[{"data":1,"prerenderedAt":1018},["ShallowReactive",2],{"help:\u002Fhelp\u002Fsettings\u002Fdata-privacy-and-retention":3,"help-all-categories":225,"help-cat-articles:\u002Fhelp\u002Fsettings\u002Fdata-privacy-and-retention":345,"help-related:\u002Fhelp\u002Fsettings\u002Fdata-privacy-and-retention":346},{"id":4,"title":5,"audience":6,"body":7,"category":203,"description":204,"draft":205,"extension":206,"icon":207,"keywords":208,"meta":215,"navigation":216,"order":217,"path":218,"related":219,"seo":221,"stem":222,"updatedAt":223,"__hash__":224},"help\u002Fhelp\u002Fsettings\u002Fdata-privacy-and-retention.md","Data privacy and retention","clinic",{"type":8,"value":9,"toc":184},"minimark",[10,19,24,64,70,74,120,124,131,135,142,149,159,163,167,170,174,177,181],[11,12,13,14,18],"p",{},"Owneli can automatically purge data older than a retention period you choose, with a dry-run preview before anything is deleted and legal holds to exempt records you must keep. It's configured at ",[15,16,17],"strong",{},"Settings → Compliance & data → Data & privacy"," (admins only).",[20,21,23],"h2",{"id":22},"how-do-i-set-a-data-retention-period","How do I set a data retention period?",[25,26,27,32,39,43,46,50,57,61],"steps",{},[28,29,31],"h3",{"id":30},"turn-on-automatic-retention","Turn on automatic retention",[11,33,34,35,38],{},"Flip ",[15,36,37],{},"Enable automatic data purge"," on.",[28,40,42],{"id":41},"choose-the-period","Choose the period",[11,44,45],{},"Set the retention window in days — anywhere from 30 to 3650 (ten years). Data older than this becomes eligible for deletion.",[28,47,49],{"id":48},"preview-before-you-commit","Preview before you commit",[11,51,52,53,56],{},"Click the preview button. Owneli runs a ",[15,54,55],{},"dry run"," and shows exactly how many records would be eligible under the period you typed — before anything is actually purged.",[28,58,60],{"id":59},"save","Save",[11,62,63],{},"The retention policy saves with the rest of your workspace defaults.",[65,66,67],"caution",{},[11,68,69],{},"A purge is permanent. Always run the preview and read the numbers before saving a shorter period — \"365\" where you meant \"3650\" is a very different policy.",[20,71,73],{"id":72},"what-never-gets-purged","What never gets purged",[75,76,77,90],"table",{},[78,79,80],"thead",{},[81,82,83,87],"tr",{},[84,85,86],"th",{},"Data",[84,88,89],{},"Why",[91,92,93,110],"tbody",{},[81,94,95,101],{},[96,97,98],"td",{},[15,99,100],{},"The audit log",[96,102,103,104,109],{},"Append-only and immutable — it's your evidence trail. See ",[105,106,108],"a",{"href":107},"\u002Fhelp\u002Fsettings\u002Faudit-log","Read the audit log",".",[81,111,112,117],{},[96,113,114],{},[15,115,116],{},"Records under a legal hold",[96,118,119],{},"Explicitly exempted until the hold is released.",[20,121,123],{"id":122},"legal-holds","Legal holds",[11,125,126,127,130],{},"A legal hold pins specific records so the retention purge skips them — for a dispute, an investigation, or a regulatory request. Active holds are listed on this tab, and an admin can ",[15,128,129],{},"release"," a hold when the obligation ends, returning those records to the normal retention rules.",[20,132,134],{"id":133},"clinical-charting-health-information","Clinical charting (health information)",[11,136,137,138,141],{},"The same tab carries the ",[15,139,140],{},"clinical charting"," switch. It's off by default because it changes what kind of data your workspace stores: turning it on enables treatment charts on appointments, which is protected health information.",[11,143,144,145,148],{},"Clinical charts get their ",[15,146,147],{},"own retention period"," — separate from, and typically much longer than, general data retention, because health-record laws commonly require charts be kept for