Platform Setup

Account Configuration Guide

Complete setup guide including profile configuration, team access, and security settings.

3 min readUpdated 2025-01-14

Setting up a BrightStar account properly at the start saves you trouble later — at the door of a kirtan, at a retreat check-in table, or at a festival gate where dozens of volunteers need different kinds of access at once. This guide walks through the full sequence: what BrightStar needs from you to open an account, how to build out your organizer profile, how team access levels work, and how to keep the account secure once real ticket revenue and attendee data are flowing through it.

What information do you need to open a BrightStar account?

BrightStar asks for a specific set of details before your account is usable, and each one serves a purpose beyond paperwork. A verified email confirms the account belongs to a real, reachable person. Your organization name is what attendees see on your event pages, so it's worth entering exactly as you want it public. The business address and tax identification exist because BrightStar processes payments through Stripe, and Stripe requires verified business information before it will move money on your behalf — this is the same reason nearly every payment platform asks for it, not a BrightStar-specific hurdle.

  • Valid email address (verified via confirmation link)
  • Organization name (displayed on event pages)
  • Primary contact phone number
  • Business address (required for Stripe verification)
  • Tax identification (EIN for US, VAT for EU)

Setting up your organizer profile

Once your account exists, your profile is what attendees actually encounter when they land on one of your event pages. A few of these settings have effects that reach further than they first appear:

  1. 1Upload an organization logo, at least 400x400px, in PNG or JPG — this appears anywhere your branding shows up on event pages
  2. 2Add an organization description, which is pulled into event footers automatically
  3. 3Set your default timezone — this is the one setting that affects all of your event times, so a retreat scheduled across a change of season or a workshop listed for attendees in another region will display correctly only if this is set right the first time
  4. 4Configure notification preferences for email and SMS so you're not missing check-in issues or sales alerts
  5. 5Add your social media links, which display on your event pages

Who should have which level of access at your events

A festival gate crew, a retreat's finance person, and the owner managing billing all need very different things from the same account, which is why BrightStar splits access into four levels. Owner is the only level with full account access, including billing management, team member management, and API key generation — this stays narrow on purpose, since billing and API keys are the two things that cause the most damage if mishandled. Admin can create, edit, and delete events, process refunds, and view all reports, but cannot touch billing, so someone can run the operational side of your events without ever being able to move money out of the account. Manager can create and edit events and see reports for the events they're assigned to, but cannot delete events, which suits someone running a single retreat or workshop series without giving them reach into everything else you run. Scanner is the narrowest: check-in access and attendee lists only, with no financial access at all — exactly what you'd hand a volunteer standing at a kirtan door with nothing more than a device to scan tickets.

Keeping your account secure

Because an organizer account holds attendee data and a path to your payment processing, BrightStar recommends a small set of security habits rather than leaving it to chance. Two-factor authentication, whether by TOTP app or SMS, means a stolen password alone isn't enough to get in. Session timeout — 24 hours by default — limits how long a login stays valid on a device that's lost or left unattended. An IP allowlist for API access is optional, useful if your API calls only ever come from a known server or office network. Reviewing login history monthly and rotating API keys quarterly are both about catching something that's gone wrong before it becomes a bigger problem, rather than after.

  • Enable two-factor authentication (TOTP or SMS)
  • Set session timeout (default: 24 hours)
  • Configure IP allowlist for API access (optional)
  • Review login history monthly
  • Rotate API keys quarterly
Never share API keys or login credentials between people, even on the same team. Each team member should have their own individual login, matched to the access level that fits their actual job — a door volunteer gets Scanner, not a shared Admin password that happens to also work for check-in. If you ever suspect a login or API key has been compromised, rotate it immediately through Settings → Security rather than waiting to see if anything looks wrong first.

Common questions

Can I give my team different levels of access?

Yes. BrightStar has four team access levels. Owner has full account access including billing, team management and API key generation. Admin can create, edit and delete events, process refunds and view all reports but cannot change billing. Manager can create and edit events and view reports for assigned events but cannot delete events. Scanner has check-in access and attendee lists only.

Read more

The role set is broader than a four-step ladder. Alongside owner there are viewer, box office, marketing, finance, manager and admin presets, plus a custom option where the exact permissions are picked individually. A member belongs to an account owner rather than to a single event, and their access is resolved at the moment they touch something, across every event that owner has, so nobody has to be added event by event. Access can also be narrowed from the whole account to a named list of events. Seven event-level permissions do the actual gating: view, edit, check-in, box office, reports, attendee data and finances.

Can door staff check people in without seeing my sales figures?

Yes. BrightStar's Scanner access level is limited to check-in access and viewing attendee lists, with no financial access at all. It is the right role for volunteers and door staff who need to scan tickets but should not see revenue or billing.

Read more

The box office preset carries exactly three permissions: view, check-in and box office sales. Reports, attendee contact data and finances are all absent, and the latter two are separately marked as sensitive so they are never handed out by accident. The checks run on the server routes themselves rather than only hiding buttons, so a role that lacks a permission is refused with an explanation naming the role and the action. Members are invited by email address and carry a status, which means removing someone drops their access across every event at once.

What should I set up on my organizer profile?

In BrightStar you upload an organization logo of at least 400x400px in PNG or JPG, add an organization description that is used in event footers, and set a default timezone, which affects all of your event times. You also configure email and SMS notification preferences and add social media links, which are displayed on your event pages.

Read more

Of these, the timezone setting deserves the most care, since it isn't cosmetic — it's the reference point for every event time you publish afterward, so getting it wrong shifts every listing you create until it's corrected. The logo and description are lower stakes but still visible everywhere your brand appears: the logo wherever branding shows, the description automatically in event footers. Notification preferences and social links are about staying informed and being findable, not about how your events function.

What should I do if I think my login or API key has been compromised?

Rotate the credentials immediately through Settings and then Security in BrightStar. Never share API keys or login credentials, and give each team member their own individual access rather than a shared login, so access can be revoked cleanly.

Read more

API credentials are built so that losing one is recoverable without collateral damage. The full key is shown once at creation and is never stored: what BrightStar keeps is a hash of it plus a short visible prefix for identifying it in a list. Verification hashes whatever is presented and looks it up, so revoking a key makes it stop matching immediately, and a database leak cannot yield a usable credential. Each key also records when it was last used, which is the quickest way to tell whether an old one is still wired into something before removing it.

Ready to get started?

Create your first event on EveryEvent Rio de Janeiro — it’s free.