Sign in, roles, and administrator access
New staging website. These steps apply to
https://beti.worldyogaalliance.org/adminand its protected pages. The legacy Django admin is separate; see the legacy inventory.
Scope and prerequisites
Section titled “Scope and prerequisites”Use this guide for the new staging administrator workspace at https://beti.worldyogaalliance.org/admin. You need an active WYA administrator account. A normal member account is deliberately rejected: the login page says Member accounts cannot access this area. Ask an authorized superuser to create or enable an administrator account when you do not have one. Never share a password or access token in a support note.
The administrator workspace has its own session and the visible signed-in block shows the administrator’s display name and email. It is separate from the member sign-in at /auth/login.
Sign in
Section titled “Sign in”- Open the staging
/adminroute. If there is no valid administrator session, the site sends you to/admin/login. - Confirm the heading is
Sign in to WYA Adminand the page text saysUse your administrator account. Member accounts cannot access this area. - Enter the administrator’s value in
Email or username. - Enter the password in
Passwordand selectSign in. - A valid session opens
/admin, which showsAdmin workspaceand the overview. If the session is not accepted, the page showsInvalid administrator credentials.For a temporary service problem it showsUnable to sign in right now.
If you arrived from the member area, use Return to member sign-in to go to /auth/login. Do not use the member form as an administrator recovery flow.
Access levels in the workspace
Section titled “Access levels in the workspace”The shell uses these concepts in the account summary and user table:
Superuser accessmeans the administrator can use superuser-only actions such as managing administrator accounts, roles, member-account access, and the highest-impact cache action.Staff/ administrator access allows the staff workflows exposed by the workspace. Every staff action still requires an active administrator account.ActiveandInactivedescribe a member account in theUsersview. They are separate from whether the administrator account itself is active.- A member row can show
Superuser,Staff,Active, orInactive. These are access flags, not a replacement for the administrator login.
The application rejects a missing, inactive, or wrong-kind session before a protected page is rendered. A 401/403 response means the session or permission is not sufficient; sign in again or ask a superuser to perform that action.
Create or update a member account
Section titled “Create or update a member account”Use People and directory → Users. Only a superuser sees the write controls.
Create a member
Section titled “Create a member”- Select
Add member. - Complete
Username,Email,First name,Last name,Phone number, andInitial password. - Keep the initial password between 8 and 128 characters and provide it through an approved private channel to the member. Do not record it in the documentation.
- Select
Create member. The account is created as an active member without staff or superuser access.
Edit a member
Section titled “Edit a member”- Open the member row and select
Edit member account. - In the details form, edit
Username,Email,First name,Last name, orPhone number, then selectSave member details. - Use
Active member,Legacy staff, andLegacy superuseronly when the access decision is approved. SelectSave access. - To rotate the member password, enter
New passwordand selectChange password.
Changing username or email revokes active member sessions. Saving access or a new password revokes all member sessions. Tell the member to sign in again after those actions.
Disable or remove a member
Section titled “Disable or remove a member”From the user list, a superuser can select Disable user or Enable user. Delete unused member is reserved for an account with no linked history. When an account is linked to directory or transaction records, deactivate it to preserve history; do not try to delete it just to hide it.
Create an administrator account
Section titled “Create an administrator account”Use System → Admin accounts. This screen is superuser-only and creates an administrator account, not a member account.
- Select
Create administrator. - Enter
Username,Email,Display name, andTemporary password. - The temporary password must be at least 12 characters and meet the password policy shown by the form. Handle it as a temporary secret and rotate it through the approved process.
- Select
Grant superuser accessonly when the person needs superuser actions. - Select
Create administratorand confirm the new row shows the intendedActiveandSuperuser/Administratorstatus.
The list has Disable account or Enable account. You cannot disable your own current administrator account. An inactive account cannot use the workspace.
Create and manage roles
Section titled “Create and manage roles”Use Authentication and Authorization → Groups (the screen opens /admin/system?view=roles). The page manages administrator roles; role changes are superuser-only.
- Select
Add role. - Enter
Role name. - Select one or more values in
Permissions. The control supports Ctrl-click or Cmd-click for multiple values. - Select
Add role. - To change an existing role, select
Edit, update the same fields, and selectSave changes. - To remove a role, select
Deleteand confirm. The confirmation warns that member assignments are removed.
Check the role’s member count and permissions before deleting it. Role membership changes affect access immediately and are recorded as administrator activity.
When access fails
Section titled “When access fails”If the page returns you to Sign in to WYA Admin, sign in again. If a screen is visible but a write control is unavailable, ask a superuser to perform the action or grant the approved role. A denied action is not a reason to retry a destructive change. The workspace checks that the administrator account is active and that the account type is administrator; member accounts cannot use this area.