Skip to content

Installing Advanced Admin Permissions

Beta release

Advanced Admin Permissions is in beta (0.1.0). The install command below pins the exact 0.1.0 version, so a later, possibly incompatible 0.x release is only installed on purpose. See the beta upgrade notes for more on beta installs, and review the changelog for what's included before using it in production.

This guide covers installing the Advanced Admin Permissions module with Composer, and what changes in the admin panel once it's installed.

Requirements

Advanced Admin Permissions needs PHP 8.2 or newer, and builds on Magento's own Magento_Authorization, Magento_User, Magento_Backend, Magento_Integration and Magento_Webapi modules. For the general prerequisites, see the Hyvä Commerce Installation Page.

Advanced Admin Permissions 0.1.0 is tested on Magento Open Source and Mage-OS, 2.4.7 to 2.4.9.

Adobe Commerce is not supported in 0.1.0

Adobe Commerce is not supported in 0.1.0: its own role scopes would apply on top of the Advanced Admin Permissions scope restriction, and the role edit page would show two scope editors saving independently. Adobe Commerce support follows in a later release.

Installing the Module with Composer

  1. Require the hyva-themes/commerce-module-advanced-admin-permissions package:

    composer require hyva-themes/commerce-module-advanced-admin-permissions:0.1.0
    
  2. Run a setup upgrade to enable the modules and create their database tables:

    bin/magento setup:upgrade
    
  3. Recompile and flush the cache, as you would after any module install:

    bin/magento setup:di:compile
    bin/magento cache:flush
    

What the Package Installs

The hyva-themes/commerce-module-advanced-admin-permissions package contains two Magento modules, and both are enabled by bin/magento setup:upgrade:

  • Hyva_AdvancedAdminPermissions - multiple roles per admin user, negative (deny) roles, expiring role grants, bulk role assignment, roles for integrations, the role assignment audit log and the effective-permissions viewer.
  • Hyva_AdvancedAdminPermissionsScope - the website and store view restriction, and everything that enforces it across grids, edit pages, saves, configuration screens and the REST and SOAP APIs.

Scope restriction lives in its own module on purpose, because it is the part that touches the most of Magento. If you only want the role features, disable Hyva_AdvancedAdminPermissionsScope and leave the other module enabled:

bin/magento module:disable Hyva_AdvancedAdminPermissionsScope
bin/magento setup:upgrade

After Installing

Your existing roles and assignments are unchanged after installing Advanced Admin Permissions. There is no configuration section to fill in and no feature flag to switch on:

  • Every existing admin user keeps the single role they already had.
  • No role is a negative (deny) role, no grant has an expiry, and nothing is scope restricted until you set it.
  • The Role Assignment Audit grid starts empty and fills up as roles change from this point on.

The permission guardrails apply immediately

The permission guardrails are active straight after install: no admin can change their own roles, and an admin can only change, delete or unlock an account whose roles they could grant themselves.

Grant the Hyva_AdvancedAdminPermissions::audit ACL resource to the roles that should be able to open the audit grid. You'll find it in the role resource tree under System → Permissions, as Role Assignment Audit Log.

Start with a test user

Scope restriction changes what an admin sees across the whole panel. Before restricting anyone real, create a throwaway admin user, restrict it to one store view, and log in as it to see the result. The Effective Permissions viewer shows what a user can reach without logging in as them, which covers the permission side but not the scope side.

  • User Guides - how to assign multiple roles, restrict scope, time-box a grant and read the audit log.
  • Command Line Reference - the bin/magento hyva:admin-permissions:* commands for scripting and deployment.
  • FAQs - upgrade safety, performance, and how the module interacts with existing roles.