Skip to main content
How-to

Runbook: Add a New Team Member

Account: VITAG (Vitagen Labs)
Navigation: Configuration → Account → Users → Add User


When to Use This Runbook

Use when onboarding a new employee, contractor, or external party who needs access to the UltraCart backend. Also use when an existing team member's role changes and their permissions need updating.

Who can do this: Account owner or anyone with Configuration — Users access.

Reference: See 15-tasks-workforce-permissions.md for the full permissions matrix by role.

Permission AreaOwnerCustomer ServiceOperationsBookkeeperMarketing
Orders — View✅ read only✅ read only
Orders — Edit
Orders — Refund⚠️ ask owner
Auto Orders — View✅ read only✅ read only
Auto Orders — Edit
Customers — View⚠️ minimal
Customers — Edit
Items — View⚠️ optional
Items — Edit⚠️ limited⚠️ descriptions only
Reports — Financial
Reports — Marketing
Reports — Shipping
StoreFronts✅ full
Coupons
Affiliates
Configuration
Fraud Review
Tasks

Rule of thumb: Start with the minimum and add permissions if the person requests them and there's a legitimate work reason. It's much easier to add access than to undo a mistake caused by over-permissioned access.


Step 3: Set Up Task Email Notifications

Still on the user's account page, find Email Notifications:

RoleSet This
OwnerDaily Organization Summary — sees all tasks due today across the whole account
Customer ServiceDaily Personal Summary — sees only tasks assigned to them
OperationsDaily Personal Summary
Bookkeeper❌ — not involved in tasks; set up scheduled report delivery instead (see run-monthly-tax-report.md)
Marketing❌ — not involved in tasks

Step 4: Assign CRM Permissions (If CRM Modules Are Enabled)

If CRM, Conversations, and Calls are active on the account, assign the appropriate CRM-level permissions:

For Customer Service Reps

  1. Go to the user's account → Conversations Chat Departments

  2. Assign them to the relevant chat department(s) (e.g., "Customer Support")

  3. Leave "Use AI to handle chat as this agent" unchecked — that checkbox is only for AI Agent accounts

  4. Set Calls permission to pbx_user (standard call handling)

For CS Team Lead / Supervisor

  1. Same as CS rep for chat departments

  2. Set Calls permission to pbx_supervisor (adds barge, coach, queue monitoring)

For Owner / Operations Manager

  1. Set Calls permission to pbx_admin (full configuration access)

  2. Enable SMS/Web Chat Administrator if they need Workforce Dashboard visibility

For AI Agent Accounts (Not Human Staff)

If you are creating a new AI Agent user (not a human), check "Use AI to handle chat as this agent" and follow 13-ai-agents-chat-sms.md for the full AI Agent setup flow.


Step 5: Send Login Credentials

Send the new user their login information securely:

Security note: Do not send the username and password in the same message/email. Send the username in one channel (e.g., email) and the password in another (e.g., text or Slack DM).


Step 6: Verify Access (5-Minute Check)

Have the new user log in and confirm they can:

  • [ ] Access the sections they need (e.g., Operations → Orders for CS staff)

  • [ ] Cannot access sections they shouldn't (e.g., Configuration for CS staff)

  • [ ] Receive the task notification email (test by assigning them a test task)


When Someone's Role Changes

If an existing user changes roles (e.g., CS rep promoted to team lead):

  1. Go to their user account in Configuration → Account → Users

  2. Update their permissions per the new role

  3. Update their CRM/Calls permission level if applicable

  4. Update their task notification setting if applicable (e.g., add Daily Org Summary)


Offboarding (When Someone Leaves)

When a team member departs:

  1. Go to Configuration → Account → Users → find their account

  2. Deactivate their account (do not delete — this preserves task history and audit trail)

  3. Go to Operations → Tasks → filter by their name → reassign any open tasks

  4. Confirm they can no longer log in

Critical: If the departing person had access to payment gateway admin panels (Stripe, Braintree, etc.) or any external service credentials, change those passwords separately — UltraCart deactivation only removes their UltraCart access.

Was this page helpful?