many years.",[150,151,152],"warning",{},[11,153,154,155,158],{},"Deleting a client on request (a GDPR-style erasure) is a separate flow from retention. Clinical treatment records are ",[15,156,157],{},"archived and access-restricted"," rather than destroyed, because retention law overrides the erasure request for health records.",[20,160,162],{"id":161},"common-questions","Common questions",[28,164,166],{"id":165},"does-retention-delete-my-audit-history","Does retention delete my audit history?",[11,168,169],{},"No — the audit log is excluded entirely.",[28,171,173],{"id":172},"can-i-see-what-a-different-period-would-delete-without-changing-anything","Can I see what a different period would delete without changing anything?",[11,175,176],{},"Yes. Type the candidate number of days and run the preview; it's a dry run and deletes nothing.",[28,178,180],{"id":179},"who-can-change-these-settings","Who can change these settings?",[11,182,183],{},"Admins. Access to read the audit log is a separate capability, so review and configuration can be held by different people.",{"title":185,"searchDepth":186,"depth":186,"links":187},"",2,[188,195,196,197,198],{"id":22,"depth":186,"text":23,"children":189},[190,192,193,194],{"id":30,"depth":191,"text":31},3,{"id":41,"depth":191,"text":42},{"id":48,"depth":191,"text":49},{"id":59,"depth":191,"text":60},{"id":72,"depth":186,"text":73},{"id":122,"depth":186,"text":123},{"id":133,"depth":186,"text":134},{"id":161,"depth":186,"text":162,"children":199},[200,201,202],{"id":165,"depth":191,"text":166},{"id":172,"depth":191,"text":173},{"id":179,"depth":191,"text":180},"settings","Set automatic data retention in Owneli, preview what a purge would delete, use legal holds, and control clinical charting for health records.",false,"md","i-lucide-database",[209,210,211,212,213,214],"data retention policy","auto delete old data","gdpr retention","legal hold","clinical charting phi","purge client data",{},true,190,"\u002Fhelp\u002Fsettings\u002Fdata-privacy-and-retention",[107,220],"\u002Fhelp\u002Fsettings\u002Froles-and-permissions",{"title":5,"description":204},"help\u002Fsettings\u002Fdata-privacy-and-retention","2026-08-14","YoQ7U7z-ziAfnoHEkvwqG8nU4bP9k3TvlxPpbfmJWLw",[226,237,246,255,265,275,285,295,305,314,324,335],{"id":227,"title":228,"audience":6,"description":229,"extension":230,"icon":231,"meta":232,"order":233,"slug":234,"stem":235,"__hash__":236},"helpCategories\u002Fhelp\u002Fcategories\u002Fgetting-started.yml","Getting started","Set up your workspace, learn the layout, and run your first day.","yml","i-lucide-compass",{},1,"getting-started","help\u002Fcategories\u002Fgetting-started","lTnfg_2tKvxQ9QanJ9XY3shoBHrJNWNfnxhcYaaKKPI",{"id":238,"title":239,"audience":6,"description":240,"extension":230,"icon":241,"meta":242,"order":186,"slug":243,"stem":244,"__hash__":245},"helpCategories\u002Fhelp\u002Fcategories\u002Fcalendar.yml","Calendar & booking","Book, move, and cancel appointments. Block time, work the waitlist, and read the grid at a glance.","i-lucide-calendar",{},"calendar","help\u002Fcategories\u002Fcalendar","s5UMHzRIeTUFi7mdsOyuSluzJBp79U9WTsTpOtbaW-E",{"id":247,"title":248,"audience":6,"description":249,"extension":230,"icon":250,"meta":251,"order":191,"slug":252,"stem":253,"__hash__":254},"helpCategories\u002Fhelp\u002Fcategories\u002Fcheckout.yml","Checkout & payments","Ring up a sale, take tips, handle deposits and fees, issue refunds, and close the drawer.","i-lucide-credit-card",{},"checkout","help\u002Fcategories\u002Fcheckout","4PQPgJd7Z25g0SvtoqqdMlnzk3DlcJpaZhNAiNiYVW0",{"id":256,"title":257,"audience":6,"description":258,"extension":230,"icon":259,"meta":260,"order":261,"slug":262,"stem":263,"__hash__":264},"helpCategories\u002Fhelp\u002Fcategories\u002Fclients.yml","Clients & forms","Add and find clients, read a client profile, and send forms and consents.","i-lucide-users",{},4,"clients","help\u002Fcategories\u002Fclients","u-tqzEJo2gR_wJ7x7y-EMIF3L4TP9EuBWlamwgwCC0I",{"id":266,"title":267,"audience":6,"description":268,"extension":230,"icon":269,"meta":270,"order":271,"slug":272,"stem":273,"__hash__":274},"helpCategories\u002Fhelp\u002Fcategories\u002Fretail.yml","Memberships, packages & gift cards","The things clients buy once and spend down over time, and how each one behaves at checkout.","i-lucide-gift",{},5,"retail","help\u002Fcategories\u002Fretail","wVVr_rc_P9p2RZWwy0XKsNB9fQ7XtQxxIz4qnixkGkg",{"id":276,"title":277,"audience":6,"description":278,"extension":230,"icon":279,"meta":280,"order":281,"slug":282,"stem":283,"__hash__":284},"helpCategories\u002Fhelp\u002Fcategories\u002Foperations.yml","Operations","The internal side of the business, covering your written playbook, task boards, venue incidents, and the policies everyone signs.","i-lucide-briefcase",{},6,"operations","help\u002Fcategories\u002Foperations","kSPRTYYbOW5LBNuaYXGv0C4IE7BqS2n-OkCSI97f-cM",{"id":286,"title":287,"audience":6,"description":288,"extension":230,"icon":289,"meta":290,"order":291,"slug":292,"stem":293,"__hash__":294},"helpCategories\u002Fhelp\u002Fcategories\u002Fteam.yml","Team & scheduling","Working hours, the weekly roster, clock-in, timesheets, and time off.","i-lucide-id-card",{},7,"team","help\u002Fcategories\u002Fteam","1cMbCRwUmewb4t_DwUJ7jJUjntx-odU8jRDgBredsPs",{"id":296,"title":297,"audience":6,"description":298,"extension":230,"icon":299,"meta":300,"order":301,"slug":302,"stem":303,"__hash__":304},"helpCategories\u002Fhelp\u002Fcategories\u002Fgrowth.yml","Reports & growth","Read the numbers, export them, and find the report you actually need.","i-lucide-trending-up",{},8,"growth","help\u002Fcategories\u002Fgrowth","3XyCU-DkoYi7xSPz0tDRohlYkNBUS0YsLo-insknI8o",{"id":306,"title":307,"audience":6,"description":308,"extension":230,"icon":309,"meta":310,"order":311,"slug":203,"stem":312,"__hash__":313},"helpCategories\u002Fhelp\u002Fcategories\u002Fsettings.yml","Settings & admin","Services and pricing, who can see what, and moving your data in from another system.","i-lucide-settings",{},9,"help\u002Fcategories\u002Fsettings","rdLQHp7tfAu5iySbsypfXu1kOuujDAuLVk6yGidNvtQ",{"id":315,"title":316,"audience":6,"description":317,"extension":230,"icon":318,"meta":319,"order":320,"slug":321,"stem":322,"__hash__":323},"helpCategories\u002Fhelp\u002Fcategories\u002Faccount.yml","Your login and profile","Your own login, password, two-factor security, profile, and language.","i-lucide-user-circle",{},10,"account","help\u002Fcategories\u002Faccount","8JZPH_8Q-lnEEFgysE9gCwyd1pzUe2hfAebATuQ5Pog",{"id":325,"title":326,"audience":327,"description":328,"extension":230,"icon":329,"meta":330,"order":331,"slug":332,"stem":333,"__hash__":334},"helpCategories\u002Fhelp\u002Fcategories\u002Fbook-online.yml","Book online","client","Booking, paying, and managing your visit from your venue's booking page and the private links they send you.","i-lucide-globe",{},20,"book-online","help\u002Fcategories\u002Fbook-online","dUBIoELt-ci1vqbw_VX1VA6PGJV8V-9x4ZmpAk1aXXE",{"id":336,"title":337,"audience":327,"description":338,"extension":230,"icon":339,"meta":340,"order":341,"slug":342,"stem":343,"__hash__":344},"helpCategories\u002Fhelp\u002Fcategories\u002Fportal.yml","Your account and visits","Booking from your account, managing your visits, and using your wallet, memberships and