Roles & permissions | BondiByte NDIS Software
Security & Identity

Granular, role-based control.

Configure roles and permissions so each user sees and does exactly what they should.

Roles and permissions

What you get with Roles & permissions.

  • Configurable roles

    Shape roles around how your organisation actually works, not a fixed template.

  • Per-permission control

    Grant access down to the individual permission, so people see only what they should.

  • Owner and Admin protections

    Sensitive controls stay with owners and admins, protecting your most important settings.

Why it exists

The problem it solves.

Everyone-is-an-admin is how most small providers start, and it is also how privacy incidents happen. As a team grows you need coordinators who can run rosters without seeing pay details, office staff who can manage documents without touching billing, and support workers limited to their own portal. Getting there should not require a full-time gatekeeper.

How it works

1

Start from the built-in roles

Owner, Admin, Manager and Staff roles cover most teams from day one, each with sensible default permissions you can review at a glance.

2

Create custom roles where you need them

When your organisation has a role the defaults do not fit, create your own, named for how you actually work.

3

Grant access permission by permission

Permissions are grouped by workspace area, rostering, staff, clients, documents, invoicing and more, and you grant each one individually.

4

Assign your people

Give each person the role or roles that match their job. Someone wearing two hats can hold both roles, and their access combines.

5

Reset or retire safely

Built-in roles can be reset to their defaults in one step, custom roles can be removed when no longer needed, and protections stop you from ever locking yourselves out.

What you can do.

System and custom roles

Use the built-in roles as they are, tune them, or add roles of your own shaped around your organisation.

Per-permission control

Grant access down to the individual permission, grouped by area, so each role sees and does exactly what it should.

More than one role per person

People who genuinely do two jobs can hold both roles, with their effective access combining cleanly.

One-step reset to defaults

If a built-in role has drifted, reset it to its defaults rather than reconstructing it permission by permission.

Enforced on the server, not just the screen

Every request is checked against permissions where the data lives, so access rules hold even outside the interface.

Separate staff-facing access

Support workers use the Staff Portal through their own role and linked staff profile, kept apart from manager and admin workspace access.

You stay in control.

Owner and Admin protection

Owner and Admin permissions cannot be edited down, so your organisation always keeps full administration access.

Lockout prevention

At least one active Owner or Admin is always required. You cannot deactivate or strip the last one, even by accident.

Sensitive controls stay senior

Organisation-level and account controls remain with owners, so a generous role grant never exposes your most important settings.

Changes are logged

Configuration changes, including role and access changes, are recorded with who made them and when.

Learn how to use this feature.

Frequently asked questions.

Can a coordinator run rosters without seeing pay or billing?

Yes. Grant the rostering permissions without the pay and invoicing ones, and that is exactly what they will see.

What about someone who wears two hats?

Assign both roles. Their effective access is the combination, so you do not need to invent a third role for every overlap.

Can we accidentally lock ourselves out?

No. BondiByte requires at least one active Owner or Admin at all times, and Owner and Admin permissions are protected from being edited down.

Are permissions just hidden menu items?

No. Permissions are enforced on the server for every request, so what a role cannot do stays impossible regardless of what appears on screen.

How should auditors get access?

Through scoped, time-limited auditor invites in the Audit Centre rather than normal login accounts, so their visibility ends when the review does.

See Roles & permissions in BondiByte

Start your free trial, or book a demo to see it with your own operation in mind.

Start free trial