Start from the built-in roles
Owner, Admin, Manager and Staff roles cover most teams from day one, each with sensible default permissions you can review at a glance.
Configure roles and permissions so each user sees and does exactly what they should.
Shape roles around how your organisation actually works, not a fixed template.
Grant access down to the individual permission, so people see only what they should.
Sensitive controls stay with owners and admins, protecting your most important settings.
Everyone-is-an-admin is how most small providers start, and it is also how privacy incidents happen. As a team grows you need coordinators who can run rosters without seeing pay details, office staff who can manage documents without touching billing, and support workers limited to their own portal. Getting there should not require a full-time gatekeeper.
Owner, Admin, Manager and Staff roles cover most teams from day one, each with sensible default permissions you can review at a glance.
When your organisation has a role the defaults do not fit, create your own, named for how you actually work.
Permissions are grouped by workspace area, rostering, staff, clients, documents, invoicing and more, and you grant each one individually.
Give each person the role or roles that match their job. Someone wearing two hats can hold both roles, and their access combines.
Built-in roles can be reset to their defaults in one step, custom roles can be removed when no longer needed, and protections stop you from ever locking yourselves out.
Use the built-in roles as they are, tune them, or add roles of your own shaped around your organisation.
Grant access down to the individual permission, grouped by area, so each role sees and does exactly what it should.
People who genuinely do two jobs can hold both roles, with their effective access combining cleanly.
If a built-in role has drifted, reset it to its defaults rather than reconstructing it permission by permission.
Every request is checked against permissions where the data lives, so access rules hold even outside the interface.
Support workers use the Staff Portal through their own role and linked staff profile, kept apart from manager and admin workspace access.
Owner and Admin permissions cannot be edited down, so your organisation always keeps full administration access.
At least one active Owner or Admin is always required. You cannot deactivate or strip the last one, even by accident.
Organisation-level and account controls remain with owners, so a generous role grant never exposes your most important settings.
Configuration changes, including role and access changes, are recorded with who made them and when.
Yes. Grant the rostering permissions without the pay and invoicing ones, and that is exactly what they will see.
Assign both roles. Their effective access is the combination, so you do not need to invent a third role for every overlap.
No. BondiByte requires at least one active Owner or Admin at all times, and Owner and Admin permissions are protected from being edited down.
No. Permissions are enforced on the server for every request, so what a role cannot do stays impossible regardless of what appears on screen.
Through scoped, time-limited auditor invites in the Audit Centre rather than normal login accounts, so their visibility ends when the review does.
Australian data residency, role-based access, and auditability by default.
Security & IdentityProtect sign-ins with a second check from a standard authenticator app, then require it for the accounts that matter most. A stolen password on its own gets an attacker nowhere.
Security & IdentityOwners and admins can preview the workspace exactly as another user's role and permissions render it, read-only, for users at or below their own role level.
Security & IdentityConnect Microsoft Entra single sign-on for your whole team.
Security & IdentitySCIM is the open standard identity systems use to manage user accounts in connected apps. Connect it to Microsoft Entra ID and BondiByte stays in step with your directory: people are provisioned when they join, updated when their details change, and deactivated the moment they leave.
Start your free trial, or book a demo to see it with your own operation in mind.
Hi, I can help with BondiByte features, pricing, setup and more.
Please don’t include sensitive participant or personal information.