---
title: "Editing consent in Payload"
description: "The General Settings tab and its access control."
requested_language: ar
language: en
translation_notice: "This page isn't translated yet"
url: https://docs.systhema.app/ar/next/guides/cookie-consent/editor
version: unreleased (main)
docs_index: https://docs.systhema.app/ar/next/llms.txt
---
> This page isn't translated yet. Showing English.


## Editor experience

Enable `generalSettings.cookieConsent.enabled` in your Payload plugin options to register the Cookie Consent tab in General Settings. The tab is off by default. You can then:

- Flip the banner on or off (editor-level kill switch, both this and `cookieConsent.enabled` in code must be true)
- Curate the footer link list (Privacy Policy, Cookie Policy, Imprint, Terms…) using a typed picker, custom URL or internal page reference (localized labels)
- Override the banner's color theme via a swatch picker (any registered colorSystem mode, or "Auto" to inherit the page's `data-theme`)
- Override every label in the consent modal and preferences modal (localized)
- Edit per-category labels and descriptions (localized; the five categories themselves are a fixed taxonomy, editors can't add or remove categories)
- Curate the cookie list, name, category, description, duration, party, domain (localized)

Editor changes are wholesale, not partial overlays. Clearing a text field in admin produces an empty value in the live banner, not a silent fall-back to the dev's `systhema.config.ts` copy. Empty footer links list ⇒ no footer strip. Empty cookies array ⇒ empty cookie tables. The dev-side translations only seed the global on first init.

### Access control

Use the registered capability names:

| Capability                                     | Purpose                        |
| ---------------------------------------------- | ------------------------------ |
| `global.general-settings.read`                 | Read General Settings broadly  |
| `global.general-settings.update`               | Update non-tab-scoped settings |
| `global.general-settings.cookieConsent.read`   | Read the consent tab           |
| `global.general-settings.cookieConsent.update` | Update the consent tab         |

The `dev` role has `*`; `admin` has `global.*`. Both cover these capabilities. Grant only the tab-specific pair when the account should manage consent without broader settings access.

To allow non-dev users to manage cookies, register a custom role via `SysthemaPayloadPluginOptions.roles`:

```ts title="Plugin options to merge"
import type { SysthemaPayloadPluginOptions } from '@systhemaui/payload'

export const cookieManagerOptions: SysthemaPayloadPluginOptions = {
  generalSettings: { cookieConsent: { enabled: true } },
  roles: {
    customRoles: [
      {
        name: 'cookieManager',
        label: 'Cookie manager',
        capabilities: [
          'global.general-settings.cookieConsent.read',
          'global.general-settings.cookieConsent.update',
        ],
      },
    ],
  },
}
```

The built-in `admin` role has a `global.*` wildcard that auto-includes the new caps. Tighten its grant in your project's plugin options if you want cookie consent strictly scoped to `dev`.

## Driving the resolver yourself

Payload's `RootLayout` seeds the global on first initialization and resolves it when the server layout renders. A config option alone does not mount the frontend banner. Projects that want to drive the resolver themselves can import:

```ts
import { resolveCookieConsentConfig, seedCookieConsentFromConfig } from '@systhemaui/payload'
```

`resolveCookieConsentConfig(payload, locale, contentLocale?)` returns a promise of the config or `null`. `seedCookieConsentFromConfig(payload, config)` seeds the editor fields; use the starter's RootLayout wiring unless you need to own that lifecycle.
