BookodileBookodile
Browse all articlesβŒ„

Your team

Roles and permissions

What each permission actually controls, the view-all versus view-own pairs that decide whether someone can see colleagues' data, and the one permission that is not about access at all.

Last verified View as Markdown

Permissions in Bookodile are attached to roles, and roles are yours to define. There is no fixed ladder of job titles β€” you build the roles your business actually has and give each one the permissions it needs.

The permissions

PermissionWhat it allows
bookings.manageCreate, edit, cancel and move bookings
bookings.view_allSee everyone's bookings
bookings.view_ownSee only their own
customers.manageCreate and edit customer records
customers.view_allSee every customer
customers.view_ownSee only customers they have served
services.manageCreate and edit services and prices
team.viewSee the team list
team.manageAdd, edit and deactivate team members, and manage roles
reports.view_allSee figures for the whole business
reports.view_ownSee only their own figures
settings.accessOpen the settings area
addons.manageSwitch add-ons on and off
members.is_bookableWhether this role is listed as a service provider

The view-all / view-own pairs

Three areas come in pairs β€” bookings, customers and reports β€” and the pair is the important part.

view_own is a genuine restriction, not a default filter someone can widen. Someone with reports.view_own sees their own numbers and cannot reach a colleague's, including through a link someone sends them.

This pair also governs money. Whether a team member can see everyone's tips is decided by whether they can view all reports or only their own.

The one that is not about access

members.is_bookable β€” labelled "List as a service provider" β€” does not grant or restrict anything. It says whether people with this role appear on your booking page as someone a customer can choose.

It lives with the permissions because it is a property of the role rather than the person: front-desk staff, managers and owners who do not personally deliver services all sit in roles that are not bookable.

Turning it off does not reduce anyone's access. Turning it on does not grant any.

Ownership

The business owner is not a role you can edit away. Ownership carries full access regardless of what roles exist, so you cannot lock yourself out by misconfiguring one.

Organisations and branches

Roles belong to a business. In a multi-branch organisation, someone's access is scoped to the branches they are a member of β€” being on the team at one location does not grant sight of another's bookings or figures.

Worked example

A three-person clinic.

  • The owner β€” everything, and not editable.
  • Practitioner β€” bookings.manage, bookings.view_all (they cover for each other), customers.view_own, reports.view_own, listed as a service provider. They can see the whole diary but only their own patients and their own numbers.
  • Reception β€” bookings.manage, bookings.view_all, customers.view_all, no reports, not listed as a service provider. They run the diary for everyone and appear to no customer as a bookable person.

Limits

  • Permissions are per role, not per person. Someone needing different access needs a different role.
  • One role per person per branch.
  • There is no per-service permission. Access is not scoped to a subset of the catalogue.
  • view_own cannot be widened temporarily. There is no "show me everything just this once".
NextWorking on your own β€” "Just me" mode