[{"data":1,"prerenderedAt":1545},["ShallowReactive",2],{"help:\u002Fhelp\u002Foperations\u002Frecord-and-follow-up-on-incidents":3,"help-all-categories":320,"help-cat-articles:\u002Fhelp\u002Foperations\u002Frecord-and-follow-up-on-incidents":439,"help-related:\u002Fhelp\u002Foperations\u002Frecord-and-follow-up-on-incidents":440},{"id":4,"title":5,"audience":6,"body":7,"category":299,"description":300,"draft":301,"extension":302,"icon":303,"keywords":304,"meta":310,"navigation":311,"order":312,"path":313,"related":314,"seo":316,"stem":317,"updatedAt":318,"__hash__":319},"help\u002Fhelp\u002Foperations\u002Frecord-and-follow-up-on-incidents.md","Record and follow up on venue incidents","clinic",{"type":8,"value":9,"toc":280},"minimark",[10,17,20,29,34,41,77,85,88,92,177,180,184,191,204,207,210,214,225,228,232,239,246,253,257,267,270,273,277],[11,12,13],"p",{},[14,15,16],"strong",{},"Operations → Incidents",[11,18,19],{},"Use Incidents to keep a record of something that happened at your venue: what occurred, who was involved, what your team did, and what still needs attention. An incident can concern a client, a visitor without a client record, or an event with no identifiable person.",[11,21,22,23,28],{},"This is separate from the confidential HR log on a team member's profile. For attendance, performance, or employee conduct records, see ",[24,25,27],"a",{"href":26},"\u002Fhelp\u002Fteam\u002Flog-an-employee-incident","Log an employee incident",".",[30,31,33],"h2",{"id":32},"who-can-use-incidents","Who can use Incidents?",[11,35,36,37,40],{},"Access follows your role's ",[14,38,39],{},"Incidents"," permissions:",[42,43,44,57],"table",{},[45,46,47],"thead",{},[48,49,50,54],"tr",{},[51,52,53],"th",{},"Permission",[51,55,56],{},"What you can do",[58,59,60,69],"tbody",{},[48,61,62,66],{},[63,64,65],"td",{},"View",[63,67,68],{},"Read the incident list and individual records.",[48,70,71,74],{},[63,72,73],{},"Manage",[63,75,76],{},"View records, file incidents, update the response, close or reopen a matter, and download reports.",[11,78,79,80,84],{},"Client access and blocking have separate permissions. Being able to file an incident does not give you access to every client's profile or contact details. Ask an administrator to review ",[24,81,83],{"href":82},"\u002Fhelp\u002Fsettings\u002Froles-and-permissions","Roles and permissions"," if an action is missing.",[11,86,87],{},"Incident records are internal. They are not displayed to the person named in the client portal.",[30,89,91],{"id":90},"file-an-incident","File an incident",[93,94,95,100,110,114,117,121,136,140,154,157,161,164,167,171],"steps",{},[96,97,99],"h3",{"id":98},"open-the-form","Open the form",[11,101,102,103,105,106,109],{},"Go to ",[14,104,16],{}," and choose ",[14,107,108],{},"File incident",". On mobile, use the add button in the page header.",[96,111,113],{"id":112},"record-when-and-where-it-happened","Record when and where it happened",[11,115,116],{},"Enter the date and time the event occurred. You can record a past event, but not a future one. Check the location, especially if your business has several venues. The form may select your active location or your only location automatically.",[96,118,120],{"id":119},"identify-the-subject","Identify the subject",[11,122,123,124,127,128,131,132,135],{},"Choose an existing ",[14,125,126],{},"client",", a ",[14,129,130],{},"visitor",", or ",[14,133,134],{},"no identifiable person",". For a visitor, provide a name or a factual description. You do not need to create a client account just to document an event.",[96,137,139],{"id":138},"describe-the-event","Describe the event",[11,141,142,143,146,147,131,150,153],{},"Choose a category and a severity of ",[14,144,145],{},"minor",", ",[14,148,149],{},"serious",[14,151,152],{},"critical",". Add a short summary and a detailed description of what happened.",[11,155,156],{},"Categories cover solicitation of sexual services, harassment, threats or violence, theft, payment issues, intoxication, property damage, trespass, safety, privacy, and other events.",[96,158,160],{"id":159},"record-the-response-and-people-involved","Record the response and people involved",[11,162,163],{},"Add any action already taken and any planned follow-up. If police were notified, record that and add the police reference if available. This records a notification you have already made; it does not contact the police.",[11,165,166],{},"You can add witnesses, affected people, and responders. Select a staff member or enter another person's name, with relevant contact information and notes. A record supports up to 20 people in this section.",[96,168,170],{"id":169},"review-and-file","Review and file",[11,172,173,174,28],{},"Check the subject, time, category, severity, description, and people before saving. The record receives an incident reference, identifies who filed it, and starts as ",[14,175,176],{},"Open",[11,178,179],{},"Write observable facts and distinguish what you witnessed from what someone told you. For example, “At 14:10, the visitor knocked a display onto the floor; Alex witnessed it” is more useful than a judgement about the visitor's character. Include only information needed to document the event and the response.",[30,181,183],{"id":182},"update-the-response","Update