Skip to content

Permissions

The complete set. Permissions are granted through roles, and a role holding * is a superuser within its tenant.

The same checks run on the web console, the REST API, the MCP server and the assistant.

Key Allows
loan.view See loans and who has what
loan.issue Issue a loan device
loan.return Mark a loan returned
loan.manage Register devices, edit, bulk actions, manage loan groups
Key Allows
device.view See device records and history
device.manage Send MDM commands, other than wipe
device.wipe.request Request a device wipe
device.wipe.approve Approve a requested wipe and make it happen
device.laps.read Read a device’s local administrator password
induction.manage Run inductions, import rosters, record issued devices
Key Allows
repair.view See submissions
repair.create Lodge one
repair.update Change non-closing status, priority, assignment, add notes, record outcome and cost
repair.close Close or delete one
Key Allows
ticket.view See tickets, their logged time, and My time
ticket.create Raise one, including by making quick time into a ticket
ticket.update Change non-closing status, queue, assignment. Also log time, run timers, set an estimate, and edit or delete your own time
ticket.comment Reply publicly
ticket.internal Read and write internal notes
ticket.close Close one
ticket.ingest Receive whole-school mailbox deliveries through an API key: create tickets, add public replies and attachments, and resume waiting tickets on requester replies

Mail intake keys require an unrestricted campus grant. The dedicated permission authorizes routing to enabled, licensed departments through configured mailbox addresses; it grants no general department reading API. Default read-only keys and ordinary ticket write permissions do not authorize intake. Create a dedicated key with ticket.ingest using an account that holds it (or an Owner), then configure that key in the mail gateway. This change is pending beta acceptance.

The beta candidate requires the relevant close permission for a transition to closed through generic edits, actions, bulk operations and external tools. Closing during a merge also requires ticket.close. Editing metadata on an already closed item and reopening it retain their update-permission behavior. Confirm the deployment status.

These controls are a beta preview in the 0.12.0-rc.3 source. Confirm the deployment status and entitlement.

Key Allows
departments.manage School-wide department administration and membership changes, while retaining campus bounds
ticket.transfer Transfer a ticket, also requiring ticket.update and access to both departments

Department membership limits which tickets a staff account can access. Existing ticket action permissions still apply. The restriction that removes legacy ICT access is explicit; broad department administration should not be granted to a department-only worker. Once departments exist, shared ticket/workflow settings also require departments.manage alongside their existing permission. See school departments.

Key Allows
stock.view See stock levels and items
stock.manage Maintain the catalogue and sell items
cost.view See cost analytics
cost.export Export cost data
cost.manage Create, edit and delete cost reporting terms
software.view Read the software contract register; licence-position reports also require identity.view
software.manage Create, edit and delete software contracts and configure renewal email recipients
charge.view See damage charges
charge.raise Propose a charge
charge.approve Approve, decline or waive a charge
Key Allows
client.view See people and their profiles; also opens the assistant
client.manage Edit person records, register cards
directory.view Search the identity provider: the Accounts view of People, and Search all accounts on a person’s page. With client.view, either one shows People in the navigation
directory.manage Licences, lock, delegate, reset passwords on demo directory accounts

Reads, then writes, against a person’s identity provider account — split from directory.* because these reach sign-in history and account state for staff and children, not the licence/mailbox/password actions directory.manage already covers.

Key Allows
identity.view See identity provider state for a person
identity.signins.view See sign-in history — IP address, city and device — for a person
identity.policy.view See identity policy, such as MFA requirements, for a person
identity.mfa.reset Reset a person’s MFA
identity.account.manage Disable a person’s identity provider account
identity.account.enable Re-enable a disabled identity provider account
identity.session.revoke Revoke a person’s active sign-in sessions
identity.license.manage Assign or remove a person’s identity provider licence, on the person’s Account tab or a live Entra account in the Accounts view, with a typed name, a reason and fresh authentication
identity.password.reset Reset a person’s identity provider password
identity.mailbox.delegate Revoke direct mailbox delegation, with step-up and a reason; live Send As grants are blocked in the 0.12.0-rc.3 candidate
identity.mailbox.fullaccess Also allow granting Full Access, together with identity.mailbox.delegate

identity.account.enable is deliberately its own key on top of identity.account.manage, not folded into it. Disabling an account is the reversible, low-stakes off-boarding action wanted at the desk; re-enabling one restores access to a leaver’s mailbox and is the harder direction to grant.

