no valid administrator session, the site sends you to /admin/login.
  2. Confirm the heading is Sign in to WYA Admin and the page text says Use your administrator account. Member accounts cannot access this area.
  3. Enter the administrator’s value in Email or username.
  4. Enter the password in Password and select Sign in.
  5. A valid session opens /admin, which shows Admin workspace and the overview. If the session is not accepted, the page shows Invalid administrator credentials. For a temporary service problem it shows Unable to sign in right now.

If you arrived from the member area, use Return to member sign-in to go to /auth/login. Do not use the member form as an administrator recovery flow.

The shell uses these concepts in the account summary and user table:

  • Superuser access means the administrator can use superuser-only actions such as managing administrator accounts, roles, member-account access, and the highest-impact cache action.
  • Staff / administrator access allows the staff workflows exposed by the workspace. Every staff action still requires an active administrator account.
  • Active and Inactive describe a member account in the Users view. They are separate from whether the administrator account itself is active.
  • A member row can show Superuser, Staff, Active, or Inactive. These are access flags, not a replacement for the administrator login.

The application rejects a missing, inactive, or wrong-kind session before a protected page is rendered. A 401/403 response means the session or permission is not sufficient; sign in again or ask a superuser to perform that action.

Use People and directory → Users. Only a superuser sees the write controls.

  1. Select Add member.
  2. Complete Username, Email, First name, Last name, Phone number, and Initial password.
  3. Keep the initial password between 8 and 128 characters and provide it through an approved private channel to the member. Do not record it in the documentation.
  4. Select Create member. The account is created as an active member without staff or superuser access.
  1. Open the member row and select Edit member account.
  2. In the details form, edit Username, Email, First name, Last name, or Phone number, then select Save member details.
  3. Use Active member, Legacy staff, and Legacy superuser only when the access decision is approved. Select Save access.
  4. To rotate the member password, enter New password and select Change password.

Changing username or email revokes active member sessions. Saving access or a new password revokes all member sessions. Tell the member to sign in again after those actions.

From the user list, a superuser can select Disable user or Enable user. Delete unused member is reserved for an account with no linked history. When an account is linked to directory or transaction records, deactivate it to preserve history; do not try to delete it just to hide it.

Use System → Admin accounts. This screen is superuser-only and creates an administrator account, not a member account.

  1. Select Create administrator.
  2. Enter Username, Email, Display name, and Temporary password.
  3. The temporary password must be at least 12 characters and meet the password policy shown by the form. Handle it as a temporary secret and rotate it through the approved process.
  4. Select Grant superuser access only when the person needs superuser actions.
  5. Select Create administrator and confirm the new row shows the intended Active and Superuser / Administrator status.

The list has Disable account or Enable account. You cannot disable your own current administrator account. An inactive account cannot use the workspace.

Use Authentication and Authorization → Groups (the screen opens /admin/system?view=roles). The page manages administrator roles; role changes are superuser-only.

  1. Select Add role.
  2. Enter Role name.
  3. Select one or more values in Permissions. The control supports Ctrl-click or Cmd-click for multiple values.
  4. Select Add role.
  5. To change an existing role, select Edit, update the same fields, and select Save changes.
  6. To remove a role, select Delete and confirm. The confirmation warns that member assignments are removed.

Check the role’s member count and permissions before deleting it. Role membership changes affect access immediately and are recorded as administrator activity.

If the page returns you to Sign in to WYA Admin, sign in again. If a screen is visible but a write control is unavailable, ask a superuser to perform the action or grant the approved role. A denied action is not a reason to retry a destructive change. The workspace checks that the administrator account is active and that the account type is administrator; member accounts cannot use this area.