Permissions explained
OnCallRadar uses explicit permissions, not roles. What each one unlocks and how to grant them.
On this page
There are no roles in OnCallRadar — authorization is a set of explicit permissions. This keeps access precise: you grant exactly what someone needs. Permissions exist at two levels and never cross organization boundaries.
Organization permissions
Granted per person on the People page. They scope what someone can do across the whole organization:
- Manage people — invite, edit, and remove people; see the full people list including invited/pending/declined; set timezones and contacts.
- Manage schedules — create schedules and manage their settings and access (this is the org-wide grant; per-schedule access can also be given individually).
- Manage financials — set pay bands and multipliers, and see money in Reports.
- Delegate permissions — grant a *limited* set of permissions to others without being a full people manager. See Delegating permissions.
Schedule permissions
Granted per person on a specific schedule’s access list — they only apply to that schedule:
- Edit periods (self) — propose changes only to shifts assigned to yourself.
- Edit periods (all) — propose changes to anyone’s shifts on the schedule.
- Approve changes — vote on proposals for the schedule.
- Approve own changes — let your own approval count toward quorum on proposals you authored.
A schedule must always have at least one approver, and *required approvals* can never exceed the number of approvers. Access changes that would break either rule are rejected.
The owner (master admin)
Whoever creates the organization is its owner. The owner holds all organization permissions implicitly — they can do everything — and Manage permissions passes every schedule-level check inside the org. You can grant admin-level permissions to others, so an org can have many admins.
Presets
When granting access you’ll see presets (e.g. *Editor*, *Approver*) that expand into a set of permissions to save you clicking each one. Presets are only a convenience at grant time — OnCallRadar stores the resulting permissions, never “which preset”.
Safety guards
- Last-admin guard — you cannot remove the final admin of an organization.
- No self-elevation — you cannot change your own permissions (add or remove). Someone with the right permission and visibility must do it for you. This keeps the audit trail meaningful.