Roles and permissions
What each role may do: the fixed roles, the four configurable staff roles, their platform defaults and each complex’s own changes.
Every person’s access comes from their roles. Some roles are fixed; the four staff sub-roles can be configured, first for the whole platform and then per complex.
The roles
| Role | Where | Configurable |
|---|---|---|
| Global Admin | The platform | No |
| Organization admin | One organization | No |
| Building admin / District admin | One complex | No |
| Accountant, Board member, Maintenance staff, Concierge / security | One complex | Yes |
| Owner, Resident | Their units | No |
A person can hold several roles; they switch between them with the context switcher.
Permissions a staff role can get
Seventeen permissions can be given to a staff role: View units, Edit units, See owner contacts, View finance, Record payments, Approve payment receipts, Manage finance, Approve budgets, Post announcements, Moderate chat, Manage polls & meetings, Manage documents, Manage tickets, Visitor log, Manage amenities & bookings, Manage meters & readings and Decide violations & fines. The rest, such as settings, the roles page itself or the audit log, never go to a staff role.
Platform defaults
The Global Admin sets the defaults in Settings › Roles matrix (platform context). The matrix shows every role as a column; the fixed ones carry a lock and show Granted or Not granted. Each switch of a staff role saves at once, and every complex that has not changed that role follows the new default immediately.
A complex’s own permissions
A complex’s administrator opens Settings › Roles & permissions inside the complex. It shows the four staff roles, each marked Default or Customized:
- The first switch you change makes the role Customized: the complex now keeps its own set for it.
- Reset to defaults makes it follow the platform defaults again.
- A customized role keeps at least one permission, so its last switch cannot be turned off; use Reset to defaults instead.
Changes apply straight away to everyone with that role in the complex.
Two rules no setting changes
- Nobody approves their own request. Whatever their permissions, a person can never decide a request they made or act on a unit they own; another staff member must.
- Every permission change is written to the audit log, with the old and new set.