Read-Only Access — AUDITOR Role and Viewer Accounts
Read-Only Access
Intelligent Roster supports two patterns for people who need to view without editing:
- AUDITOR role (recommended for compliance officers) — Reports, Audit Log, and read-only roster visibility
- STAFF viewer account (legacy pattern) — Living Roster visibility without an employee link
Option A — AUDITOR role (recommended)
Use this for compliance officers, external auditors, or governance staff who need reports and an audit trail without any write access.
How to set up
- Log in as Organisation Admin (or higher)
- Go to Organizations → your organisation → Users tab
- Click Create User (or edit an existing user)
- Set the role to Auditor
- Optionally link an Employee record if the auditor is also a clinical staff member who needs to see their own shifts
- Save and share credentials
What an AUDITOR can do
| Access | Allowed |
|---|---|
| Reports — all export types | ✅ |
| Audit Log modal on the Reports page | ✅ |
| The Living Roster — read-only (staff view when linked to an employee) | ✅ |
| Dashboard, Leave Calendar, Shift Deck (own data when employee-linked) | ✅ |
| Security Settings (password, MFA) | ✅ |
What an AUDITOR cannot do
| Action | Blocked |
|---|---|
| Edit roster, approve leave, approve swaps | ❌ |
| Use IRIS (AI credits / generation) | ❌ |
| Access Vacancy Planning, Master Roster, admin configuration | ❌ |
| Organisations, user management, AI Rules | ❌ |
Note: AUDITOR sits between STAFF and ROSTER BUILDER in the permission model — read-only by design, with explicit access to Reports and the Audit Log that ordinary STAFF do not have.
Option B — STAFF viewer account (roster visibility only)
Use this when someone needs to see the roster but does not need Reports or the Audit Log — for example a Nurse In Charge overseeing coverage without a formal auditor remit.
How to set up
- Log in as Organisation Admin (or higher)
- Go to Organizations → your organisation → Users tab
- Click Create User
- Set the role to STAFF
- Do NOT link an Employee record — leave the Employee field empty
- Save and share credentials
What a STAFF viewer can do
- ✅ View the full Living Roster (all streams and assignments)
- ✅ See the Dashboard, Leave Calendar, and Shift Deck
- ✅ Access their own Security Settings (password, MFA)
What a STAFF viewer cannot do
- ❌ Be assigned to shifts (no employee link = not in the assignment pool)
- ❌ Edit the roster, approve leave, or approve swaps
- ❌ Access admin pages, Vacancy Planning, Master Roster, or Reports
Alternative — Non-rostered craft group
If the viewer needs an employee profile (for auditing purposes), create a craft group called "Observers" or "Non-Clinical" that has no vacancies. Link the user to an employee in that group.
Tips
- Prefer AUDITOR when the person needs compliance exports or the Audit Log — it is clearer in access reviews than a STAFF account with no employee link.
- Permission changes take effect on next login. Log out and back in after role changes.
- For accreditation prep, see Searching Activity Logs and Compliance Reports.