rewards.","i-lucide-user-round",{},21,"portal","help\u002Fcategories\u002Fportal","D8_zQhv9hO2b9PYDADw-ebh1yZUuC0UcBt3DDZbMAH4",[],[347,557],{"id":348,"title":108,"audience":6,"body":349,"category":203,"description":542,"draft":205,"extension":206,"icon":543,"keywords":544,"meta":551,"navigation":216,"order":552,"path":107,"related":553,"seo":554,"stem":555,"updatedAt":223,"__hash__":556},"help\u002Fhelp\u002Fsettings\u002Faudit-log.md",{"type":8,"value":350,"toc":528},[351,357,361,373,377,380,458,486,492,496,505,507,511,514,518,521,525],[11,352,353,354,109],{},"The audit log is the permanent record of who did what in your business — role changes, refunds, deletions, permission edits, and every other sensitive action, each stamped with the person and the time. Open it from ",[15,355,356],{},"Settings → Compliance & data → Audit log",[20,358,360],{"id":359},"who-can-see-the-audit-log","Who can see the audit log?",[11,362,363,364,367,368,372],{},"Access is its own capability — ",[15,365,366],{},"audit — view"," — not a role tier. That means a compliance reviewer can be granted read access to the log without being made an admin. The full-page log at ",[369,370,371],"code",{},"\u002Fsettings\u002Faudit"," is additionally admin-gated.",[20,374,376],{"id":375},"how-do-i-find-a-specific-change","How do I find a specific change?",[11,378,379],{},"The log is filterable from every angle:",[75,381,382,392],{},[78,383,384],{},[81,385,386,389],{},[84,387,388],{},"Filter",[84,390,391],{},"Use it to answer",[91,393,394,404,414,424,434,448],{},[81,395,396,401],{},[96,397,398],{},[15,399,400],{},"Entity type",[96,402,403],{},"\"Show me everything that happened to gift cards\"",[81,405,406,411],{},[96,407,408],{},[15,409,410],{},"Action",[96,412,413],{},"\"Show me every deletion\"",[81,415,416,421],{},[96,417,418],{},[15,419,420],{},"Team member",[96,422,423],{},"\"What did this person change?\"",[81,425,426,431],{},[96,427,428],{},[15,429,430],{},"Client",[96,432,433],{},"\"Everything that touched this client's record\"",[81,435,436,441],{},[96,437,438],{},[15,439,440],{},"Severity",[96,442,443,444,447],{},"Info, notice, or ",[15,445,446],{},"critical"," — the shortlist worth reviewing",[81,449,450,455],{},[96,451,452],{},[15,453,454],{},"Date range",[96,456,457],{},"Bound the search to the period in question",[25,459,460,464,468,472,475,479],{},[28,461,463],{"id":462},"open-the-log","Open the log",[11,465,466,109],{},[15,467,356],{},[28,469,471],{"id":470},"narrow-it-down","Narrow it down",[11,473,474],{},"Combine filters — a team member plus a date range plus an action gets you from \"50 pages\" to \"the six entries that matter\".",[28,476,478],{"id":477},"open-an-entry","Open an entry",[11,480,481,482,485],{},"Each entry shows who, what, and when. Where a record was changed, the ",[15,483,484],{},"diff viewer"," shows the before and after values side by side, so \"someone edited the price\" becomes \"changed from $120 to $90\".",[487,488,489],"tip",{},[11,490,491],{},"Other pages deep-link here pre-filtered — a client profile or a form submission can jump you straight to its own audit trail, already scoped to that record.",[20,493,495],{"id":494},"can-audit-entries-be-edited-or-deleted","Can audit entries be edited or deleted?",[11,497,498,499,502,503,109],{},"No. The log is append-only by design and is ",[15,500,501],{},"not"," touched by your data-retention purge — entries can't be edited or removed, by anyone, including the owner. That immutability is what makes it evidence rather than notes. See ",[105,504,5],{"href":218},[20,506,162],{"id":161},[28,508,510],{"id":509},"does-the-log-capture-reads-or-only-changes","Does the log capture reads or only changes?",[11,512,513],{},"It records actions and changes — the things that alter state or move money. It isn't a keystroke recorder.",[28,515,517],{"id":516},"how-far-back-does-it-go","How far back does it go?",[11,519,520],{},"To the beginning of your workspace. Retention purges skip the audit log entirely.",[28,522,524],{"id":523},"can-i-export-it","Can