the response",[11,185,186,187,190],{},"Open the incident and select ",[14,188,189],{},"Edit response",". You can update:",[192,193,194,198,201],"ul",{},[195,196,197],"li",{},"Action taken.",[195,199,200],{},"Planned follow-up.",[195,202,203],{},"Whether police were notified and the police reference.",[11,205,206],{},"Save your changes when finished. Follow-up is a written record; it does not automatically schedule a task or send a reminder.",[11,208,209],{},"The original narrative, subject, category, severity, date, location, and people involved cannot be edited after filing. If you need to correct or clarify the original account, explain the correction in the follow-up, with a date and context, so readers can understand what changed.",[30,211,213],{"id":212},"close-or-reopen-the-matter","Close or reopen the matter",[11,215,216,217,220,221,224],{},"Choose ",[14,218,219],{},"Close incident"," when the required response is complete. Closing keeps the record available; it does not delete it. Choose ",[14,222,223],{},"Reopen incident"," if further attention is needed.",[11,226,227],{},"Use the incident list's status and category filters to find open matters or review similar events.",[30,229,231],{"id":230},"block-a-client-when-appropriate","Block a client when appropriate",[11,233,234,235,238],{},"Filing an incident does ",[14,236,237],{},"not"," automatically block the client.",[11,240,241,242,245],{},"For a linked client, users with the required client-management permission can choose ",[14,243,244],{},"Block client",". The block form suggests a reason and includes the incident reference. Review and confirm it separately. Some reasons, including the safety designation, require additional authority.",[11,247,248,249,28],{},"The incident shows the client's current blocked status. Closing the incident does not unblock the client. Manage that separately using ",[24,250,252],{"href":251},"\u002Fhelp\u002Fclients\u002Fblocked-and-flagged-clients","Blocked and flagged clients",[30,254,256],{"id":255},"download-a-report","Download a report",[11,258,259,260,262,263,266],{},"Users with ",[14,261,73],{}," permission can choose ",[14,264,265],{},"Download report"," to save a PDF. The report includes the incident record and your business branding, where configured. Its timestamps use the incident location's time zone, falling back to the business time zone and then UTC.",[11,268,269],{},"The download is recorded in the audit log. Client contact and sensitive details follow the exporting user's permissions, so a report may omit information the user cannot access. Review the PDF before sharing it through your business's chosen process. Downloading does not send it to police, insurers, or the client.",[11,271,272],{},"Repeated exports are limited. If you see a message about too many reports, wait before trying again.",[30,274,276],{"id":275},"why-can-i-no-longer-open-a-record","Why can I no longer open a record?",[11,278,279],{},"Your role may no longer have access, you may be in a different organization, or the linked client's record may have been restricted following an erasure request. A restricted record cannot be opened or exported through the ordinary incident screens. Ask your administrator to review the restriction rather than creating a duplicate record to bypass it.",{"title":281,"searchDepth":282,"depth":282,"links":283},"",2,[284,285,294,295,296,297,298],{"id":32,"depth":282,"text":33},{"id":90,"depth":282,"text":91,"children":286},[287,289,290,291,292,293],{"id":98,"depth":288,"text":99},3,{"id":112,"depth":288,"text":113},{"id":119,"depth":288,"text":120},{"id":138,"depth":288,"text":139},{"id":159,"depth":288,"text":160},{"id":169,"depth":288,"text":170},{"id":182,"depth":282,"text":183},{"id":212,"depth":282,"text":213},{"id":230,"depth":282,"text":231},{"id":255,"depth":282,"text":256},{"id":275,"depth":282,"text":276},"operations","File a factual record of a venue incident, document your response, close or reopen the matter, and download a report.",false,"md","i-lucide-siren",[305,306,307,308,309],"venue incident report","client incident","visitor safety harassment theft","police insurance report pdf","incident follow up",{},true,40,"\u002Fhelp\u002Foperations\u002Frecord-and-follow-up-on-incidents",[251,26,82,315],"\u002Fhelp\u002Foperations\u002Fpolicies",{"title":5,"description":300},"help\u002Foperations\u002Frecord-and-follow-up-on-incidents","2026-09-19","6GIwILJ6dpgkEdmPZDgQVBq7Qffa4rqC-KPs7z3TCWY",[321,332,341,350,360,370,379,389,399,409,419,429],{"id":322,"title":323,"audience":6,"description":324,"extension":325,"icon":326,"meta":327,"order":328,"slug":329,"stem":330,"__hash__":331},"helpCategories\u002Fhelp\u002Fcategories\u002Fgetting-started.yml","Getting started","Set up your workspace, learn the layout, and run your first day.","yml","i-lucide-compass",{},1,"getting-started","help\u002Fcategories\u002Fgetting-started","lTnfg_2tKvxQ9QanJ9XY3shoBHrJNWNfnxhcYaaKKPI",{"id":333,"title":334,"audience":6,"description":335,"extension":325,"icon":336,"meta":337,"order":282,"slug":338,"stem":339,"__hash__":340},"helpCategories\u002Fhelp\u002Fcategories\u002Fcalendar.yml","Calendar & booking","Book, move, and cancel appointments. Block time, work the