DominoRole Permission Manager: 4-Tab Capability Editor with Dynamic Menu Access Viewer for WordPress

Permission Manager
4 Tabs + Menu Access Viewer
Grouped Capabilities

WordPress capabilities are the foundation of every access control decision the platform makes. When you navigate to the Dashboard, edit a post, upload an image, manage a plugin, or process a WooCommerce order — WordPress checks whether your current user has the required capability for that action. There are hundreds of these capabilities in a fully loaded WordPress installation with WooCommerce, an LMS plugin, a gallery plugin, and SEO tools — and managing them without a proper interface is essentially impossible.

DominoRole’s Powerful Permission Manager is the most sophisticated WordPress capability management interface available. It organizes hundreds of capabilities across four specialized tabs, groups them by meaningful functional categories, provides curated tooltips for the most commonly needed capabilities, and includes the unique Dynamic Menu Access Viewer that shows you exactly which admin menus each capability unlocks before you save the change. No other user role editor wordpress plugin comes close to this level of clarity and functionality.

WordPress Capabilities Explained

In WordPress, a capability is a named permission string (like edit_posts, manage_options, or publish_pages) that is either granted or denied to a user role. WordPress checks capabilities using the current_user_can() function before displaying admin menu items, allowing page access, or processing form submissions.

There are three sources of capabilities on a WordPress site:

  1. WordPress core capabilities: ~60 capabilities defined by WordPress itself, covering posts, pages, media, users, plugins, themes, and settings
  2. WooCommerce capabilities: ~100+ capabilities added when WooCommerce is active, covering products, orders, coupons, reports, and settings
  3. Third-party plugin capabilities: Any number of custom capabilities added by installed plugins — detected automatically by DominoRole’s Smart Capability Detector

The Four-Tab Permission Manager Interface

The Permission Manager opens as a full-screen modal (not a separate page — keeping your role grid context preserved) with four tabs, each serving a distinct purpose in the capability management workflow:

⭐ Most Used

Curated list of ~15 top capabilities with plain-English tooltips explaining each one’s exact function. Best starting point for new role configuration.

💻 Admin Menu

Capabilities mapped to core WordPress admin menu areas. Toggle to control which sidebar menus the role can access.

📊 All Permissions

Complete capability list with bulk checkboxes and live search. Every capability on the site, organized in expandable category groups.

✅ Active Permissions

Only currently enabled capabilities, with a one-click revoke toggle for each. The fastest way to audit and remove permissions.

Most Used Permissions Tab: Curated with Tooltips

The Most Used tab is the recommended starting point for configuring a new role. It presents the capabilities that cover the vast majority of real-world permission needs, each with a tooltip showing a plain-English explanation of what the capability does:

Capability What It Grants
read Basic access to the WordPress frontend and dashboard home
edit_posts Create and edit the user’s own draft posts
publish_posts Publish posts immediately without editor approval
edit_others_posts Edit posts authored by other users
delete_posts Move own posts to trash
upload_files Upload files to the Media Library
moderate_comments Approve, edit, and delete comments on all posts
manage_categories Create, edit, and delete post categories and tags
edit_pages Create and edit WordPress Pages
manage_options Access WordPress Settings pages and general options
list_users View the Users list in the WordPress admin
edit_users Edit user profiles, roles, and settings
manage_woocommerce Access WooCommerce admin settings and menus
edit_theme_options Access Appearance menu including Themes and Customizer
activate_plugins Activate and deactivate WordPress plugins

Admin Menu Permissions Tab

The Admin Menu Permissions tab presents capabilities organized specifically by which WordPress admin menu area they control access to. This tab answers the practical question: “I want this role to see the Posts menu but not the Plugins menu — which capabilities do I enable?”

The menu-capability mapping is maintained in DominoRole’s DominoRole_Permission_Groups class and covers all core WordPress admin menus: Dashboard, Posts, Pages, Media, Comments, Appearance, Plugins, Users, Tools, Settings, and WooCommerce. Toggling a capability in this tab changes it in the same permission database as all other tabs — the tabs are different views of the same capability set, not separate systems.

All Permissions Tab: Bulk Actions & Live Search

The All Permissions tab is the complete capability view. Every capability on the site — from WordPress core, WooCommerce, and all installed plugins — appears here in expandable category groups with checkboxes. Key features:

  • Live Search: Type in the search field to filter the capability list in real-time — finds matches across all categories instantly without waiting for server roundtrips
  • Bulk Checkboxes: Select multiple capabilities using checkboxes and toggle them all in one save operation — enabling 10 WooCommerce capabilities takes one checkbox sweep and one Save click rather than 10 individual toggles
  • Category Expansion: Categories are collapsed by default for a clean initial view — expand only the categories you need (e.g., “WooCommerce Orders” for a Shop Manager role)
  • Grouped Display: All capabilities are organized into logical functional groups (detailed in the next section)

Active Permissions Tab: Audit and Revoke

The Active Permissions tab shows only the capabilities currently enabled for the role — filtering out all the capabilities the role doesn’t have. This creates a focused audit view that answers: “What can this role actually do?”