Key Allows
user.manage Create and deactivate staff accounts
site.manage Create campuses, and set which campuses a person administers
role.manage Create roles and change what they hold
connector.manage Configure connectors and credentials
assistant.agentforce.use Use a separately enabled Salesforce Agentforce advisory connection in the staff assistant (upcoming pilot); also requires client.view and Integrations. Salesforce execution-user permissions determine remote data access
branding.manage Change name, logo and colours
dashboard.manage Publish, update and remove shared team dashboard templates. Personal saved views need no grant
feature.manage Enable and disable modules
workflow.manage Statuses, priorities, types, coverages, parts. From 0.17.1 also the time tracking settings, and editing or deleting anybody’s ticket time and quick time
billing.manage Enter or remove a licence key
integration.manage Issue API keys, manage webhooks
audit.view Read the audit log
Key Allows
monitor.view See service monitors
monitor.manage Create and configure monitors
network.view See the network estate — switches, access points, uplinks
network.clients.view See where a device was last seen on the network
network.config.view From 0.21.0, read stored network configuration snapshots and the differences between versions, on the Configuration tab of Network
network.manage Refresh from the vendor, map a vendor network to a campus, and from 0.21.0 record subnets and reservations by hand
backup.view See backup history
backup.manage Schedule, run, verify and export backups
kb.manage Write and publish knowledge base articles
docs.view Read internal documentation and search it
docs.edit Write, update, delete and bind documents
docs.manage Spaces, restriction, and publishing a document to the help page
docs.viewRestricted Read restricted spaces, on top of docs.view
remote.start Start a remote session on a device
remote.manage Configure remote access targets
report.view Run and export reports, and the Team view on My time
report.manage Create and schedule reports

From 0.21.0. The visitor and contractor register needs the Facilities module, which comes with the Campus Operations add-on.

Key Allows
visitor.view See who is on site, today’s visits, visit history and contractors whose Working With Children Check needs attention
visitor.manage Sign visitors and contractors in and out at the office, record a sighted WWCC, and add or edit visitor records
visitor.configure Register settings: host notification for the school and each campus, WWCC reminder notice and recipients. Also needed to change a contractor into a visitor, and to delete a visitor record

visitor.view and visitor.manage are free Participant permissions, so a receptionist who signs people in does not become a paid seat. visitor.configure is a Technical permission. No built-in role other than Owner holds any of the three; an administrator grants them.

Permission Allows
operations.view Read projects, work plans, resources and reservations within the user’s campuses
operations.manage Plan work, manage bookings and purchases, request approval, and export purchasing records
operations.approve Decide assigned project and work approvals; also requires access to the subject
approvals.view Read ticket approval requests, together with ticket access
approvals.manage Request and cancel ticket approvals, together with ticket access
approvals.decide Decide ticket approvals assigned to the user, within their ticket and campus access

Calendar publication and team updates also require integration.manage. Synced person onboarding and offboarding planning requires client.view. AV uses the existing network.view and network.manage permissions. Offline stocktake uses device.manage; queued scans are checked again against current permissions.

Approval permission does not let someone decide another person’s assigned step. Changing the business request requires approval of the revised details.

These permissions are separate keys on purpose.

ticket.internal separates the desk’s own notes from working the queue. An internal note is where somebody writes “third time this term, escalate” or “her mother rang, do not put this in writing”, so a school can hand a casual or a student helper the queue without handing them that.

charge.raise and charge.approve separate proposing a charge from making it real. A technician who can propose must not be able to bill a family, and because the person who decides a family pays is the person who can decide they do not, waiving sits with approval rather than with raising.

network.clients.view separates where a device was last seen from both the network estate (network.view) and the device inventory (device.view). Client sightings are location data about a population that is mostly children, so the key is one you grant deliberately: no built-in role except Owner holds it, and it is not a Technician default. Client tracking is off until a school turns it on, and sightings are kept for 7 days by default (90 at most).

network.config.view separates reading a stored network configuration from seeing the estate (network.view). The pane says what is up; a configuration is the firewall rules, the VLAN plan and which wireless network bridges where. Secrets are removed before anything is stored, but the topology that remains is still worth protecting. No built-in role except Owner holds it.

visitor.configure separates switching host notification off from reading or working the register. Whoever may read the on-site list, or sign a visitor in, cannot thereby stop teachers being told their visitor has arrived.

device.wipe.approve makes a wipe happen, which destroys a student’s data and cannot be undone. It is deliberately split from device.wipe.request, so the person who asks for a wipe is not, by default, the person who can also make it happen.

device.laps.read reads a device’s local administrator password — a credential that grants control of the machine, not just visibility into it.

Live password, MFA and mailbox permissions can change control of an identity provider account. Re-enabling an account requires both identity.account.manage and identity.account.enable; Full Access grants require both identity.mailbox.delegate and identity.mailbox.fullaccess. Grant these keys selectively. The older directory.manage permission does not substitute for the separate live identity.* action permissions.

A role holding * has every permission within its tenant. There is no permission anywhere that crosses a tenant boundary.

API keys carry scopes from this same set. A key cannot exceed them, and on the MCP server a key without a permission does not even see the corresponding tool in tools/list.