waitlist, and read the grid at a glance.","i-lucide-calendar",{},"calendar","help\u002Fcategories\u002Fcalendar","s5UMHzRIeTUFi7mdsOyuSluzJBp79U9WTsTpOtbaW-E",{"id":342,"title":343,"audience":6,"description":344,"extension":325,"icon":345,"meta":346,"order":288,"slug":347,"stem":348,"__hash__":349},"helpCategories\u002Fhelp\u002Fcategories\u002Fcheckout.yml","Checkout & payments","Ring up a sale, take tips, handle deposits and fees, issue refunds, and close the drawer.","i-lucide-credit-card",{},"checkout","help\u002Fcategories\u002Fcheckout","4PQPgJd7Z25g0SvtoqqdMlnzk3DlcJpaZhNAiNiYVW0",{"id":351,"title":352,"audience":6,"description":353,"extension":325,"icon":354,"meta":355,"order":356,"slug":357,"stem":358,"__hash__":359},"helpCategories\u002Fhelp\u002Fcategories\u002Fclients.yml","Clients & forms","Add and find clients, read a client profile, and send forms and consents.","i-lucide-users",{},4,"clients","help\u002Fcategories\u002Fclients","u-tqzEJo2gR_wJ7x7y-EMIF3L4TP9EuBWlamwgwCC0I",{"id":361,"title":362,"audience":6,"description":363,"extension":325,"icon":364,"meta":365,"order":366,"slug":367,"stem":368,"__hash__":369},"helpCategories\u002Fhelp\u002Fcategories\u002Fretail.yml","Memberships, packages & gift cards","The things clients buy once and spend down over time, and how each one behaves at checkout.","i-lucide-gift",{},5,"retail","help\u002Fcategories\u002Fretail","wVVr_rc_P9p2RZWwy0XKsNB9fQ7XtQxxIz4qnixkGkg",{"id":371,"title":372,"audience":6,"description":373,"extension":325,"icon":374,"meta":375,"order":376,"slug":299,"stem":377,"__hash__":378},"helpCategories\u002Fhelp\u002Fcategories\u002Foperations.yml","Operations","The internal side of the business, covering your written playbook, task boards, venue incidents, and the policies everyone signs.","i-lucide-briefcase",{},6,"help\u002Fcategories\u002Foperations","kSPRTYYbOW5LBNuaYXGv0C4IE7BqS2n-OkCSI97f-cM",{"id":380,"title":381,"audience":6,"description":382,"extension":325,"icon":383,"meta":384,"order":385,"slug":386,"stem":387,"__hash__":388},"helpCategories\u002Fhelp\u002Fcategories\u002Fteam.yml","Team & scheduling","Working hours, the weekly roster, clock-in, timesheets, and time off.","i-lucide-id-card",{},7,"team","help\u002Fcategories\u002Fteam","1cMbCRwUmewb4t_DwUJ7jJUjntx-odU8jRDgBredsPs",{"id":390,"title":391,"audience":6,"description":392,"extension":325,"icon":393,"meta":394,"order":395,"slug":396,"stem":397,"__hash__":398},"helpCategories\u002Fhelp\u002Fcategories\u002Fgrowth.yml","Reports & growth","Read the numbers, export them, and find the report you actually need.","i-lucide-trending-up",{},8,"growth","help\u002Fcategories\u002Fgrowth","3XyCU-DkoYi7xSPz0tDRohlYkNBUS0YsLo-insknI8o",{"id":400,"title":401,"audience":6,"description":402,"extension":325,"icon":403,"meta":404,"order":405,"slug":406,"stem":407,"__hash__":408},"helpCategories\u002Fhelp\u002Fcategories\u002Fsettings.yml","Settings & admin","Services and pricing, who can see what, and moving your data in from another system.","i-lucide-settings",{},9,"settings","help\u002Fcategories\u002Fsettings","rdLQHp7tfAu5iySbsypfXu1kOuujDAuLVk6yGidNvtQ",{"id":410,"title":411,"audience":6,"description":412,"extension":325,"icon":413,"meta":414,"order":415,"slug":416,"stem":417,"__hash__":418},"helpCategories\u002Fhelp\u002Fcategories\u002Faccount.yml","Your login and profile","Your own login, password, two-factor security, profile, and language.","i-lucide-user-circle",{},10,"account","help\u002Fcategories\u002Faccount","8JZPH_8Q-lnEEFgysE9gCwyd1pzUe2hfAebATuQ5Pog",{"id":420,"title":421,"audience":126,"description":422,"extension":325,"icon":423,"meta":424,"order":425,"slug":426,"stem":427,"__hash__":428},"helpCategories\u002Fhelp\u002Fcategories\u002Fbook-online.yml","Book online","Booking, paying, and managing your visit from your venue's booking page and the private links they send you.","i-lucide-globe",{},20,"book-online","help\u002Fcategories\u002Fbook-online","dUBIoELt-ci1vqbw_VX1VA6PGJV8V-9x4ZmpAk1aXXE",{"id":430,"title":431,"audience":126,"description":432,"extension":325,"icon":433,"meta":434,"order":435,"slug":436,"stem":437,"__hash__":438},"helpCategories\u002Fhelp\u002Fcategories\u002Fportal.yml","Your account and visits","Booking from your account, managing your visits, and using your wallet, memberships and rewards.","i-lucide-user-round",{},21,"portal","help\u002Fcategories\u002Fportal","D8_zQhv9hO2b9PYDADw-ebh1yZUuC0UcBt3DDZbMAH4",[],[441,643,790,1246],{"id":442,"title":252,"audience":6,"body":443,"category":357,"description":627,"draft":301,"extension":302,"icon":628,"keywords":629,"meta":636,"navigation":311,"order":637,"path":251,"related":638,"seo":639,"stem":640,"updatedAt":641,"__hash__":642},"help\u002Fhelp\u002Fclients\u002Fblocked-and-flagged-clients.md",{"type":8,"value":444,"toc":612},[445,448,452,519,522,526,529,567,571,577,587,591,595,598,602,605,609],[11,446,447],{},"Blocking a client stops them booking online and receiving marketing, while keeping their record and history intact. It's a soft block: staff can still book them deliberately, and nothing already on the calendar is touched.",[30,449,451],{"id":450},"what-does-blocking-a-client-actually-do","What does blocking a client actually