Permissions
The complete set. Permissions are granted through roles,
and a role holding * is a superuser within its tenant.
The same checks run on the web console, the REST API, the MCP server and the assistant.
| Key | Allows |
|---|---|
loan.view |
See loans and who has what |
loan.issue |
Issue a loan device |
loan.return |
Mark a loan returned |
loan.manage |
Register devices, edit, bulk actions, manage loan groups |
Devices and inductions
Section titled “Devices and inductions”| Key | Allows |
|---|---|
device.view |
See device records and history |
device.manage |
Send MDM commands, other than wipe |
device.wipe.request |
Request a device wipe |
device.wipe.approve |
Approve a requested wipe and make it happen |
device.laps.read |
Read a device’s local administrator password |
induction.manage |
Run inductions, import rosters, record issued devices |
Repairs
Section titled “Repairs”| Key | Allows |
|---|---|
repair.view |
See submissions |
repair.create |
Lodge one |
repair.update |
Change non-closing status, priority, assignment, add notes, record outcome and cost |
repair.close |
Close or delete one |
Tickets
Section titled “Tickets”| Key | Allows |
|---|---|
ticket.view |
See tickets, their logged time, and My time |
ticket.create |
Raise one, including by making quick time into a ticket |
ticket.update |
Change non-closing status, queue, assignment. Also log time, run timers, set an estimate, and edit or delete your own time |
ticket.comment |
Reply publicly |
ticket.internal |
Read and write internal notes |
ticket.close |
Close one |
ticket.ingest |
Receive whole-school mailbox deliveries through an API key: create tickets, add public replies and attachments, and resume waiting tickets on requester replies |
Mail intake keys require an unrestricted campus grant. The dedicated permission
authorizes routing to enabled, licensed departments through configured mailbox
addresses; it grants no general department reading API. Default read-only keys
and ordinary ticket write permissions do not authorize intake. Create a dedicated
key with ticket.ingest using an account that holds it (or an Owner), then
configure that key in the mail gateway. This change is pending beta acceptance.
The beta candidate requires the relevant close permission for a transition to
closed through generic edits, actions, bulk operations and external tools.
Closing during a merge also requires ticket.close. Editing metadata on an
already closed item and reopening it retain their update-permission behavior.
Confirm the deployment status.
Department access
Section titled “Department access”These controls are a beta preview in the 0.12.0-rc.3 source. Confirm the deployment status and entitlement.
| Key | Allows |
|---|---|
departments.manage |
School-wide department administration and membership changes, while retaining campus bounds |
ticket.transfer |
Transfer a ticket, also requiring ticket.update and access to both departments |
Department membership limits which tickets a staff account can access. Existing
ticket action permissions still apply. The restriction that removes legacy ICT
access is explicit; broad department administration should not be granted to a
department-only worker. Once departments exist, shared ticket/workflow settings
also require departments.manage alongside their existing permission. See
school departments.
Stock and money
Section titled “Stock and money”| Key | Allows |
|---|---|
stock.view |
See stock levels and items |
stock.manage |
Maintain the catalogue and sell items |
cost.view |
See cost analytics |
cost.export |
Export cost data |
cost.manage |
Create, edit and delete cost reporting terms |
software.view |
Read the software contract register; licence-position reports also require identity.view |
software.manage |
Create, edit and delete software contracts and configure renewal email recipients |
charge.view |
See damage charges |
charge.raise |
Propose a charge |
charge.approve |
Approve, decline or waive a charge |
People and directory
Section titled “People and directory”| Key | Allows |
|---|---|
client.view |
See people and their profiles; also opens the assistant |
client.manage |
Edit person records, register cards |
directory.view |
Search the identity provider: the Accounts view of People, and Search all accounts on a person’s page. With client.view, either one shows People in the navigation |
directory.manage |
Licences, lock, delegate, reset passwords on demo directory accounts |
Identity
Section titled “Identity”Reads, then writes, against a person’s identity provider account — split from
directory.* because these reach sign-in history and account state for staff
and children, not the licence/mailbox/password actions directory.manage
already covers.
| Key | Allows |
|---|---|
identity.view |
See identity provider state for a person |
identity.signins.view |
See sign-in history — IP address, city and device — for a person |
identity.policy.view |
See identity policy, such as MFA requirements, for a person |
identity.mfa.reset |
Reset a person’s MFA |
identity.account.manage |
Disable a person’s identity provider account |
identity.account.enable |
Re-enable a disabled identity provider account |
identity.session.revoke |
Revoke a person’s active sign-in sessions |
identity.license.manage |
Assign or remove a person’s identity provider licence, on the person’s Account tab or a live Entra account in the Accounts view, with a typed name, a reason and fresh authentication |
identity.password.reset |
Reset a person’s identity provider password |
identity.mailbox.delegate |
Revoke direct mailbox delegation, with step-up and a reason; live Send As grants are blocked in the 0.12.0-rc.3 candidate |
identity.mailbox.fullaccess |
Also allow granting Full Access, together with identity.mailbox.delegate |
identity.account.enable is deliberately its own key on top of
identity.account.manage, not folded into it. Disabling an account is the
reversible, low-stakes off-boarding action wanted at the desk; re-enabling one
restores access to a leaver’s mailbox and is the harder direction to grant.
