Skip to main content

Permissions

Understand how system permissions define what each role can access and perform in Diversity Sync’d. This section lists all available permissions and their functions to help administrators assign roles safely and manage user access effectively.

Updated over 2 weeks ago

Permissions (also known as “Rules”) in Diversity Sync’d determine what actions a user can perform and which areas of the system they can access.
Permissions belong to a Role, and once a user is assigned to that Role, they immediately receive all permissions associated with it.

TLDR: Assign Roles carefully — permissions are granted instantly.

Below is a complete list of all available permissions and what each one allows.

Admin

  • The admin tab allows users to configure settings, administrate users, and view activity logs. This section is generally not for support staff and is targeted more towards system administrators & executives.

Admin - Users Tab

  • View the "users" tab in the admin panel

    • Allows a user to view all existing staff members to check their account status, role, or blocked state. This does not include more detailed information about each staff member.

  • Add or remove users from roles from the admin panel

    • Allows users to assign others to pre-configured roles within the "users" tab of the admin section. This permission does not provide access to create, delete, or modify existing roles.

  • Archive or un-archive users from the admin panel

    • Allows users to archive (but not delete) users from the admin panel.

  • Block or unblock users' access to the system from the admin panel

    • Allows users to quickly block staff members' access to the system or re-allow access. This action is instant.

  • Reset users' multi-factor authentication from the admin panel

    • Allows users to reset other users' multi-factor authentication to regain access to the system if a previous method was lost.

Admin - System Logging Tab

  • ⚠ View the logs tab in the admin panel

    • Allows users to view all system logs for all users

Admin - Integrations Tab

  • View the integrations tab in the admin panel

    • This allows users to view what integrations are currently set up, but doesn't allow users to actively manage third-party connections

  • Ability to add and remove integration connections

    • Allows users to manage connected third-party services to the organisation's diversity account

Admin - Roles Tab

  • View the roles tab in the admin panel

    • Allows users to view all existing roles & the users assigned to them. This does not allow access to change people's access throughout the system.

  • ⚠ Create and edit system roles in the admin panel

    • This is a critical permission that allows the ability to assign system access to any other staff member, including themselves. Having this permission functionally serves to make a user a system-wide administrator.

Admin - Billing Tab

  • View the billing tab in the admin panel

    • This permission allows users to manage the organisation's Diversity Sync'd billing configuration. This section is specific to billing for Diversity Sync'd's subscription and is not associated with other areas of billing such as payroll, NDIS invoicing, worker allowances ect.

Admin - Configuration Tab

The configuration tab contains all organisational settings and is not specific to the user accessing this section.

  • View the configuration tab in the admin panel

    • Allows a user access to view the current configuration settings, but does not allow the management of these settings.

  • Make changes to organisational configuration settings in the admin panel

    • This permission allows for the management of organisational-wide configuration settings.

System Entities

The ability to manage work sites, support clients, and staff members is broken up into three sections: sites, staff, & participants. The following permissions pertain to the management of these entities.

Sites

  • View the sites tab

    • This permission allows access to view the sites tab and, as such, open and view each site profile, but not make changes.

  • Make changes to sites

    • Allows access to create and update existing staff profiles.

Staff

Note that this area is different from the staff tab in the administration staff tab. They both are used to manage users, although the staff section is specifically geared towards managing the user data of each staff member opposed to managing system access.

  • View staff profiles

    • This permission allows access to view the staff tab and, as such, open and view each staff profile, but not make changes.

  • Make changes to staff profiles

    • Allows access to create and update existing staff profiles. Since Diversity Sync's billing structure is focused on the number of staff who are active in the system over a period, this action may influence account billing cycles.

  • Make changes to staff positions

    • When updating a staff profile, there is a field pertaining to the staff's position in the organisation. This field is editable to allow for positions to be created and removed. This permission allows users to manage these positions. You do not need this permission to assign a staff member a position, only to update the available options.

Participants

  • ⚠ Make changes to participant access restrictions

    • This is an administrator-level permission that allows a user to assign roles & users to participant profiles. Participant profiles are public by default and become private when assigned. This assignment feeds into the following permissions to further tailor access.

  • View all public & assigned participants

    • This permission allows users to view but not edit participant profiles. The profiles that can be viewed will be all public & assigned profiles (see above)

  • Make changes to participant requirements

    • Make changes to a participant's requirements within a participant's profile. These requirements show up in rostering for staff assignment.

  • View participant groups

    • Allows users to see participant groups within a partipants profile.

  • Make changes to participant groups

    • Allows users to make changes to groups within participant profiles. These groups may influence other participants that some users may not have access to.

Roster

  • Make changes to the roster

    • Allows users to make changes to all shifts on the roster. This permission is aimed at rostering managers for setting up rosters for support workers.

  • Make bulk changes to the roster

    • Allows users to select up to 1000 shifts on the roster and make bulk updates by changing the staff member, participant, site, and other attributes. This permission should only be assigned to high-level rostering managers

  • View the shift hour calculation on the roster

    • Allows the user to see SCHADS-related hour calculation overlaid on the roster. Removing this permission will still show shift durations, but will hide any hour-type breakdowns.