do?",[42,453,454,464],{},[45,455,456],{},[48,457,458,461],{},[51,459,460],{},"Surface",[51,462,463],{},"Blocked client",[58,465,466,476,486,496,509],{},[48,467,468,473],{},[63,469,470],{},[14,471,472],{},"Online \u002F portal booking",[63,474,475],{},"Refused",[48,477,478,483],{},[63,479,480],{},[14,481,482],{},"Marketing emails and SMS",[63,484,485],{},"Stopped",[48,487,488,493],{},[63,489,490],{},[14,491,492],{},"Staff booking at the desk",[63,494,495],{},"Allowed, with a warning you can override — the override is audited",[48,497,498,503],{},[63,499,500],{},[14,501,502],{},"Existing future appointments",[63,504,505,508],{},[14,506,507],{},"Untouched"," — never auto-cancelled",[48,510,511,516],{},[63,512,513],{},[14,514,515],{},"Their record and history",[63,517,518],{},"Fully intact",[11,520,521],{},"When you block, any upcoming appointments are listed for you to review — cancel them yourself if that's the intent; Owneli won't decide for you.",[30,523,525],{"id":524},"how-do-i-block-a-client","How do I block a client?",[11,527,528],{},"You need permission to manage clients.",[93,530,531,535,538,542,553,557,560,564],{},[96,532,534],{"id":533},"open-the-client-and-choose-block","Open the client and choose Block",[11,536,537],{},"From the profile panel's header actions.",[96,539,541],{"id":540},"pick-a-reason","Pick a reason",[11,543,544,545,548,549,552],{},"Choose from the fixed list — repeated no-shows, payment issues, behaviour, and so on. ",[14,546,547],{},"Other"," requires a note explaining it. The ",[14,550,551],{},"Safety concern"," reason is reserved for admins and owners, because it carries more weight and more liability.",[96,554,556],{"id":555},"add-a-note-and-an-optional-review-date","Add a note and an optional review date",[11,558,559],{},"The note is internal. A review date is a nudge to reconsider the block later — it doesn't auto-unblock.",[96,561,563],{"id":562},"confirm","Confirm",[11,565,566],{},"The profile header now shows the block, when it was applied, and by whom. If the client has upcoming appointments, the confirmation tells you how many to review.",[30,568,570],{"id":569},"unblock","Unblock",[11,572,573,574,576],{},"Open the same panel on a blocked client and choose ",[14,575,570],{},". The block details are cleared and online booking works again. A safety-concern block can only be lifted by an admin or owner.",[578,579,580],"tip",{},[11,581,582,583,28],{},"Blocking is not deleting. If the goal is removing the person's data rather than refusing service, see ",[24,584,586],{"href":585},"\u002Fhelp\u002Fclients\u002Fdelete-a-client","Delete a client",[30,588,590],{"id":589},"common-questions","Common questions",[96,592,594],{"id":593},"will-the-client-know-theyre-blocked","Will the client know they're blocked?",[11,596,597],{},"They aren't notified. They'll simply find online booking unavailable to them; how you communicate the decision is up to you.",[96,599,601],{"id":600},"why-did-a-blocked-client-still-show-up-on-the-calendar","Why did a blocked client still show up on the calendar?",[11,603,604],{},"Either the appointment predated the block — existing bookings are never auto-cancelled — or a staff member booked them past the warning, which the audit trail records.",[96,606,608],{"id":607},"does-the-review-date-unblock-automatically","Does the review date unblock automatically?",[11,610,611],{},"No. It's a reminder for a human decision; the block stays until someone lifts it.",{"title":281,"searchDepth":282,"depth":282,"links":613},[614,615,621,622],{"id":450,"depth":282,"text":451},{"id":524,"depth":282,"text":525,"children":616},[617,618,619,620],{"id":533,"depth":288,"text":534},{"id":540,"depth":288,"text":541},{"id":555,"depth":288,"text":556},{"id":562,"depth":288,"text":563},{"id":569,"depth":282,"text":570},{"id":589,"depth":282,"text":590,"children":623},[624,625,626],{"id":593,"depth":288,"text":594},{"id":600,"depth":288,"text":601},{"id":607,"depth":288,"text":608},"Block a client from booking online, what a block does and doesn't stop, and how to set a review date or lift the block later.","i-lucide-ban",[630,631,632,633,634,635],"block a client","stop client booking online","client no show repeatedly","unblock client","ban client from salon","safety concern client",{},60,null,{"title":252,"description":627},"help\u002Fclients\u002Fblocked-and-flagged-clients","2026-08-14","jJfqZnt87bvJ2WmgwWEl9cdAX-RrO5YKTn8VboZMrhw",{"id":644,"title":27,"audience":6,"body":645,"category":386,"description":776,"draft":301,"extension":302,"icon":777,"keywords":778,"meta":784,"navigation":311,"order":785,"path":26,"related":786,"seo":787,"stem":788,"updatedAt":641,"__hash__":789},"help\u002Fhelp\u002Fteam\u002Flog-an-employee-incident.md",{"type":8,"value":646,"toc":762},[647,650,655,659,715,718,724,728,735,737,741,744,748,751,755],[11,648,649],{},"The incident log is a confidential HR record on each team member's panel: what happened, how serious it was, and what you did about it. Only admins and owners can see or write it — the person it concerns never sees the tab.",[11,651,652,653,28],{},"For an event involving a client, visitor, or the venue itself, use ",[24,654,5],{"href":313},[30,656,658],{"id":657},"how-do-i-record-an-incident","How do I record an