Skip to main content

Understanding Admin Permission Roles

Admin Permission Roles (Full, Lite, and Custom) define user access levels across modules to keep your platform secure.

πŸ“Œ Note: The screenshots and settings shown in this article may not match what you see in your own platform, as Rosterfy is highly customisable. If you need guidance specific to your setup, please contact our support team.

Admin Permission Roles allow you to manage user access across different modules within Rosterfy by defining which areas an admin can access and the extent of their permissions. There are three role types that can be configured for your organisation: Full Admin, Lite Admin, and System Admin (Custom).

πŸ’‘Tip: See the Create and Manage Admin Permission Roles article for more information.


Admin Permission Roles

Select from three Admin Permission roles to tailor system access and administrative capabilities to your team’s specific needs:

Full Admin

The Full Admin role comes pre-configured by default with your Rosterfy account and includes all permissions enabled. Users with this role hold comprehensive authority to configure system settings, tailor platform functionality, control critical system functions, and perform sensitive actions such as data deletion. This is the highest access level and should be reserved exclusively for trusted personnel who require full platform control.
​

To strengthen platform security and safeguard data integrity, strict safeguards govern how permissions are allocated and modified. Administrators are restricted from assigning permission roles to other users if those roles exceed their own level of access. Additionally, administrators cannot modify or alter any permission roles currently assigned to their own account.


Lite Admin

The Lite Admin role is designed for users who need operational access to the Admin Console but should not have the ability to modify core settings, system configurations, or sensitive information established by a Full Admin. While you can adjust Lite Admin permissions for specific modules based on individual user requirements, standard pre-set restrictions apply to safeguard foundational system settings.


System Admin (Custom)

A System Admin role is a fully customisable role where you start with the exact same set of permissions available to a Full Admin, but can tailor them down to fit specific needs. Before configuring this role, identify which modules the user needs to interact with and the exact level of CRUD (Create, Read, Update, Delete) access required for their daily tasks. You can enable or disable permissions on a module-by-module basis, as well as apply attribute filters so the user only sees and manages the specific records relevant to their position.


Full Admin vs. Lite Admin Permissions

Permission

Full & System Admin

Lite Admin

Account

βœ…

βœ…

Admin Access

βœ…

βœ…

Automation

βœ…

❌

Billing

βœ…

❌

Budget

βœ…

❌

Certificate

βœ…

βœ…

Communication

βœ…

βœ…

Contract

βœ…

βœ…

EAV (Custom Field)

βœ…

βœ…

Event

βœ…

βœ…

Family

βœ…

βœ…

Files

βœ…

❌

Filters

βœ…

βœ…

Form

βœ…

βœ…

Headcount

βœ…

βœ…

Import

βœ…

❌

Integration

βœ…

❌

Inventory Management

βœ…

❌

Maps

βœ…

❌

Messaging

βœ…

βœ…

News

βœ…

βœ…

Note

βœ…

βœ…

Notifier

βœ…

βœ…

Partner

βœ…

❌

Payments

βœ…

❌

Payroll

βœ…

❌

Reports

βœ…

βœ…

Reward points

βœ…

βœ…

Rewards & recognition

βœ…

βœ…

Sandbox

βœ…

❌

System

βœ…

❌

System Limits

βœ…

❌

System Log

βœ…

❌

Training

βœ…

βœ…

Unreleased

βœ…

❌

User

βœ…

βœ…

Webhook

βœ…

❌


Lite Admin Permission Limitations

While Lite Admins provide operational access to day-to-day management tools, certain platform features remain restricted to protect core infrastructure and sensitive data. These limits fall into two categories: modules that are completely off-limits, and modules where access can be tailored based on operational needs.

Restricted Modules

Lite Admins have no access to the following areas:

  • Organisation Settings: Cannot view or access Organisation Settings, including headcount settings, Terminology, Content, Weblinks, Branding, or exporting account configurations.

  • Admin Permissions: Cannot view, create, edit, or delete admin permission roles, or manage admin access for other users.

  • Support & Helpdesk: Cannot submit support tickets or use the in-product help assistant. Lite Admins must escalate issues directly to their Full Admin.

