Skip to content

Roles and permissions ​

Who this is for: Admins inviting users; anyone wondering why a button is missing
What you'll achieve: Match people to the right role for their job

Person vs user ​

ConceptMeaning
PersonSomeone who can appear on the rota (staff directory)
UserSomeone who can sign in

A person does not need a login. A user invite creates a login and assigns a role. For My schedule, the user must be linked to a person (person_id).

Linking is automatic when possible: SCIM/SSO match by IdP external id or email to the staff directory; Admin invite can pick a person or auto-match; staff CSV import back-links users with the same email.

Roles ​

RoleTypical school job
Tenant ownerHead of school / system owner for the tenant
AdminOffice manager configuring the school (setup, invites, publish)
Duty leadDesignated rota person - publishes the day, records absences, runs cover
OfficeReception / cover desk recording absences
StaffTeachers and support staff (login optional)
ViewerRead-only export access

Designated rota person

SchoolRota works best when one person (or a small pair) owns publishing. Invite them as Duty lead during setup. Other staff mainly receive the published PDF rota and calendar updates - they do not need admin access.

Site-scoped access (Phase 9)

Multi-site trusts will add site-scoped access via user_site_access: the same role slugs (admin, duty_lead, …) scoped to one school site. Trust-wide admins keep tenant-level admin or tenant_owner. See docs/MULTI_SITE_AND_ORGS.md.

Permission summary ​

CapabilityOwnerAdminDuty leadOfficeStaffViewer
Manage setup / staff / commitments✓✓
Import staff✓✓
Build & publish rota✓✓✓
Request a rota change✓✓✓✓✓
Record absences✓✓✓✓
Configure notifications✓✓
View analytics✓✓✓✓
Create exports✓✓✓✓✓
Invite users✓✓
Use AI assistant✓✓✓
Configure SSO✓
Configure SCIM✓
Configure Outlook calendar✓✓
Configure Microsoft profile photos✓✓
View audit log✓✓
Send Help & ideas✓✓✓✓✓✓

Microsoft profile photos use the same permission as Outlook (integrations.outlook.configure). See Microsoft profile photos.

For the full matrix, see RBAC matrix.

Inviting users ​

  1. Open Admin, or use Setup → Rota person during onboarding.
  2. Enter email, temporary password (setup auto-generates one), and role.
  3. Select Invite.
  4. Share the portal URL and credentials securely if email is delayed.

Invite user form

Requires role

Admin or Tenant owner (user.invite)

What happens next ​

The sidebar only shows areas your role can use. Staff see My schedule, Missed work, Notifications, and Account. Viewers also get Today, Timetable, and Exports. Office and duty leads get absences, missed work, and analytics. Duty leads also see Rota requests. Admins and owners also see Staff, Setup, and Admin.

Staff cannot open school-wide Today or Timetable by URL either. Those boards stay with cover and ops roles. The same rule applies to the board APIs.

SchoolRota documentation. Every slot covered, every day.