Skip to main content

Control permission levels

You can control what functions a user has access to by setting their permission level accordingly.

Amelia Andrews avatar
Written by Amelia Andrews
Updated over a week ago

A permission level is a group of access rights within Rotaready, like "can view rotas" and "can view employee pay records". You can create as many different permission levels as you like and customise what access rights they have. Each employee user account is mapped to a permission level, thus determining what they have access to.

You might want to ensure certain employees are limited to their reportees when accessing some functions, such as "can view employee pay records for reportees only". By organising your permission levels into a hierarchy, this is possible. It's not uncommon to organise your permission levels in a similar structure to your corporate hierarchy.

πŸ“ŒNote: Permission levels are easy to use, but can be difficult to get right, especially in larger organisations. Saving your changes puts them live, so be sure to test them first using the Permissions Sandbox.

πŸ‘€ Find out more in our Spotlight Session Permissions - the key to getting it right.

Use permission levels

Specific use cases such as rota publishing permissions can also be managed effectively using permission levels, allowing organizations to tailor access to meet operational needs.

To access permissions, go to Settings then click Permissions.


View and amend permission levels

Drag and drop levels, ordering them in a tree-like fashion to represent a hierarchy. Clicking Edit on a level allows you to customise what access rights the level represents, using the checkboxes next to each item.

When creating a new permission level, don't forget to drag it to the appropriate place within your hierarchy.

πŸ“ŒNote: If you have anything that uses the Rotaready API, such as an integration built by you or a 3rd party, you're likely to see a permission level for these. Be careful as what you change here will affect what your API credentials have access to. Full-access users, such as Head Office administrators, have the ability to assign or modify permissions for API integrations, ensuring only necessary access rights are provided.

Full-access users also have the ability to grant or modify rota publishing permissions, ensuring alignment with organizational requirements for managing team schedules.


Change an employee's permission level

You can change an employee's permission level if you follow the below steps:

  • Click on Staff in the main navigation menu.

  • Find the employee you wish to edit.

  • Ensure the Account tab is selected and choose a new permission level in the drop-down.

For instance, to grant rota publishing access for a specific team, ensure the permission settings include functionality for that schedule area by navigating to the Staff section and following the outlined processes.

In addition to the access rights associated within their permission level, an employee is also limited by their site access. This is a restriction on the sites/departments they can view. This can be modified on their account in the Site access section.

To ensure rota publishing access for a specific site, you can update a user's site access, which involves navigating to the Staff section, locating the relevant user, and modifying their site assignments accordingly. Upon changing an employee's permission level, they will be logged out of Rotaready if they are currently logged in.


Permissions sandbox

The permissions sandbox is a helpful tool that allows you to test the impact of your changes before putting them live. You can simulate whether or not an employee can perform a specific action on another employee.

The criteria you need to complete are the following:

  • Source user - the employee who will be performing the action.

  • Action.

  • Target user - the employee on which the source user's action will apply.

An example scenario: I'd like to check if 'employee 1 can view the pay rates of employee 2:

  • Source user - Employee 1

  • Action - View pay records

  • Target user - Employee 2

If the source user has the relevant access to perform the action the sandbox will turn green, otherwise it'll turn red. Regularly reviewing permission levels and segmenting users by roles can help streamline updates and maintain security in large teams.


Specific permission use cases

Rota publishing permissions management is an important example of applying permission levels in Rotaready. Full-access users can edit permission levels to include or restrict publishing rights at specific organizational levels. This involves updating role-based permissions and coordinating with team leads to ensure appropriate access.

Did this answer your question?