  • Export roster data

    • Allows users to export period views of the roster. This information includes hour breakdowns, participant assignments, and other shift details.

  • Manually clock on or off all shifts

    • Allows users to manually start or stop work for other users via the roster.

  • Shift Logs

    • Allows users to view the shift logs tab within the shift editor. This tab contains the change log events, including who changed what and when. This is a different system log from the application-wide system logging.

  • View shift allowances within the roster

    • Allows users to view the allowance tab in the shift editor. This permission only allows read access but does not allow users to make changes.

  • Make changes to shift allowances within the roster

    • Allows users to update & approve shift allowances & shift allowance requests made by support staff.

  • Make changes to draft shifts

    • Allows users to update the roster, but only update shifts that are in a draft state. These people will not have access to updating all other shifts on the roster.

  • Ability to view shift bid requests

    • This permission allows users to see what staff members have placed bids on open shifts on the roster

  • Ability to approve or deny shift bid requests

    • Allows users access to approving or denying shift bidding requests. This permission is only applicable if the user also has access to view shift bid requests.

  • View location data on shifts

    • Allows users to see the location of shift clock events within the shift editor window.

Storage

The storage section of Diversity is hidden from all users unless the user has access to at least download, upload, delete, or admin storage permissions. By default, all directories in storage are accessible to all users able to view storage. A folder becomes protected when it has been assigned a role or a group of users.

When a folder becomes protected, all its sub-directories fall under the parent directory's protection rules.

  • ⚠ Assign folders to roles and users within storage

    • An administrative permission allowing users to allocate roles & users to storage directories. Allocating users to a directory causes the directory to become locked to that group of people.

  • Download & preview files within storage

    • Allows users to download files that fall under public & user-assigned directories

  • Upload files to storage

    • Allows users to upload files into public & user-assigned directories

  • Delete files within storage

    • Allows users to delete files from public & user-assigned directories. This permission is also required to perform operations that result in the deletion or modification of a file, such as an overwrite, rename, cut, replace ect.

  • Open a document in OneDrive and sync changes back to storage

    • This permission is required to open & sync files into an external OneDrive account. Note - opening a file in OneDrive will create a temporary file in your OneDrive account and only sync back while diversity is open in the background.

Leave

The leave request tab is public by default, although without any additional permissions, users will only see their own leave requests.

  • View all leave requests

    • Allows the user to view not only their own leave requests, but also leave requests from all other users.

  • Create and update leave requests for all users

    • Allows the user to submit leave requests on behalf of other users, update leave request statuses, and comment on leave requests. Note - leave requests must be in an 'Authorized' state before their status can be updated, which is protected by a separate permission

  • Authorize leave requests

    • Users with this permission can authorize leave requests. Typically, a finance manager is given this permission to confirm that employees have sufficient leave balance. Once a leave request has been authorized, its status can be changed by house managers and such.

  • Create leave requests

    • This permission simply enables a user to submit a leave request

  • Edit leave request mail list

    • Enables users to update the mailing list that receives leave request notifications

Finance

  • View staff finance data within staff profiles

    • Allows users to view linked third-party finance accounts associated with users within their staff profile

  • Update user finance accounts

    • Allows users to update assigned third-party finance accounts to staff profiles within the staff section

  • Ability to sync timesheets, pay items, and leave requests with finance software.

    • Allows users to communicate diversity roster, leave request, and hour data to external payroll platforms

  • Make changes within the finance section

    • Allows users to access and make changes to configurations within the finance section, including pay calendars, allowances, leave-types ect.

Messaging

  • Create large conversations in Cora Chat

    • Enables users to create conversations with staff members containing more than 20 users.

  • Show & hide messages within Cora Chat

    • Allows users to toggle messages between being hidden & visible.

  • Create compulsory conversations in Cora Chat

    • Allows users to create conversations in Cora Chat that cannot be left.

  • Create read-only conversations

    • Allows users to create conversations that can only be contributed to by other users with this permission. All other users added to read-only conversations can only read messages and not send messages.

  • Remove users from conversations

    • Allows users to remove other users from conversations.

View Forms
Access support forms.

Store Forms
Save support forms.

Edit Forms
Modify support shift forms.

Email Forms
Send or download support forms.

Delete Forms
Remove support forms.

Registers

View Registers
View registers and shift details.

Edit Registers
Make changes within registers.

Export Register
Export registers within a selected range.

Notice Board

Post Notices
Create and publish announcements.

Continuous Improvement

View Continuous Improvement
View improvement submissions.

Create & Edit Continuous Improvements
Create or update improvement entries.

Shift Notes

Admin View All
View shift note timelines with no restrictions.

Admin Edit All
Edit or create notes without restrictions.

Invocing / Carey

Ability to access NDIS billing and invoicing
View and edit invoicing section.

Did this answer your question?