Skip to content

Permissions

The complete set. Permissions are granted through roles, and a role holding * is a superuser within its tenant.

The same checks run on the web console, the REST API, the MCP server and the assistant.

KeyAllows
loan.viewSee loans and who has what
loan.issueIssue a loan device
loan.returnMark a loan returned
loan.manageRegister devices, edit, bulk actions, manage loan groups
KeyAllows
device.viewSee device records and history
device.manageSend MDM commands, including wipe
induction.manageRun inductions, import rosters, record issued devices
KeyAllows
repair.viewSee submissions
repair.createLodge one
repair.updateChange status, priority, assignment, add notes
repair.closeClose one, record outcome and cost
KeyAllows
ticket.viewSee tickets
ticket.createRaise one
ticket.updateChange status, queue, assignment
ticket.commentReply publicly
ticket.internalRead and write internal notes
ticket.closeClose one
KeyAllows
stock.manageMaintain the catalogue and sell items
cost.viewSee cost analytics
cost.exportExport cost data
charge.viewSee damage charges
charge.raisePropose a charge
charge.approveApprove, decline or waive a charge
KeyAllows
client.viewSee people and their profiles
client.manageEdit person records, register cards
directory.viewSearch the identity provider
directory.manageLicences, lock, delegate, reset passwords
KeyAllows
user.manageCreate and deactivate staff accounts
role.manageCreate roles and change what they hold
connector.manageConfigure connectors and credentials
branding.manageChange name, logo and colours
feature.manageEnable and disable modules
workflow.manageStatuses, priorities, types, coverages, parts
billing.manageEnter or remove a licence key
integration.manageIssue API keys, manage webhooks
audit.viewRead the audit log
KeyAllows
monitor.viewSee service monitors
monitor.manageCreate and configure monitors
backup.viewSee backup history
backup.manageSchedule, run, verify and export backups
kb.manageWrite and publish knowledge base articles
report.viewRun and export reports
report.manageCreate and schedule reports

Two permissions exist as separate keys for reasons worth knowing.

ticket.internal separates the desk’s own notes from working the queue. An internal note is where somebody writes “third time this term, escalate” or “her mother rang, do not put this in writing”, so a school can hand a casual or a student helper the queue without handing them that.

charge.raise and charge.approve separate proposing a charge from making it real. A technician who can propose must not be able to bill a family, and because the person who decides a family pays is the person who can decide they do not, waiving sits with approval rather than with raising.

device.manage allows wipes, which destroy a student’s data and cannot be undone.

directory.manage allows password resets and mailbox delegation in your identity provider. It is effectively an account takeover capability.

A role holding * has every permission within its tenant. There is no permission anywhere that crosses a tenant boundary.

API keys carry scopes from this same set. A key cannot exceed them, and on the MCP server a key without a permission does not even see the corresponding tool in tools/list.