Skip to content

Roles and permissions ​

Who this is for: Admins inviting users; anyone wondering why a button is missing
What you'll achieve: Match people to the right role for their job

Person vs user ​

ConceptMeaning
PersonSomeone who can appear on the rota (staff directory)
UserSomeone who can sign in

A person does not need a login. A user invite creates a login and assigns a role. For My schedule, the user must be linked to a person (person_id).

Linking is automatic when possible: SCIM/SSO match by IdP external id or email to the staff directory; Admin invite can pick a person or auto-match; staff CSV import back-links users with the same email.

Roles ​

RoleTypical school job
Tenant ownerHead of school / system owner for the tenant
AdminOffice manager configuring the school (setup, invites, publish)
Duty leadDesignated rota person - publishes the day, records absences, runs cover
OfficeReception / cover desk recording absences
StaffTeachers and support staff (login optional)
ViewerRead-only export access

Designated rota person

SchoolRota works best when one person (or a small pair) owns publishing. Invite them as Duty lead during setup. Other staff mainly receive the published PDF rota and calendar updates - they do not need admin access.

Site-scoped access (Phase 9)

Multi-site trusts will add site-scoped access via user_site_access: the same role slugs (admin, duty_lead, …) scoped to one school site. Trust-wide admins keep tenant-level admin or tenant_owner. See docs/MULTI_SITE_AND_ORGS.md.

Permission summary ​

CapabilityOwnerAdminDuty leadOfficeStaffViewer
Manage setup / staff / commitments✓✓
Import staff✓✓
Build & publish rota✓✓✓
Request a rota change✓✓✓✓✓
Record absences✓✓✓✓
Configure notifications✓✓
View analytics✓✓✓✓
Create exports✓✓✓✓✓
Invite users✓✓
Use AI assistant✓✓✓
Configure SSO✓
Configure SCIM✓
Configure Outlook calendar✓✓
Configure Microsoft profile photos✓✓
View audit log✓✓
Send Help & ideas✓✓✓✓✓✓

Microsoft profile photos use the same permission as Outlook (integrations.outlook.configure). See Microsoft profile photos.

For the full matrix, see RBAC matrix.

Inviting users ​

  1. Open Settings. Invite extra publishers after setup. The person who signed up can already publish.
  2. Enter email, temporary password (setup auto-generates one), and role.
  3. Select Invite.
  4. Share the portal URL and credentials securely if email is delayed.

Invite user form

Requires role

Admin or Tenant owner (user.invite)

What happens next ​

The sidebar only shows areas your role can use. Staff see a short list: My schedule, Missed, and Help, plus Inbox and Account at the bottom (no Rota / Cover / School headings). Viewers get Today, Week, My schedule, and Help. Office and duty leads get Today, Week, My schedule, and Absences. Admins and owners also see Staff and Settings. After the school is live, Setup lives under Settings rather than the sidebar.

Staff cannot open school-wide Today or Week by URL either. Those boards stay with cover and ops roles. The same rule applies to the board APIs.

SchoolRota documentation. Every slot covered, every day.