Roster Builder Permissions — What You Can and Can't Do
Roster Builder Permissions
Your permissions are the intersection of two lists set by your Org Admin on your Clinician Staff record:
- Editable Craft Groups — the professions you can roster (e.g. RN, EN)
- Editable Streams — the wards you can roster (e.g. Emergency, ICU)
Plus a third list for leave:
- Leave-approval Craft Groups — usually the same as editable, sometimes broader
What you CAN do
| Action | Scope |
|---|---|
| Edit roster cells | (your craft groups) ∩ (your streams) |
| Approve / reject leave | requests from your leave-approval craft groups |
| View rosters | every stream you have view access to |
| Override compliance warnings | inside your areas, with a reason |
| Run IRIS generation | for your areas |
| Manage Vacancy Planning entries | for your streams |
| Manage Master Roster entries | for your streams |
| Approve / reject swaps and open shifts | inside your areas |
| Set your own availability and request leave | always (the clinician hat) |
What you CANNOT do
| Action | Who can |
|---|---|
| Create / archive Streams | Org Admin |
| Create Craft Groups or Scopes | Org Admin |
| Create users / promote roles | Org Admin |
| Edit other Roster Builders' areas | Org Admin |
| Change MFA / SSO policy | Org Admin |
| Approve your own leave | Another Roster Builder or Org Admin |
Worked example
Sarah Chen — Roster Builder
Editable Craft Groups: [RN]
Editable Streams: [Emergency, ICU, Sub-Acute]
Leave-approval Craft Groups: [RN, EN]
✅ Edit RN roster in Emergency
✅ Approve EN leave in any of her streams (broader leave scope)
❌ Edit Doctor roster in Emergency (not her craft group)
❌ Edit RN roster in Surgical (not her stream)
Where to view yours
Profile → tab Roster Permissions. You can see (but not edit) your own permissions.
When these limits actually apply
The two-list model above only starts blocking edits once your organisation has Roster Builder scope enforcement turned on. Before that switch is flipped, roster builders can still see and act on org-wide data — the editable-craft-groups / editable-streams lists are stored on your record but not enforced.
- Org Admins enable enforcement per organisation, usually after they've audited every roster builder's craft-group and stream assignments.
- Once enforcement is on, out-of-scope cells grey out, dropdowns filter to your permitted values, and bulk operations (like bulk delete or Apply Master Roster) silently narrow to just your slice.
- If you're not sure whether enforcement is on for your org, ask your Org Admin — the answer changes what you can do on the roster grid, Bulk Delete, Fill Gaps, and Generate with IRIS.
IRIS and scope enforcement
When Roster Builder scope enforcement is enabled for your organisation, IRIS respects the same boundaries as manual edits:
| IRIS action | Scope behaviour |
|---|---|
| Generate with IRIS (Intelligence Bar) | Route-level enforcement. Only streams in your Editable Streams list. Craft-group pool filters are intersected with your Editable Craft Groups — you cannot roster staff outside your permitted crafts. |
| Fill Gaps (Intelligence Bar modal) | Same stream and craft-group limits as Generate — enforced on the batch suggestions route. |
IRIS chat (generate_roster_batch / fill_gaps_suggestions) | Uses the same permission model when scope enforcement is on. Out-of-scope streams or craft groups return a permission error — contact your Org Admin to expand your permissions, not a workaround. |
| Bulk Reconcile | Search defaults to your permitted streams. Submitting out-of-scope vacancy IDs is rejected. |
| Scope this run filter | Narrows the candidate pool within your permitted area only. It never lets you bypass craft-group or stream restrictions. |
Permission errors you may see
| Error code | Message | What to do |
|---|---|---|
NO_ROSTER_BUILDER_PERMISSIONS | You have no roster-builder permissions assigned. Contact your administrator. | Ask your Org Admin to set Editable Craft Groups and Editable Streams on your Clinician Staff record. |
ROSTER_BUILDER_SCOPE_DENIED (stream) | You do not have permission to generate for this stream (or N of the requested streams) | Pick a stream in your permitted list, or ask your Org Admin to expand your Editable Streams. |
ROSTER_BUILDER_SCOPE_DENIED (craft group) | None of the selected craft groups are within your permitted scope. | Adjust Scope this run craft-group filter to your permitted crafts, or ask your Org Admin to expand Editable Craft Groups. |
Date range via IRIS chat: free-text chat generation is capped (default 42 days / six weeks, IRIS_MAX_GENERATE_DAYS). For longer periods, use the Intelligence Bar Generate with IRIS button, which batches by fortnight, or split the period into smaller requests.
Tips
- If a cell is greyed out, you don't have permission to edit it. Hover and the tooltip will tell you why.
- Permission changes take effect on next login. Log out and back in if your admin just expanded your scope.
- If you can still see org-wide data but expected to be restricted, your Org Admin hasn't enabled scope enforcement yet. The permissions on your record are ready; the switch just hasn't been flipped.
AUDITOR role (read-only compliance)
The AUDITOR role is for compliance officers and governance staff — not roster builders. It is configured on the Users tab, not on Clinician Staff editable craft groups.
| Access | AUDITOR |
|---|---|
| Reports (all exports) | ✅ |
| Audit Log (Reports page) | ✅ |
| Living Roster | Read-only (staff view if employee-linked) |
| Edit roster / approve leave or swaps | ❌ |
| IRIS / AI generation | ❌ |
| Vacancy Planning, Master Roster, admin settings | ❌ |
AUDITOR permissions are not scoped by editable craft groups or streams — the role is organisation-wide read access to reporting surfaces. See Read-Only Access — AUDITOR Role and Viewer Accounts for setup steps.