Go to AdminVenues[venue]Team to manage who has access to your venue. You need the canManageUsers capability to add or remove staff.

Two roles
Noctern has two roles for venue staff:
| Role | Default access | |---|---| | Venue admin | Full access to events, patrons, reports, and settings | | Box office | Can sell tickets and check in guests — cannot view patrons, reports, or settings |
Capability flags
On top of the base role, each staff member can be granted or denied specific capabilities:
| Capability | What it unlocks |
|---|---|
| canRefund | Process card refunds and issue credit notes |
| canExport | Download CSV/XLSX reports and attendee lists |
| canEditSettings | Edit venue profile and season settings |
| canManageUsers | Add, remove, and update other staff members |
| canViewDonors | Access patron giving history and fundraising data |
Box-office staff have all capabilities set to off by default. Venue admins have all capabilities set to on by default.
Adding a staff member
- Go to AdminVenues[venue]Team.
- Click Add team member.
- Search by the person's email address. They must already have a Noctern account.
- Select a Role (venue admin or box office).
- Check or uncheck capability flags as needed.
- Click Add. The person receives access immediately.
Removing a staff member
Click Remove next to a staff member's row. Their venue access is revoked immediately. Any active session they have may stay alive until it expires (up to 14 days), but they cannot start new sessions.
Two-factor authentication
The Require two-factor authentication toggle enforces MFA for all venue staff. Turning it on signs out all existing staff sessions. Each person must set up an authenticator app the next time they sign in.
Coming soon: MFA enrollment UI in the staff profile settings.
The venue owner (the account that created the venue) always has full access regardless of grant settings. Super-admin accounts bypass all capability checks.
Add a colleague as a venue admin with only canRefund enabled. Sign in as them in a private browser window and confirm they can open the refund dialog but cannot access venue settings.