Hero

Rights and roles in your schedule: who can see and edit what

×
Go back to the overview

Permissions and roles in your schedule determine who can view, modify, approve, and export what. If everyone has too many permissions, errors occur. If people have too few permissions, the process grinds to a halt for the planner. A good permissions structure ensures security, speed, and clarity. In this article, you will learn how to logically set up permissions and roles in your schedule without making management unnecessarily complicated.


Why rights management is important

Schedules contain more information than just times. You see availability, absences, swap requests, comments, hours, and sometimes sensitive team information. Not everyone needs to see everything. At the same time, team leaders and coordinators must have enough space to do their work.

  • To avoid mistakesNot everyone is allowed to modify other people's services.
  • restrict privacyPeople only see what they need.
  • Maintain speedTeam leaders can make their own changes without an administrator.
  • Enable auditYou know who made which change.

Target: as few rights as possible, but enough rights to keep the schedule running smoothly.


Step 1. Determine main roles

Start with a small number of system roles. Do not create a separate role for every exception. That becomes difficult to manage.

System role May see Can edit Typical use
Employee or volunteer Own services and open services Availability, exchange request Manage your own schedule
Team Leader Own team Services within the team, approvals Daily operation
Planner Multiple teams Creating and modifying schedules Central planning
Concierge Everything Settings, rights, exports System Administration

Practical: Start with four roles. Only add an extra role if a recurring need does not fit with these four roles.


Step 2. View, modify, and approve divorce

Many organizations immediately grant someone full rights because that person needs to be able to view something. That is not necessary. Differentiate between viewing, modifying, and approving.

  • ZienSomeone may view information.
  • ChangeSomeone may adjust shifts, availability, or swaps.
  • To approveSomeone may approve a swap, leave, or deviations.
  • ExportSomeone is allowed to retrieve data from the system.

Important: Export duties are sensitive. Provide them only to people who really need the data.


Step 3. Use reach per team or location

Permissions should determine not only what someone is allowed to do, but also where. A team leader might be allowed to change shifts, but only within their own team or location.

Role Range Example Risk if too broad
Team Leader Own team Hospitality team evening Changes other teams by mistake
Location planner Own location North branch Unintended location changes
Regional planner Multiple locations West region Too much focus on details
Concierge All locations Main management Must remain limited

By linking permissions to scope, you give people exactly enough space. This makes the system safer and clearer.


Step 4. Use approval rights consciously

Approving is different from planning. Someone can perfectly well create shifts but not be authorized to approve late swaps, leave, or overtime. Therefore, create separate approval rights.

  • Exchange approvalWho is allowed to exchange after lock approval?
  • Leave approvalWho monitors minimum staffing?
  • Approval hoursWho approves deviations or overtime?
  • Critical service approvalWho may grant exceptions?

Tip: Always log critical approvals with the approver, time, and brief reason.


Step 5. Prevent management chaos

Too many administrators is a risk. Settings, qualifications, permissions, and exports affect the entire system. Limit administrative rights and work with fixed checks.

Management unit Who is allowed to make changes Check frequency Why
Roles and rights Concierge Quarterly Prevents uncontrolled growth
Qualifications Planner or manager Monthly Safe deployment
Exports Administrator or administration Per period Data verification
Lock rules Concierge Upon policy change Grid stability

Rule: Do not change permissions ad hoc for a single incident. Create temporary permissions only with an end date and reason.


Step 6. Use audit logs

An audit log makes visible who modified what and when. This is important for exchanges, leave, hours, qualifications, and rights.

  • WhoWhich user made the change?
  • WhatWhich service, role, or setting changed?
  • When. Time of change.
  • WhyBrief reason for significant changes.

Practical: Do not use audit logs to hold people accountable, but to quickly correct errors and improve policies.


Measuring and maintaining

Rights management remains healthy when you clean it up periodically.

  • Number of administrators. Must remain limited.
  • Inactive users with rights. To withdraw.
  • Temporary rights without an end date. Check.
  • Changes beyond your control. Signal for overly broad rights.

Frequently asked questions

How many rolls do you need

Usually, an employee, team leader, planner, and administrator are sufficient. Only add extra roles if the process structurally requires it.

Who is allowed to approve a trade

That depends on the team. For regular swaps, a team leader may suffice. For critical roles or cross-location swaps, a planner or administrator is more logical.

How often do you check rights

At least quarterly and always when someone changes roles or leaves the company. You should check temporary rights sooner.


Get started now

  1. Create four basic roles: employee, team leader, planner, and administrator.
  2. Separate view, modify, approve and export.
  3. Link rights to a team, location, or region.
  4. Separate approval rights for swaps, leave, and hours.
  5. Restrict administrative rights and check them periodically.
  6. Use audit logs for significant changes.
  7. Clear inactive and temporary rights.

With proper permissions and roles, your schedule remains safe and workable. People can do what is necessary, without access to components they do not need.

Go back to the overview