Skip to content

Roles and permissions

Who this is for: Admins inviting users; anyone wondering why a button is missing
What you'll achieve: Match people to the right role for their job

Person vs user

ConceptMeaning
PersonSomeone who can appear on the rota (staff directory)
UserSomeone who can sign in

A person does not need a login. A user invite creates a login and assigns a role. For My schedule, the user must be linked to a person (person_id).

Linking is automatic when possible: SCIM/SSO match by IdP external id or email to the staff directory; Admin invite can pick a person or auto-match; staff CSV import back-links users with the same email.

Roles

RoleTypical school job
Tenant ownerHead of school / system owner for the tenant
AdminOffice manager configuring the school
Duty leadSLT or rota lead who publishes the day
OfficeReception / cover desk recording absences
StaffTeachers and support staff (login optional)
ViewerRead-only export access

Site-scoped access (Phase 9)

Multi-site trusts will add site-scoped access via user_site_access — the same role slugs (admin, duty_lead, …) scoped to one school site. Trust-wide admins keep tenant-level admin or tenant_owner. See docs/MULTI_SITE_AND_ORGS.md.

Permission summary

CapabilityOwnerAdminDuty leadOfficeStaffViewer
Manage setup / staff / commitments
Import staff
Build & publish rota
Record absences
Configure notifications
View analytics
Create exports
Invite users
Use AI assist
Configure SSO
Configure SCIM
Configure Outlook calendar
View audit log

For the full matrix, see RBAC matrix.

Inviting users

  1. Open Admin.
  2. Enter email, temporary password, and role.
  3. Select Invite.
  4. Share the portal URL and credentials securely.

Invite user form

Requires role

Admin or Tenant owner (user.invite)

What happens next

SchoolRota documentation — every slot covered, every day.