incident?",[93,660,661,665,674,678,689,693,708,712],{},[96,662,664],{"id":663},"open-the-incidents-tab","Open the Incidents tab",[11,666,667,670,671,673],{},[14,668,669],{},"Team"," → click the member → ",[14,672,39],{},". The tab is only visible to admins and owners.",[96,675,677],{"id":676},"add-the-incident","Add the incident",[11,679,680,681,684,685,688],{},"Pick a ",[14,682,683],{},"category"," — attendance, conduct, performance, safety, client complaint, policy, or other — and a ",[14,686,687],{},"severity",": minor, serious, or gross.",[96,690,692],{"id":691},"describe-it","Describe it",[11,694,695,696,699,700,703,704,707],{},"Set the date and time it occurred and write what happened. Optional fields capture the ",[14,697,698],{},"business impact",", the ",[14,701,702],{},"action taken",", and any ",[14,705,706],{},"follow-up"," planned.",[96,709,711],{"id":710},"save","Save",[11,713,714],{},"The incident joins the member's log, timestamped and attributed to you.",[11,716,717],{},"Backdating is expected — you're documenting something that already happened — but an incident can't be dated in the future.",[719,720,721],"warning",{},[11,722,723],{},"Incidents are confidential HR records. Write them as you'd want them read in a dispute: factual, dated, specific, and free of speculation. The log can be exported when you need the full record.",[30,725,727],{"id":726},"marking-an-incident-as-protected","Marking an incident as protected",[11,729,730,731,734],{},"An incident can be flagged ",[14,732,733],{},"protected"," for particularly sensitive records. ",[30,736,590],{"id":589},[96,738,740],{"id":739},"can-the-employee-see-their-incident-log","Can the employee see their incident log?",[11,742,743],{},"No. Incidents are admin\u002Fowner-only and are never shown to the subject inside Owneli. Whether and how you share them is your HR process, not the software's.",[96,745,747],{"id":746},"should-every-complaint-become-an-incident","Should every complaint become an incident?",[11,749,750],{},"Use the log for things you'd want a dated record of — patterns of lateness, a client complaint, a safety event. One-off coaching conversations usually don't need one.",[96,752,754],{"id":753},"how-does-this-relate-to-offboarding","How does this relate to offboarding?",[11,756,757,758,28],{},"They're independent, but a well-kept incident log is what makes a termination defensible. See ",[24,759,761],{"href":760},"\u002Fhelp\u002Fteam\u002Fsuspend-archive-or-offboard-a-team-member","Suspend, archive, or offboard a team member",{"title":281,"searchDepth":282,"depth":282,"links":763},[764,770,771],{"id":657,"depth":282,"text":658,"children":765},[766,767,768,769],{"id":663,"depth":288,"text":664},{"id":676,"depth":288,"text":677},{"id":691,"depth":288,"text":692},{"id":710,"depth":288,"text":711},{"id":726,"depth":282,"text":727},{"id":589,"depth":282,"text":590,"children":772},[773,774,775],{"id":739,"depth":288,"text":740},{"id":746,"depth":288,"text":747},{"id":753,"depth":288,"text":754},"Record a confidential HR incident on a team member's profile — category, severity, what happened, and the action taken.","i-lucide-flag",[779,780,781,782,783],"employee incident log","hr record staff","document staff conduct","staff disciplinary record","incident report team member",{},70,[313,760,315],{"title":27,"description":776},"help\u002Fteam\u002Flog-an-employee-incident","vvEBRGunRWymWWp6wcek1jIn3OWb5uXgqAWLeaYpwZ8",{"id":791,"title":83,"audience":6,"body":792,"category":406,"description":1235,"draft":301,"extension":302,"icon":1236,"keywords":1237,"meta":1238,"navigation":311,"order":425,"path":82,"related":1239,"seo":1242,"stem":1243,"updatedAt":1244,"__hash__":1245},"help\u002Fhelp\u002Fsettings\u002Froles-and-permissions.md",{"type":8,"value":793,"toc":1216},[794,797,802,806,809,863,869,873,876,880,898,933,936,987,991,998,1062,1065,1070,1074,1077,1108,1115,1119,1162,1166,1173,1178,1182,1185,1189,1203,1206,1210],[11,795,796],{},"Access in Owneli is capability-based, not tier-based. There is no hidden ladder where \"manager\" magically unlocks things — every screen and every API call checks a specific capability, and roles are just named bundles of capabilities.",[11,798,799],{},[14,800,801],{},"Settings → Team & access → Permission roles",[30,803,805],{"id":804},"the-four-starting-roles","The four starting roles",[11,807,808],{},"Every business is created with four system roles you can adapt.",[42,810,811,821],{},[45,812,813],{},[48,814,815,818],{},[51,816,817],{},"Role",[51,819,820],{},"What it is",[58,822,823,833,843,853],{},[48,824,825,830],{},[63,826,827],{},[14,828,829],{},"Owner",[63,831,832],{},"Full access to everything, plus owner-reserved actions: enforcing multi-factor authentication and transferring ownership.",[48,834,835,840],{},[63,836,837],{},[14,838,839],{},"Admin",[63,841,842],{},"Full access to the business. Can invite people, manage the team, and change settings.",[48,844,845,850],{},[63,846,847],{},[14,848,849],{},"Manager",[63,851,852],{},"Operational lead. Manages clients, forms and sends, approves time off. Cannot change settings or invite users.",[48,854,855,860],{},[63,856,857],{},[14,858,859],{},"Staff",[63,861,862],{},"Standard team member. The capability set is adjustable per