  • Automations: Cannot view, build, edit, delete, or manually trigger automations, actions, or automation categories.

  • Integrations: Cannot view or configure integrations, including SSO, CRMs, background checks, e-signatures, payment/payroll providers, marketing tools, SMS, address lookup, video tools, or mobile app connections.

  • Finance & Billing: No access to Billing screens, Payroll (awards, pay runs, timesheets), Payments (invoices, refunds, vouchers), or Budgets.

  • System Tools & Logs: Cannot access System Logs, Insights Dashboards, Webhooks, Data Imports, File Manager, or Sandbox environments.

  • Maps & Inventory: No access to venue/Event map layers, Partners, inventory bundles, or location stock.

  • System Actions & Overrides: Cannot run system-level actions (clearing cache, applying recipes, setting temporary passwords, restoring deleted records) or override built-in guardrails (Shift limits, capacity caps, check-in windows, or locked pay runs).


Partial Access Modules

In these operational modules, Lite Admins can manage day-to-day tasks but cannot delete records, modify structural templates, or change core configurations:

  • Custom Fields & Forms: Can view existing custom fields and forms, but cannot create, edit, or delete fields, manage categories, or access encrypted/sensitive data.

  • Checkpoints: Can view a user's current checkpoint, but cannot create, edit, or delete checkpoints, or manually move users between them.

  • Events & Shifts: Can create, edit, copy, publish, and cancel Shifts, manage patterns and templates, run auto-rostering, and assign users. Cannot approve/cancel Events, delete items, manage Shift payments, edit locked template fields, or create custom statuses.

  • Headcount, Role Offers & Journeys: Can create and edit locations, venues, functional areas, job titles, role offers, and Journeys, as well as make offers and progress applicants. Cannot approve role offers, delete items, edit locked template fields, or create custom statuses.

  • Users: Can create and edit profiles, manage availability, user groups, ratings, and invitations. Cannot delete or restore users, impersonate accounts, manage user types or waivers, set team leaders, or edit invitation templates.

  • Communications: Can create and edit emails, SMS, notifications, and templates. Cannot delete messages, templates, or contacts, manage merge variables, view guest emails, or access the Communication Summary.

  • Messaging: Can manage channels and channel members only if explicitly enabled by a Full Admin (disabled by default).

  • Reports: Can build, run, and delete their own custom reports. Cannot view reports created by other administrators.

  • Training & Certificates: Can create and edit training modules (including SCORM) and issue certificates to users. Cannot delete training records, training modules, or underlying certificate templates.

  • Contracts, Rewards & News: Can build and issue contracts, manage reward items and allocations, and publish news articles. Cannot delete contracts, contract records, reward items, or news articles, and cannot manage news categories or inventory reports.


Understanding Permission Types (CRUD)

Each Admin Permission governs access to various sections of the Rosterfy Admin Console using a standard CRUD permission model. Understanding these terms is crucial for assigning the appropriate level of access:

  • Create: Grants the user the ability to add new data entries within the designated module.

  • Read: Permits the user to view existing data in the specific module.

  • Update: Allows the user to modify and refresh current data within the module.

  • Delete: Enables the user to remove data from the module.

πŸ’‘Tip: All Admin Users must have Admin Access enabled in their user profile to access the Admin Console, regardless of their role.


Which Role Should You Assign?

Use this reference to select the right role based on your user's daily responsibilities:

πŸ”‘ Comes pre-configured with all permissions enabled by default. Users have total authority to adjust system settings, manage critical functions, and delete data. This access level should be reserved strictly for trusted personnel who require complete platform control.

πŸ‘‰ Assign Full Admin.


πŸ“‹ Designed for users who need operational access to the Admin Console without the ability to alter core configurations or sensitive settings established by a Full Admin. Standard pre-set restrictions apply, though specific module access can still be adjusted.

πŸ‘‰ Assign Lite Admin.


πŸ› οΈ A fully customisable role that gives you access to the same options available to a Full Admin, but allows you to scale back permissions to fit specific duties. You can customize Create, Read, Update, and Delete capabilities per module and apply attribute filters to restrict data visibility to relevant records.

πŸ‘‰ Assign System Admin (Custom).

Did this answer your question?