Skip to content
EntryWick documentation

For an owner (or somebody the owner gave the Roles permission) whose team does not fit the eight built-in.

Roles

Settings → Roles, and Team → Role. Growth plan and above for roles of your own. Spec: docs/CUSTOMIZATION_MODEL.md §6, docs/PRICING_ENTITLEMENTS.md §7 (custom_roles).

Who opens it: an owner (or somebody the owner gave the Roles permission) whose team does not fit the eight built-in roles — a volunteer who only prints badges for their own group, a desk that registers walk-ups and scans. What they came to do: make a role that can do exactly what the job needs, and nothing more, then give it to people. What must be true when they leave: everybody holding the role lands on a page they can open, sees only their group if the role says so, and cannot do anything the role does not grant.

The page

Every role is listed: the eight system roles (read-only — Permissions shows what they hold) and the organization's own. For each: whether it covers the whole organization or one group, the page it lands on, whether it scans and overrides, and how many people hold it.

  • New role — start from nothing, or pick a system role under Start from to fill in its permissions, scope, page and scanning.
  • Copy — on any row: a new role with that role's settings, to change. This is how a system role is adjusted.
  • Edit / Remove — on your own roles. The code cannot change (check-in points and messages name the role by it).

A role is:

  • Permissions — ticked per area (Events, Registrations, Attendees, Tickets, Checkin, …). Billing is never offered: it stays with the Owner.
  • ScopeWhole organization, or a group per member: each person's own scope on the Team page decides. One group, always: everybody given the role must be given a group, and sees that group and every group below it.
  • Lands on — Dashboard; Their group (one-group roles only); Scanner (roles that scan); Reports, Payments, Developers (roles that can read them).
  • Can scan / Can override — must match the Checkin: Scan and Checkin: Override permissions. Override needs scanning.

Giving a role

Invite on the Team page, or change somebody's role with Role on their row. A role limited to one group asks for the group. Single sign-on cannot give a one-group role, because nobody is there to choose the group.

Refused, and why

  • A page the role could not open, or scanning and permissions that disagree — fix the setting named.
  • You cannot give / make / change a role that can do more than you can — nobody hands out permissions, scanning or overriding they do not hold themselves. Somebody limited to a group places people inside that group only.
  • N people hold this role — a role in use cannot be removed; give them another role first. A role single sign-on gives to newcomers cannot be removed either until another is chosen there.
  • N people hold this role without a group — a role cannot become One group, always while somebody holds it with no group.

On a plan without custom roles

New role says which plan has it. Roles already made keep working for the people who hold them and can still be given and removed; they cannot be edited or copied.

Printing inside a group

A one-group role with Tickets: Print prints badges on Events → Badge runs for its group and the groups below it only — Everyone means everyone they can see — and sees and downloads only the packs printed inside the group.

Every change to a role, and every change to who holds which role, is in the audit log.