business.",[864,865,866],"note",{},[11,867,868],{},"The owner is deliberately a superuser and is granted every capability, including ones added in future releases. That's so a new feature can never accidentally lock the owner out of their own business.",[30,870,872],{"id":871},"two-axes","Two axes",[11,874,875],{},"Access is controlled along two axes, and both matter.",[96,877,879],{"id":878},"_1-what-you-can-do","1. What you can do",[11,881,882,883,146,886,889,890,893,894,897],{},"Each of roughly three dozen capability areas carries its own actions — typically ",[14,884,885],{},"view",[14,887,888],{},"manage",", and ",[14,891,892],{},"delete",", plus ",[14,895,896],{},"create"," where creating differs meaningfully from editing.",[11,899,900,901,146,904,146,907,146,910,146,913,146,916,146,919,146,922,146,924,146,927,889,930,28],{},"The permission editor groups them the way you think about the app: ",[14,902,903],{},"Calendar",[14,905,906],{},"Scheduling & timesheets",[14,908,909],{},"Sales",[14,911,912],{},"Clients",[14,914,915],{},"Catalog",[14,917,918],{},"Marketing",[14,920,921],{},"Inventory & Retail",[14,923,669],{},[14,925,926],{},"Reports",[14,928,929],{},"Workspace",[14,931,932],{},"AI concierge",[11,934,935],{},"Things are split more finely than you might expect, on purpose:",[192,937,938,947,956,966,972],{},[195,939,940,943,944,946],{},[14,941,942],{},"Cash drawer"," is separate from ",[14,945,909],{}," — a cashier can ring up without holding the power to open, count and reconcile the till.",[195,948,949,943,952,955],{},[14,950,951],{},"Scheduling",[14,953,954],{},"Appointments"," — you can grant \"runs the rota and signs off payroll\" without handing over the client calendar.",[195,957,958,961,962,965],{},[14,959,960],{},"Client photos"," and ",[14,963,964],{},"clinical charts"," are separate from the client record — health imagery grants and revokes on its own.",[195,967,968,971],{},[14,969,970],{},"Compensation"," is its own area — someone can see their own earnings without seeing a colleague's.",[195,973,974,146,977,146,980,961,983,986],{},[14,975,976],{},"Purchasing",[14,978,979],{},"stock",[14,981,982],{},"transfers",[14,984,985],{},"products"," each grant independently, so a buyer can raise purchase orders without touching stock counts.",[96,988,990],{"id":989},"_2-which-rows-you-can-do-it-to","2. Which rows you can do it to",[11,992,993,994,997],{},"The ",[14,995,996],{},"data scope"," decides which records an action reaches:",[42,999,1000,1010],{},[45,1001,1002],{},[48,1003,1004,1007],{},[51,1005,1006],{},"Scope",[51,1008,1009],{},"Meaning",[58,1011,1012,1022,1032,1042,1052],{},[48,1013,1014,1019],{},[63,1015,1016],{},[14,1017,1018],{},"All",[63,1020,1021],{},"Everything in the business",[48,1023,1024,1029],{},[63,1025,1026],{},[14,1027,1028],{},"Own",[63,1030,1031],{},"Only records belonging to this person",[48,1033,1034,1039],{},[63,1035,1036],{},[14,1037,1038],{},"Assigned",[63,1040,1041],{},"Only records they're assigned to",[48,1043,1044,1049],{},[63,1045,1046],{},[14,1047,1048],{},"Location",[63,1050,1051],{},"Only records at their location",[48,1053,1054,1059],{},[63,1055,1056],{},[14,1057,1058],{},"None",[63,1060,1061],{},"Nothing",[11,1063,1064],{},"Staff-tier defaults reflect how a provider actually works: their own calendar, their assigned clients, their own timesheets, their own sales, their own reports and earnings.",[719,1066,1067],{},[11,1068,1069],{},"Granting an action without widening its scope is the most common configuration mistake. Someone with \"view all appointments\" but a scope of \"own\" will still only see their own calendar, and it will look like a bug.",[30,1071,1073],{"id":1072},"fine-grained-client-access","Fine-grained client access",[11,1075,1076],{},"The client record is the most sensitive surface in the app, so it's split further:",[192,1078,1079,1085,1091,1097,1103],{},[195,1080,1081,1084],{},[14,1082,1083],{},"Can view client profile"," — the base",[195,1086,1087,1090],{},[14,1088,1089],{},"Can view contact details"," — email and phone",[195,1092,1093,1096],{},[14,1094,1095],{},"Can view personal info"," — date of birth and home address",[195,1098,1099,1102],{},[14,1100,1101],{},"Can view spending and wallet"," — lifetime value, balances, loyalty",[195,1104,1105],{},[14,1106,1107],{},"Can add and remove tags",[11,1109,1110,1111,1114],{},"Denied fields are masked in the interface ",[14,1112,1113],{},"and"," stripped from API responses — this is enforced at the server, not hidden with CSS.",[30,1116,1118],{"id":1117},"building-a-custom-role","Building a custom role",[93,1120,1121,1125,1128,1132,1135,1139,1142,1146,1153,1157],{},[96,1122,1124],{"id":1123},"start-from-the-closest-system-role","Start from the closest system role",[11,1126,1127],{},"Duplicate it rather than building from an empty matrix. Empty matrices produce roles that can't do their job.",[96,1129,1131],{"id":1130},"turn-on-the-areas-the-role-needs","Turn on the areas the role needs",[11,1133,1134],{},"Each area has a master toggle. The editor enforces parent-first ordering — a child permission can't take effect while its parent is off.",[96,1136,1138],{"id":1137},"set-the-scope-for-each-area","Set the scope for each area",[11,1140,1141],{},"Only surfaces with end-to-end enforcement