02 · User roles & permissions
HappierBiz controls who can see and do what through roles. Every team member has one role, and each role is a set of fine-grained permissions. This lets a front-desk staffer use the roster and read announcements without ever seeing your finances or customer marketing.
The four built-in roles
Every new business starts with four roles. You can edit, rename, reorder and add to these (except where noted).
| Role | Default access | Can be edited? | Can be deleted? |
|---|---|---|---|
| Owner | Everything (full access). | No, Owner is always full access. | No. |
| Manager | Everything by default, runs the business day to day. | Yes. | Yes. |
| Supervisor | A senior-staff subset: create/edit bookings, run-sheet, check-in, calendar, view customers, see & reply to customer messages, post announcements, build the roster & view timesheets, approve shift swaps and leave, complete safety checks, view documents/forms, manage shopping (incl. raising & approving purchase orders), view recipes, see the team directory, and manage tasks. | Yes. | Yes. |
| Staff | A minimal everyday set: read announcements, see customer messages, view roster, see shift requests, request leave, complete safety checks, view documents and forms, view shopping and recipes, and see & complete tasks. | Yes. | No (Staff is a built-in baseline). |
Owner is the only account that can never be locked out of anything. Make sure at least one person you trust holds the Owner role.
Add-on roles ("hats")
Beyond the single base role above, a person can wear zero or more add-on roles (we call them "hats"). A hat stacks on top of their base role rather than replacing it, so a plain Staff member can also be, say, the Payroll Officer or a First Aid Officer. Their effective access is the union of their base role and every hat they wear.
Assign hats at Team → Staff list → open the person → **Add-on roles** (tick
boxes, each with a short note). Base roles are a single choice; hats are
multi-select.
Business-function hats (grant extra access):
- Payroll Officer, holds the Final payroll sign-off plus read access to the time-and-money approvals (timesheets, leave, expenses, purchase orders), without full manager reach. Give it to whoever releases pay under two-step approvals. One or many people can hold it. See Approvals & payroll sign-off.
- HR, people management: the team directory, licences/certs and HR documents, and who's off, without pay sign-off.
Australian designated-role hats (mostly about who the team can find). These are surfaced on the safety board so staff know who to go to, and some grant a little safety access:
- WHS Officer / H&S Rep (WHS Act health & safety representative), runs the safety checks; safety incidents route to them.
- First Aid Officer, a trained first aider.
- Fire / Emergency Warden (AS 3745), leads evacuation.
- Mental Health First Aider, a trained, confidential first point of contact.
- Return to Work Coordinator, supports injured workers back to work (required above certain thresholds in some states).
Each hat is an ordinary role you can edit or rename on the Roles &
permissions screen (Team → Staff list), and you can create your own.
How permissions work
- A role holds a list of permission keys (or "full access" for the Owner).
- A permission is a single right, such as "Create bookings" or "Send marketing campaigns".
- Permissions only appear when their module is switched on. If you don't use Marketing, its permissions don't clutter the roles screen.
- The navigation, dashboard and every page respect permissions: a person only sees a menu item or button if their role allows it.
The full permission catalogue
Permissions are grouped into sections. A section only appears if you've switched on the module it belongs to (sections without a module are always available).
Bookings (module: Bookings)
- View bookings
- Create bookings
- Edit bookings
- Delete / cancel bookings
- Approve booking requests
- View the run-sheet
- Use day-of check-in
- Manage experiences & packages
- Manage spaces & equipment
- Manage class passes (view sold, cancel, refund)
Calendar (module: Calendar)
- View the calendar
Customers (module: Customers)
- View customers
- Add / edit customers
Messages
- See & reply to customer messages
Marketing (module: Marketing)
- View campaigns & audiences
- Send marketing campaigns
Team comms (module: Team comms)
- Read announcements
- Post announcements
Roster & timesheets (module: Roster)
- View the roster
- Build / edit the roster
- View timesheets
- Edit / approve timesheets
- Final payroll sign-off (release pay), the last step that releases pay when two-step approvals are on (timesheets, leave, expenses and purchase orders). Owners and managers hold it by default; the Payroll Officer add-on role also grants it. See Approvals & payroll sign-off.
