DominoRole Import/Export & Technical Architecture: Deploy WordPress Role Configurations Across Sites

Import & Export
JSON Format
React + Chakra UI Dashboard

Any time you invest in building a carefully configured role structure — choosing the right capability combinations for each custom role, testing them, and refining them over weeks of real usage — that configuration has significant value. It represents hours of research and testing that you shouldn’t have to repeat on every new site. The Import/Export module in DominoRole makes this role configuration portable: export to a JSON file, import on any WordPress site, and your entire custom role structure is deployed in seconds.

Exporting Your Role Configuration

Navigate to DominoRole → Import / Export and click the Export Roles button. DominoRole generates a JSON file containing all your custom roles (default protected roles are excluded from export — they exist on every WordPress site by default). The JSON structure includes:

  • Role IDs (slugs): The unique identifier used internally by WordPress
  • Display names: The human-readable label shown in the WordPress admin
  • Full capability arrays: Every capability assigned to the role with its boolean grant value

The exported JSON is human-readable — meaning you can open it in a text editor, review the capability configuration, and even make minor edits before importing on a target site. This also makes the JSON file suitable for version control — store your role configuration in Git alongside your theme and plugin files for complete site configuration management.

Importing Roles from JSON

On the target site (with DominoRole installed), navigate to Import / Export, upload the JSON file, and click Import Roles. The import process:

  1. Validates the JSON structure and format
  2. Iterates through each role in the file
  3. Checks if the role ID already exists on the target site
  4. Creates new roles that don’t exist, or optionally overwrites existing roles with the imported configuration
  5. Reports success/failure counts and any conflicts

The import is safe for production sites — it does not modify user assignments, it does not affect existing roles that aren’t in the import file, and it validates all capability names to prevent importing invalid capability strings that could cause WordPress errors.

Agency Workflow: Deploy Once, Import Everywhere

For WordPress agencies, the import/export system enables a standardized role deployment workflow:

  1. Build the perfect role configuration once on a development site or agency template site
  2. Export the role configuration JSON
  3. Store the JSON in your agency’s project template repository
  4. For every new client site: install DominoRole, import the JSON — done
  5. Customize per-client as needed (rename roles, add/remove specific capabilities)

This means the hours invested in building the perfect Client Editor, Content Manager, Shop Manager, and Accountant role configuration need only be invested once across your entire agency’s client base. Every subsequent site gets the same battle-tested role structure from day one.

Staging-to-Production Migration

The most common individual developer use case for import/export is staging-to-production migration. When building or restructuring a site, you typically configure roles and test permissions on a staging environment before deploying changes to production. Without an export/import tool, this means manually recreating all your role configurations on the production site — a tedious, error-prone process.

With DominoRole’s Import/Export: configure and test on staging, export the JSON, import on production. The entire role structure transfers in under 60 seconds with no risk of manual transcription errors.


The React + Chakra UI Dashboard: Technical Architecture

Every DominoRole module — Role Manager, Permission Manager, User Manager, Presets, Temporary Permissions, Smart Detector, and Import/Export — is powered by the same React single-page application frontend. Understanding the technical architecture helps explain why the DominoRole experience feels so different from legacy WordPress plugins:

  • React: The entire admin UI is a React component tree mounted on a single <div id="dominorole-root"> element in each DominoRole admin page. No PHP-rendered HTML forms — everything is rendered client-side from JSON API responses.
  • Chakra UI: All visual components (modals, tabs, form elements, badges, cards) use Chakra UI’s component library — producing a consistent, accessible, and visually polished interface without custom CSS for each element.
  • React Router (HashRouter): Navigation between DominoRole admin modules is handled by React Router — providing instant, no-reload navigation between Role Manager, User Manager, and other sections.
  • REST API Communication: All data operations use WordPress’ REST API with nonce authentication. The React app communicates via fetch/axios calls to /wp-json/dominorole/v1/ endpoints secured by wp_create_nonce('wp_rest').

Security Architecture: Nonce-Secured & Capability-Gated

DominoRole’s REST API implements multiple security layers:

  • Custom capability gate: All REST API endpoints require the dominorole_manage capability, which is granted only to Administrators by default. Only users with this capability can access any DominoRole API endpoint.
  • Nonce verification: All mutating operations (POST, PUT, DELETE) require a valid WordPress REST nonce, preventing CSRF attacks.
  • Protected role enforcement: Server-side validation explicitly blocks all modification operations on the five default WordPress roles — protection is enforced at the API level, not just in the UI.
  • Input sanitization: All API parameters are sanitized using WordPress’ standard sanitization functions (sanitize_key(), sanitize_text_field()) before any database or WordPress core function calls.

Database Tables & Data Storage

DominoRole creates custom database tables on activation for features requiring persistent storage beyond WordPress’ core options and user meta:

Table Purpose
wp_dominorole_temp_perms Temporary permissions records — user ID, capability, expiry timestamp, status
wp_dominorole_detected_caps Smart Detector capability snapshot — baseline and newly detected capabilities

Role data itself is stored in WordPress’ standard wp_options table under the wp_user_roles key — the same location WordPress core uses. DominoRole does not duplicate role data — it reads and writes to the same canonical location, ensuring full compatibility with any other WordPress plugin or tool that interacts with roles.

WooCommerce Admin Access Control Integration

One of DominoRole’s underappreciated integrations is its WooCommerce admin access control. WooCommerce by default uses the woocommerce_prevent_admin_access filter to block users without the manage_woocommerce capability from accessing the WordPress admin entirely — which causes problems when you have custom roles with admin-level capabilities that don’t include manage_woocommerce.

DominoRole hooks into this filter and prevents WooCommerce from blocking users who have any of the defined “admin-capable” capabilities (manage_options, edit_posts, upload_files, edit_theme_options, manage_woocommerce, view_admin_dashboard, etc.). This ensures your carefully configured custom admin roles can access the WordPress admin without needing the full manage_woocommerce capability — solving a frequent WooCommerce + custom roles compatibility issue.

FAQ

Can I import roles from a different WordPress version?

Yes. The exported JSON contains role names and capability arrays — standard WordPress data that doesn’t change between versions. As long as the capabilities in the export file exist on the target site (i.e., the same plugins are installed), the import will work perfectly regardless of WordPress version differences.

Will importing roles affect existing users?

No. The import creates or updates roles only — it does not reassign any users. Users are unaffected by the import operation. If you import a role that already exists and choose to overwrite it, users assigned to that role will simply have the updated capability set from the import.

Is DominoRole compatible with multisite WordPress?

DominoRole is designed for single-site installations. Full multisite support with network-wide role management is planned for a future Pro version. On a multisite network, DominoRole manages roles on a per-site basis when activated for individual sites.

Deploy Your Role Structure to Any WordPress Site in Seconds

JSON import/export, React + Chakra UI dashboard, nonce-secured REST API — the complete modern wordpress role manager.

Get DominoRole →

Mark Henry's avatar
Written by

Mark Henry

Mark Henry is a lead content creator and WordPress expert at ShopCentral.