offer a scope picker, so every option you're shown actually does something.",[96,1143,1145],{"id":1144},"preview-it","Preview it",[11,1147,1148,1149,1152],{},"Use ",[14,1150,1151],{},"View as"," to see the app exactly as that role sees it. This is the step people skip and then regret.",[96,1154,1156],{"id":1155},"assign-it","Assign it",[11,1158,1159,1160,28],{},"Set the role on each team member under ",[14,1161,669],{},[30,1163,1165],{"id":1164},"what-the-sidebar-tells-you","What the sidebar tells you",[11,1167,1168,1169,1172],{},"Every nav item is capability-gated, so people only see what they can open. An ",[14,1170,1171],{},"eye icon"," beside a link means view-only access — you can read the page but not change anything. It saves a click into a page where every button is disabled.",[719,1174,1175],{},[11,1176,1177],{},"Hiding a link is presentation. The real gate is on the server: every endpoint re-checks the capability and the scope. Restoring a hidden link in the browser gets you an error, not access.",[30,1179,1181],{"id":1180},"multi-factor-authentication","Multi-factor authentication",[11,1183,1184],{},"Owners can require multi-factor authentication for the business. Once enforced, everyone is prompted to enrol at sign-in.",[30,1186,1188],{"id":1187},"suspending-and-offboarding","Suspending and offboarding",[192,1190,1191,1197],{},[195,1192,1193,1196],{},[14,1194,1195],{},"Suspend"," locks someone out immediately while keeping their record and history intact",[195,1198,1199,1202],{},[14,1200,1201],{},"Archive"," runs a reassignment wizard so their upcoming appointments and open work move to someone else before the record is closed",[11,1204,1205],{},"Neither deletes their history. Past sales, appointments and timesheets stay attached to them for reporting and payroll.",[30,1207,1209],{"id":1208},"auditing","Auditing",[11,1211,1212,1215],{},[14,1213,1214],{},"Settings → Compliance → Audit log"," records who did what and when — role changes, permission changes, refunds, voids, merges, deletions. Audit access is its own capability, so a compliance reviewer can read it without being an admin.",{"title":281,"searchDepth":282,"depth":282,"links":1217},[1218,1219,1223,1224,1231,1232,1233,1234],{"id":804,"depth":282,"text":805},{"id":871,"depth":282,"text":872,"children":1220},[1221,1222],{"id":878,"depth":288,"text":879},{"id":989,"depth":288,"text":990},{"id":1072,"depth":282,"text":1073},{"id":1117,"depth":282,"text":1118,"children":1225},[1226,1227,1228,1229,1230],{"id":1123,"depth":288,"text":1124},{"id":1130,"depth":288,"text":1131},{"id":1137,"depth":288,"text":1138},{"id":1144,"depth":288,"text":1145},{"id":1155,"depth":288,"text":1156},{"id":1164,"depth":282,"text":1165},{"id":1180,"depth":282,"text":1181},{"id":1187,"depth":282,"text":1188},{"id":1208,"depth":282,"text":1209},"The four starting roles, the two axes that control access, and how to build a custom role without locking yourself out.","i-lucide-shield-check",[],{},[1240,1241],"\u002Fhelp\u002Fteam\u002Fshifts-timesheets-and-time-off","\u002Fhelp\u002Fgrowth\u002Ffind-and-read-a-report",{"title":83,"description":1235},"help\u002Fsettings\u002Froles-and-permissions","2026-09-01","TENSZfd1Unekw8skVK5ZgEABdPfFFfQpo8przNdYK7o",{"id":1247,"title":1248,"audience":6,"body":1249,"category":299,"description":1536,"draft":301,"extension":302,"icon":1236,"keywords":1537,"meta":1538,"navigation":311,"order":1539,"path":315,"related":1540,"seo":1541,"stem":1542,"updatedAt":1543,"__hash__":1544},"help\u002Fhelp\u002Foperations\u002Fpolicies.md","Policies — reading, signing, and authoring",{"type":8,"value":1250,"toc":1526},[1251,1256,1259,1265,1269,1272,1275,1280,1286,1291,1295,1302,1371,1380,1384,1406,1410,1413,1417,1426,1433,1436,1440,1446,1449,1456,1460,1520],[11,1252,1253],{},[14,1254,1255],{},"Operations → Policies",[11,1257,1258],{},"Policies are the HR and compliance layer — code of conduct, health and safety, privacy, harassment, attendance, social media, confidentiality, the employee handbook.",[11,1260,1261,1262,1264],{},"They sit in ",[14,1263,372],{},", not in Settings, because every employee has to read and sign them. Only authoring is restricted.",[30,1266,1268],{"id":1267},"if-youre-an-employee","If you're an employee",[11,1270,1271],{},"You need to do two things: read the policy, and acknowledge it.",[11,1273,1274],{},"When a policy that requires acknowledgment is published — or its version is bumped — you're prompted to sign at your next sign-in. Read it, then acknowledge.",[864,1276,1277],{},[11,1278,1279],{},"Your signature and its timestamp are permanently logged against the exact version you signed. That record is the point of the feature: it's what proves the business told you, and what proves you read it.",[11,1281,1282,1283,1285],{},"You can revisit any policy at any time from ",[14,1284,1255],{},". If you can read but not author, the sidebar shows a small eye icon next to the link — that's expected, not a fault.",[719,1287,1288],{},[11,1289,1290],{},"Acknowledgment prompts are skipped on read-only reporting pages, so a manager reviewing numbers isn't blocked by an HR overlay on every report. The prompt still reaches you everywhere else, and the notification bell keeps the item