Roles and capabilities: owner, admin, manager, supervisor, receptionist, staff
Access is the decision you make once per person and then forget. Six roles cover a building; each is a fixed set of capabilities, so 'what can Shane see' is always answerable.
Choosing
Ask what the person must do, not what they might want to see. Someone who records payments and talks to tenants is a receptionist. Someone who runs the building and reads the P&L is a manager. Someone who needs to change settings, see staff pay or add staff is an admin — and that is a short list. Cleaners and maintenance are staff. Head cleaner or head guard is supervisor.
Promote, don't demote
Start one step lower than asked. Promoting is a click and nobody minds; demoting is a conversation, and by then the person has already seen everything. The audit log records every role change with who made it.
Capabilities behind the roles
Each role is a fixed bundle of about forty capabilities — invoices.manage, finance.view, staff.pay and so on. The bundles are not editable per person on purpose: six nameable roles are auditable; forty checkboxes per person are not. If a role genuinely does not fit your building, tell us which capability is wrong for it; changing a bundle for everyone is a decision we make carefully and write down.
Tenants are not a role
Tenants never appear in this list. They use the portal, a separate door with its own sessions and eight pages. A staff member who is also a tenant has two logins.
Kiosks
A guard post or a clock-in tablet uses a kiosk PIN: a device session tied to a place, with the person on shift entering a short PIN on top. Kiosks reach only the Gate or the clock, regardless of who is on shift.
Related
Describes the platform as it is today. Something out of date? Tell us. · help 0.12.3