Administration
Section titled “Administration”| Key | Allows |
|---|---|
user.manage |
Create and deactivate staff accounts |
site.manage |
Create campuses, and set which campuses a person administers |
role.manage |
Create roles and change what they hold |
connector.manage |
Configure connectors and credentials |
assistant.agentforce.use |
Use a separately enabled Salesforce Agentforce advisory connection in the staff assistant (upcoming pilot); also requires client.view and Integrations. Salesforce execution-user permissions determine remote data access |
branding.manage |
Change name, logo and colours |
dashboard.manage |
Publish, update and remove shared team dashboard templates. Personal saved views need no grant |
feature.manage |
Enable and disable modules |
workflow.manage |
Statuses, priorities, types, coverages, parts. From 0.17.1 also the time tracking settings, and editing or deleting anybody’s ticket time and quick time |
billing.manage |
Enter or remove a licence key |
integration.manage |
Issue API keys, manage webhooks |
audit.view |
Read the audit log |
Operations
Section titled “Operations”| Key | Allows |
|---|---|
monitor.view |
See service monitors |
monitor.manage |
Create and configure monitors |
network.view |
See the network estate — switches, access points, uplinks |
network.clients.view |
See where a device was last seen on the network |
network.config.view |
From 0.21.0, read stored network configuration snapshots and the differences between versions, on the Configuration tab of Network |
network.manage |
Refresh from the vendor, map a vendor network to a campus, and from 0.21.0 record subnets and reservations by hand |
backup.view |
See backup history |
backup.manage |
Schedule, run, verify and export backups |
kb.manage |
Write and publish knowledge base articles |
docs.view |
Read internal documentation and search it |
docs.edit |
Write, update, delete and bind documents |
docs.manage |
Spaces, restriction, and publishing a document to the help page |
docs.viewRestricted |
Read restricted spaces, on top of docs.view |
remote.start |
Start a remote session on a device |
remote.manage |
Configure remote access targets |
report.view |
Run and export reports, and the Team view on My time |
report.manage |
Create and schedule reports |
Visitor register
Section titled “Visitor register”From 0.21.0. The visitor and contractor register needs the Facilities module, which comes with the Campus Operations add-on.
| Key | Allows |
|---|---|
visitor.view |
See who is on site, today’s visits, visit history and contractors whose Working With Children Check needs attention |
visitor.manage |
Sign visitors and contractors in and out at the office, record a sighted WWCC, and add or edit visitor records |
visitor.configure |
Register settings: host notification for the school and each campus, WWCC reminder notice and recipients. Also needed to change a contractor into a visitor, and to delete a visitor record |
visitor.view and visitor.manage are free Participant permissions, so a
receptionist who signs people in does not become a paid seat.
visitor.configure is a Technical permission. No built-in role other than
Owner holds any of the three; an administrator grants them.
Projects, school operations and approvals
Section titled “Projects, school operations and approvals”| Permission | Allows |
|---|---|
operations.view |
Read projects, work plans, resources and reservations within the user’s campuses |
operations.manage |
Plan work, manage bookings and purchases, request approval, and export purchasing records |
operations.approve |
Decide assigned project and work approvals; also requires access to the subject |
approvals.view |
Read ticket approval requests, together with ticket access |
approvals.manage |
Request and cancel ticket approvals, together with ticket access |
approvals.decide |
Decide ticket approvals assigned to the user, within their ticket and campus access |
Calendar publication and team updates also require integration.manage. Synced
person onboarding and offboarding planning requires client.view. AV uses the
existing network.view and network.manage permissions. Offline stocktake uses
device.manage; queued scans are checked again against current permissions.
Approval permission does not let someone decide another person’s assigned step. Changing the business request requires approval of the revised details.
The deliberate splits
Section titled “The deliberate splits”These permissions are separate keys on purpose.
ticket.internal separates the desk’s own notes from working the queue. An
internal note is where somebody writes “third time this term, escalate” or “her
mother rang, do not put this in writing”, so a school can hand a casual or a
student helper the queue without handing them that.
charge.raise and charge.approve separate proposing a charge from making
it real. A technician who can propose must not be able to bill a family, and
because the person who decides a family pays is the person who can decide they do
not, waiving sits with approval rather than with raising.
network.clients.view separates where a device was last seen from both the
network estate (network.view) and the device inventory (device.view). Client
sightings are location data about a population that is mostly children, so the key
is one you grant deliberately: no built-in role except Owner holds it, and it is not
a Technician default. Client tracking is off until a school turns it on, and
sightings are kept for 7 days by default (90 at most).
network.config.view separates reading a stored network configuration from
seeing the estate (network.view). The pane says what is up; a configuration is
the firewall rules, the VLAN plan and which wireless network bridges where.
Secrets are removed before anything is stored, but the topology that remains is
still worth protecting. No built-in role except Owner holds it.
visitor.configure separates switching host notification off from reading
or working the register. Whoever may read the on-site list, or sign a visitor
in, cannot thereby stop teachers being told their visitor has arrived.
The ones to be careful with
Section titled “The ones to be careful with”device.wipe.approve makes a wipe happen, which destroys a student’s data
and cannot be undone. It is deliberately split from device.wipe.request, so
the person who asks for a wipe is not, by default, the person who can also
make it happen.
device.laps.read reads a device’s local administrator password — a
credential that grants control of the machine, not just visibility into it.
Live password, MFA and mailbox permissions can change control of an identity
provider account. Re-enabling an account requires both identity.account.manage
and identity.account.enable; Full Access grants require both
identity.mailbox.delegate and identity.mailbox.fullaccess. Grant these keys
selectively. The older directory.manage permission does not substitute for
the separate live identity.* action permissions.
Wildcard
Section titled “Wildcard”A role holding * has every permission within its tenant. There is no permission
anywhere that crosses a tenant boundary.
API key scopes
Section titled “API key scopes”API keys carry scopes from this same set. A key cannot
exceed them, and on the MCP server a key without a permission
does not even see the corresponding tool in tools/list.