visible.",[30,1292,1294],{"id":1293},"if-you-author-policies","If you author policies",[11,1296,1297,1298,1301],{},"Authoring needs the policy-management permission. ",[14,1299,1300],{},"New policy"," offers five ways in:",[42,1303,1304,1314],{},[45,1305,1306],{},[48,1307,1308,1311],{},[51,1309,1310],{},"Route",[51,1312,1313],{},"Use it when",[58,1315,1316,1326,1336,1351,1361],{},[48,1317,1318,1323],{},[63,1319,1320],{},[14,1321,1322],{},"Start from a template",[63,1324,1325],{},"You want a solid starting draft. Templates prefill your business name, HR contact and jurisdiction.",[48,1327,1328,1333],{},[63,1329,1330],{},[14,1331,1332],{},"AI Policy Studio",[63,1334,1335],{},"You want a draft generated from a description. Only available when the AI assistant is enabled for your business.",[48,1337,1338,1343],{},[63,1339,1340],{},[14,1341,1342],{},"Upload a document",[63,1344,1345,1346,1350],{},"You already have the policy as a PDF, ",[1347,1348,1349],"code",{},".docx",", or HTML file.",[48,1352,1353,1358],{},[63,1354,1355],{},[14,1356,1357],{},"Paste HTML",[63,1359,1360],{},"You're bringing it from another system. The pasted markup is sanitised before it's stored.",[48,1362,1363,1368],{},[63,1364,1365],{},[14,1366,1367],{},"Blank",[63,1369,1370],{},"You'd rather write it yourself.",[11,1372,1373,1374,961,1376,1379],{},"Uploads accept PDF, ",[1347,1375,1349],{},[1347,1377,1378],{},".html"," only, and are size-limited — the editor tells you the maximum.",[96,1381,1383],{"id":1382},"fields","Fields",[192,1385,1386,1394,1400],{},[195,1387,1388,1391,1392],{},[14,1389,1390],{},"Title"," and optional ",[14,1393,683],{},[195,1395,1396,1399],{},[14,1397,1398],{},"Summary"," — a one-liner shown in lists and on the acknowledgment overlay. Worth writing well; for many staff it's the only part they read carefully.",[195,1401,1402,1405],{},[14,1403,1404],{},"Require acknowledgment"," — when on, every employee must sign it at next login",[96,1407,1409],{"id":1408},"draft-then-publish","Draft, then publish",[11,1411,1412],{},"A new policy is created as a draft. Review it — particularly the extracted text from an upload or the sanitised output of a paste — and publish when you're satisfied.",[96,1414,1416],{"id":1415},"versions-and-re-acknowledgment","Versions and re-acknowledgment",[719,1418,1419],{},[11,1420,1421,1422,1425],{},"Bumping a policy's version ",[14,1423,1424],{},"resets everyone's acknowledgment"," and asks the whole team to sign again. That's correct for a substantive change and wasteful for a typo. Save the version bump for changes that alter what someone is agreeing to.",[11,1427,1428,1429],{},"When you edit and re-publish with a version bump, the app confirms it: ",[1430,1431,1432],"em",{},"\"Version bumped. Team must re-acknowledge.\"",[11,1434,1435],{},"You can also replace the attached file on an uploaded policy — the signature record then attaches to the file you uploaded.",[30,1437,1439],{"id":1438},"compliance-tracking","Compliance tracking",[11,1441,1442,1445],{},[14,1443,1444],{},"Compliance"," (admin only) shows, per employee: how many policies they've acknowledged, out of how many, as a percentage — plus exactly which ones are missing.",[11,1447,1448],{},"A policy someone signed at an older version is flagged separately from one they've never signed, so you can tell \"hasn't read it at all\" from \"read the previous edition\".",[11,1450,1451,1452,1455],{},"Filter to ",[14,1453,1454],{},"only missing"," to get your chase list.",[30,1457,1459],{"id":1458},"policies-versus-notes","Policies versus notes",[42,1461,1462,1474],{},[45,1463,1464],{},[48,1465,1466,1468,1471],{},[51,1467],{},[51,1469,1470],{},"Policies",[51,1472,1473],{},"Notes",[58,1475,1476,1487,1498,1509],{},[48,1477,1478,1481,1484],{},[63,1479,1480],{},"Subject",[63,1482,1483],{},"Conduct, safety obligations, privacy, employment",[63,1485,1486],{},"How to do the work",[48,1488,1489,1492,1495],{},[63,1490,1491],{},"Who can author",[63,1493,1494],{},"Policy-management permission only",[63,1496,1497],{},"Anyone who can create notes",[48,1499,1500,1503,1506],{},[63,1501,1502],{},"Who can read",[63,1504,1505],{},"Everyone with policy view",[63,1507,1508],{},"Depends on the note's visibility",[48,1510,1511,1514,1517],{},[63,1512,1513],{},"Signature",[63,1515,1516],{},"Permanently logged against the version",[63,1518,1519],{},"Acknowledgment logged, optional per note",[11,1521,1522,1523,28],{},"If it would go in an employee handbook, it's a policy. If it would go on a laminated card by the machine, it's a ",[24,1524,864],{"href":1525},"\u002Fhelp\u002Foperations\u002Fnotes-your-team-playbook",{"title":281,"searchDepth":282,"depth":282,"links":1527},[1528,1529,1534,1535],{"id":1267,"depth":282,"text":1268},{"id":1293,"depth":282,"text":1294,"children":1530},[1531,1532,1533],{"id":1382,"depth":288,"text":1383},{"id":1408,"depth":288,"text":1409},{"id":1415,"depth":288,"text":1416},{"id":1438,"depth":282,"text":1439},{"id":1458,"depth":282,"text":1459},"What every employee has to do with a policy, how authors create one from a template, upload or paste, and how compliance is tracked.",[],{},30,[1525,82],{"title":1248,"description":1536},"help\u002Foperations\u002Fpolicies","2026-07-26","Olc7gRagEd7UYBUv2Ug9gJ9Km9IBKV4mIQ6NWjhd-7w",1790210903956]