Shift requests (module: Shift requests)
- View shift requests
- Approve swaps
Leave (module: Leave)
- Request leave & track their own
- See the whole team's leave (who's off)
- Approve leave & edit leave types
Licences & certificates (module: Licences & certificates)
- View licences & certs
- Add / edit licences & certs
Team happiness (module: Team happiness)
- View team happiness
- Manage pulse & recognition
Payments (module: Payments)
- View payments
- Take / charge payments
- Refunds, payouts & bank (Stripe dashboard)
Invoicing (module: Invoicing)
- View invoices
- Create / send invoices
- Raise purchase orders
- Approve purchase orders
Expenses (module: Expenses)
- Submit & track own expenses
- Approve & reimburse expenses
Memberships (module: Memberships)
- View members & plans
- Create plans, cancel members
Accounting export (module: Accounting export)
- View / export accounting
Safety & cleaning (module: Safety)
- View safety checklists
- Complete safety checks
- Build / edit checklists
Documents (module: Documents)
- View documents
- Upload / manage documents
Forms & workflows (module: Forms)
- View / submit forms
- Build forms & manage submissions
Reminders & digests (module: Reminders)
- View reminders & digests
- Configure & send digests
Assets & maintenance (module: Assets)
- View assets
- Add / service assets
Shopping list (module: Shopping)
- View shopping list
- Add / edit shopping items
Recipes & menu (module: Recipes)
- View recipes
- Add / remove recipes
Tasks (module: Tasks)
- See, add & complete tasks
- Edit/delete any task & set up the board
AI assistant (module: AI assistant)
- Use the AI assistant
Business overview (always available)
- View Business Health
Team & roles (always available)
- View the team directory
- Add / edit team members
- Manage roles & permissions
Business settings (always available)
- Edit business settings & branding
- Manage plan & billing
Managing roles
Purpose: Adjust what each role can do, or create your own roles.
When to use it: When the default roles don't match how your business is run, e.g. you want a "Front desk" role that can take bookings and payments but not see marketing.
Required permission: Manage roles & permissions.
Navigation path: Team → Staff list.
Step-by-step, edit a role:
- Go to
Team → Staff list. - Select the role you want to change.
- Tick or untick individual permissions. Sections you see reflect the modules you have on.
- Save. The change applies immediately to everyone with that role.
Step-by-step, create a custom role:
- On the Roles screen, choose to add a new role.
- Give it a clear name (e.g. Front desk).
- Tick the permissions it should have.
- Save, then assign it to team members in
Team → Staff list.
with its permission checkboxes.
Step-by-step, assign a role to a person:
- Go to
Team → Staff list. - Open the team member.
- Change their role and save.
Example use case: A salon wants stylists to manage their own appointments and take payment, but not change prices or see business finances. Create a Stylist role with View/Create/Edit bookings, View customers, Take / charge payments and View roster, and nothing else.
Common mistakes:
- Editing the Owner role, you can't; it's always full access. Use a Manager or custom role for people who need almost everything.
- Forgetting a module gate, a permission won't take effect if the related module is switched off. Turn the module on first (Settings), then grant the permission.
- Removing your own access, if you demote yourself, you may lose the ability to manage roles. Keep one trusted Owner.
Troubleshooting:
| Problem | Fix |
|---|---|
| A staff member can't see a page they should | Check both the module is on and their role has the matching permission. |
| A permission section is missing on the Roles screen | The module it belongs to is switched off, enable it in Settings. |
| Someone has too much access | Move them to a more limited role, or untick specific permissions on their role. |
Next: The dashboard & navigation.