Each capability in the Active tab has an interactive Revoke toggle that removes the capability immediately on click, with visual feedback confirming the revocation. The revoke action shows a visual “revoked” state (strikethrough, grayed color) before saving, so you can revoke multiple capabilities visually and then save all changes in one batch operation.

This tab is particularly useful when performing a permission audit of an existing role — reviewing a role that has accumulated capabilities over time and cleaning up anything that shouldn’t be there without needing to hunt through the complete capability list.

Capability Grouping by Category

All capabilities in the All Permissions tab are organized into logical category groups by the DominoRole_Permission_Groups class. The main groups include:

📋 Posts

edit_posts, publish_posts, delete_posts, edit_others_posts…

📄 Pages

edit_pages, publish_pages, delete_pages…

📷 Media

upload_files, edit_files, unfiltered_upload…

👤 Users

list_users, edit_users, promote_users, delete_users…

💬 Comments

moderate_comments, edit_comment…

🧴 Themes

switch_themes, edit_themes, edit_theme_options…

🔌 Plugins

activate_plugins, install_plugins, update_plugins…

🛒 WooCommerce

manage_woocommerce, edit_products, edit_shop_orders…

⚙️ Settings

manage_options, manage_links, manage_categories…

🛠️ Other

Custom and third-party plugin capabilities not in other groups.

The Menu Access Viewer is DominoRole’s most unique differentiating feature in the Permission Manager. Every capability row includes a “Menu Access” button that opens a secondary modal showing exactly which WordPress admin menus (main menu items and submenus) become accessible when that specific capability is enabled.

The viewer displays menus in a clean two-column table:

Main Menu Sub Menu
Appearance Themes
Appearance Customize
Appearance Menus

Example above: The menu access for edit_theme_options — before you enable it, you see it unlocks three Appearance submenus.

This feature is the answer to the most common complaint about WordPress capability management: “I never know what I’m actually enabling.” The Menu Access Viewer makes every capability’s admin-side impact visually explicit before any change is saved — completely eliminating the trial-and-error approach of enabling a capability, logging in as a test user, checking what appeared in the sidebar, and adjusting if wrong.

Practical example: You’re configuring a “Community Manager” role and want them to be able to moderate comments. Before enabling moderate_comments, you click Menu Access — it shows the Comments menu and its submenus. You enable it. You then consider manage_options for some settings access — Menu Access shows it unlocks the entire Settings menu with all submenus. Too broad. You look for a more specific capability instead. All without any test user login.

Recommended Permission Assignment Workflow

  1. Open the role in the Permission Manager modal
  2. Start on the Most Used tab — enable the foundational capabilities for the role’s job function
  3. Switch to the Admin Menu tab — use Menu Access viewer on any uncertain capabilities to verify their menu impact
  4. Switch to the All Permissions tab — use the search to find specific capabilities (e.g., search “woocommerce” to see all WC capabilities)
  5. Use the Active Permissions tab for a final audit — review everything enabled and revoke any that seem too broad
  6. Save changes — the permission set is written to the WordPress roles option immediately

Permission Save API

Permission changes are saved via POST /dominorole/v1/roles/{id}/capabilities with a JSON body containing the full array of capability keys and boolean values (true = granted, false = revoked). The API iterates through the array, calling $role->add_cap($cap) for true values and $role->remove_cap($cap) for false values. All operations are nonce-verified and permission-checked against the dominorole_manage capability.

FAQ

Can I grant capabilities to users individually, not just to roles?

Yes — use the Temporary Permissions module to grant specific capabilities to individual users for a time-limited period without modifying their role. For permanent individual capability grants, these are also manageable through the User Manager’s advanced user edit view.

Do permission changes take effect immediately?

Yes. Permission changes are written to the WordPress wp_user_roles option immediately on save. Users currently logged in may need to refresh their session for the changes to take effect, but new login sessions will see the updated permission set immediately.

Can I see what capabilities an Administrator has?

Yes — you can open the Permission Manager for the Administrator role (it’s a protected role, so changes are disabled, but viewing is allowed). The Active Permissions tab shows the full list of capabilities the Administrator role currently has. This is useful for reference when configuring custom roles.

Manage WordPress Capabilities with Complete Clarity

4-tab Permission Manager with Menu Access Viewer — see exactly what you’re enabling before you save it.

Get DominoRole →

Mark Henry's avatar
Written by

Mark Henry

Mark Henry is a lead content creator and WordPress expert at ShopCentral.