Security, Roles, and Access
Give the right people the right access.
Roles control manager/admin workspace access, staff-facing portal access, and scoped auditor access paths.
Before you begin
Before configuring Roles & Access, make sure you have:
- Identified who requires administrative or management access.
- Determined which users only require Staff Portal access.
- Created or prepared staff profiles for employees who will use the Staff Portal.
- Decided who will act as your Owner or Administrator.
Recommended setup order
For the best experience, we recommend configuring Roles & Access in the following order.
1 Confirm an Owner or Administrator
Ensure your organisation always has at least one active Owner or Administrator account. These roles are responsible for managing workspace configuration, users and operational settings.
2 Create user login accounts
Create login accounts for each person who requires access to the BondiByte platform.
Each login account provides an individual sign-in and should never be shared between users.
3 Assign user roles
Assign the appropriate role based on each user's responsibilities.
Available roles include:
- Owner
- Administrator
- Manager
- Staff
Selecting the correct role ensures users only have access to the areas required for their job.
4 Link Staff Portal users
If a user requires access to the Staff Portal, their login account must be linked to an active staff profile.
Without this link, Staff Portal features such as availability, documents, timesheets and rostering will not be available.
5 Invite auditors
When providing access for auditors, use the Audit Centre Auditor Invite feature rather than creating a standard login account.
This provides secure, controlled access specifically for audit purposes.
6 Separate platform administration
Keep platform administration separate from your organisation's day-to-day workspace access.
This helps maintain better governance, improves security and ensures administrative permissions are only provided where required.
Understanding user roles
Owner
The highest level of access within your organisation, responsible for organisation-wide settings, account management and administrative controls.
Administrator
Provides full workspace administration, allowing users to configure operational settings and manage day-to-day platform administration.
Manager
Designed for operational managers who oversee staff, participants, rostering and other day-to-day workflows without requiring full administrative control.
Staff
A staff-facing role that provides access to the Staff Portal for self-service functions such as viewing rosters, updating availability, accessing documents and completing timesheets.
Login Account
A unique user account that allows an individual to securely sign in to the BondiByte platform.
Staff Profile
The employee record used throughout BondiByte for rostering, qualifications, availability, documents, timesheets and Staff Portal access.
Auditor Invite
A secure, limited-access invitation designed specifically for auditors using the Audit Centre. This is separate from standard user login accounts.
Best practice
- Assign user roles before inviting large groups of staff.
- Limit Owner and Administrator access to trusted personnel who require these permissions.
- Ensure every Staff Portal user is linked to an active staff profile before providing access.
- Regularly review user permissions to ensure they remain appropriate as staff roles change.
- Use Auditor Invites for audit access instead of creating permanent user accounts.
Common mistakes to avoid
- Assigning a Staff Portal role without linking the user to an active staff profile.
- Creating standard login accounts for auditors instead of using Auditor Invites.
- Granting unnecessary administrative permissions to staff members.
- Confusing platform administration with day-to-day workspace access.
- Sharing login accounts between multiple users instead of providing individual access.
What to do next
Related guides
Staff
Create and manage staff in BondiByte: CSV import, employment and rostering settings, staff availability, leave, unavailability and time off, evidence-backed capabilities, compliance documents, login access, and site relationships.
Staff WorkflowsStaff Portal
Set up staff self-service in the browser Staff Portal and in the BondiByte Staff app for iPhone and Android: shifts, staff availability, leave and time off, shift interest, swaps, cancellations, timesheets, reports, documents, notifications, and profile details.
Audit, Documents, and EvidenceAudit Centre
Live audit readiness score, compliance checks and enforcement, the Prepare Audit wizard, evidence packs, NDIS Practice Standards mapping, secure auditor portal, staff ratings, and audit sessions.
Need help applying this setup path?
Book a BondiByte demo and we can walk through the right setup order for your provider.