I export it?",[11,526,527],{},"Use the date and entity filters to scope what you need on screen. ",{"title":185,"searchDepth":186,"depth":186,"links":529},[530,531,536,537],{"id":359,"depth":186,"text":360},{"id":375,"depth":186,"text":376,"children":532},[533,534,535],{"id":462,"depth":191,"text":463},{"id":470,"depth":191,"text":471},{"id":477,"depth":191,"text":478},{"id":494,"depth":186,"text":495},{"id":161,"depth":186,"text":162,"children":538},[539,540,541],{"id":509,"depth":191,"text":510},{"id":516,"depth":191,"text":517},{"id":523,"depth":191,"text":524},"See who did what and when in Owneli — filter the audit log by person, client, action, or date, and read the before\u002Fafter of any change.","i-lucide-shield-alert",[545,546,547,548,549,550],"audit log","who changed this","activity history","track staff changes","who deleted a client","audit trail",{},180,[220,218],{"title":108,"description":542},"help\u002Fsettings\u002Faudit-log","etNUA2Dtb8G1PWHXC01q76Smz9Njmy9DJgC9aKIFCQk",{"id":558,"title":559,"audience":6,"body":560,"category":203,"description":1007,"draft":205,"extension":206,"icon":1008,"keywords":1009,"meta":1010,"navigation":216,"order":331,"path":220,"related":1011,"seo":1014,"stem":1015,"updatedAt":1016,"__hash__":1017},"help\u002Fhelp\u002Fsettings\u002Froles-and-permissions.md","Roles and permissions",{"type":8,"value":561,"toc":988},[562,565,570,574,577,631,637,641,644,648,667,703,706,759,763,770,834,837,842,846,849,880,887,891,934,938,945,950,954,957,961,975,978,982],[11,563,564],{},"Access in Owneli is capability-based, not tier-based. There is no hidden ladder where \"manager\" magically unlocks things — every screen and every API call checks a specific capability, and roles are just named bundles of capabilities.",[11,566,567],{},[15,568,569],{},"Settings → Team & access → Permission roles",[20,571,573],{"id":572},"the-four-starting-roles","The four starting roles",[11,575,576],{},"Every business is created with four system roles you can adapt.",[75,578,579,589],{},[78,580,581],{},[81,582,583,586],{},[84,584,585],{},"Role",[84,587,588],{},"What it is",[91,590,591,601,611,621],{},[81,592,593,598],{},[96,594,595],{},[15,596,597],{},"Owner",[96,599,600],{},"Full access to everything, plus owner-reserved actions: enforcing multi-factor authentication and transferring ownership.",[81,602,603,608],{},[96,604,605],{},[15,606,607],{},"Admin",[96,609,610],{},"Full access to the business. Can invite people, manage the team, and change settings.",[81,612,613,618],{},[96,614,615],{},[15,616,617],{},"Manager",[96,619,620],{},"Operational lead. Manages clients, forms and sends, approves time off. Cannot change settings or invite users.",[81,622,623,628],{},[96,624,625],{},[15,626,627],{},"Staff",[96,629,630],{},"Standard team member. The capability set is adjustable per business.",[632,633,634],"note",{},[11,635,636],{},"The owner is deliberately a superuser and is granted every capability, including ones added in future releases. That's so a new feature can never accidentally lock the owner out of their own business.",[20,638,640],{"id":639},"two-axes","Two axes",[11,642,643],{},"Access is controlled along two axes, and both matter.",[28,645,647],{"id":646},"_1-what-you-can-do","1. What you can do",[11,649,650,651,654,655,658,659,662,663,666],{},"Each of roughly three dozen capability areas carries its own actions — typically ",[15,652,653],{},"view",", ",[15,656,657],{},"manage",", and ",[15,660,661],{},"delete",", plus ",[15,664,665],{},"create"," where creating differs meaningfully from editing.",[11,668,669,670,654,673,654,676,654,679,654,682,654,685,654,688,654,691,654,694,654,697,658,700,109],{},"The permission editor groups them the way you think about the app: ",[15,671,672],{},"Calendar",[15,674,675],{},"Scheduling & timesheets",[15,677,678],{},"Sales",[15,680,681],{},"Clients",[15,683,684],{},"Catalog",[15,686,687],{},"Marketing",[15,689,690],{},"Inventory & Retail",[15,692,693],{},"Team",[15,695,696],{},"Reports",[15,698,699],{},"Workspace",[15,701,702],{},"AI concierge",[11,704,705],{},"Things are split more finely than you might expect, on purpose:",[707,708,709,719,728,738,744],"ul",{},[710,711,712,715,716,718],"li",{},[15,713,714],{},"Cash drawer"," is separate from ",[15,717,678],{}," — a cashier can ring up without holding the power to open, count and reconcile the till.",[710,720,721,715,724,727],{},[15,722,723],{},"Scheduling",[15,725,726],{},"Appointments"," — you can grant \"runs the rota and signs off payroll\" without handing over the client calendar.",[710,729,730,733,734,737],{},[15,731,732],{},"Client photos"," and ",[15,735,736],{},"clinical charts"," are separate from the client record — health imagery grants and revokes on its own.",[710,739,740,743],{},[15,741,742],{},"Compensation"," is its own area — someone can see their own earnings without seeing a colleague's.",[710,745,746,654,749,654,752,733,755,758],{},[15,747,748],{},"Purchasing",[15,750,751],{},"stock",[15,753,754],{},"transfers",[15,756,757],{},"products"," each grant independently, so a buyer can raise purchase orders without touching stock counts.",[28,760,762],{"id":761},"_2-which-rows-you-can-do-it-to","2. Which rows you can do it to",[11,764,765,766,769],{},"The ",[15,767,768],{},"data scope"," decides which records an action reaches:",[75,771,772,782],{},[78,773,774],{},[81,775,776,779],{},[84,777,778],{},"Scope",[84,780,781],{},"Meaning",[91,783,784,794,804,814,824],{},[81,785,786,791],{},[96,787,788],{},[15,789,790],{},"All",[96,792,793],{},"Everything in the business",[81,795,796,801],{},[96,797,798],{},[15,799,800],{},"Own",[96,802,803],{},"Only records belonging to this person",[81,805,806,811],{},[96,807,808],{},[15,809,810],{},"Assigned",[96,812,813],{},"Only records they're assigned to",[81,815,816,821],{},[96,817,818],{},[15,819,820],{},"Location",[96,822,823],{},"Only records at their location",[81,825,826,831],{},[96,827,828],{},[15,829,830],{},"None",[96,832,833],{},"Nothing",[11,835,836],{},"Staff-tier defaults reflect how a provider actually works: their own calendar, their assigned clients, their own timesheets, their own sales, their own reports and earnings.",[150,838,839],{},[11,840,841],{},"Granting an action without widening its scope is the most common configuration mistake. Someone with \"view all appointments\" but a scope of \"own\" will still only see their own calendar, and it will look like a bug.",[20,843,845],{"id":844},"fine-grained-client-access","Fine-grained client access",[11,847,848],{},"The client record is the most sensitive surface in the app, so it's split further:",[707,850,851,857,863,869,875],{},[710,852,853,856],{},[15,854,855],{},"Can view client profile"," — the base",[710,858,859,862],{},[15,860,861],{},"Can view contact details"," — email and phone",[710,864,865,868],{},[15,866,867],{},"Can view personal info"," — date of birth and home address",[710,870,871,874],{},[15,872,873],{},"Can view spending and wallet"," — lifetime value, balances, loyalty",[710,876,877],{},[15,878,879],{},"Can add and remove tags",[11,881,882,883,886],{},"Denied fields are masked in the interface ",[15,884,885],{},"and"," stripped from API responses — this is enforced at the server, not hidden with CSS.",[20,888,890],{"id":889},"building-a-custom-role","Building a custom role",[25,892,893,897,900,904,907,911,914,918,925,929],{},[28,894,896],{"id":895},"start-from-the-closest-system-role","Start from the closest system role",[11,898,899],{},"Duplicate it rather than building from an empty matrix. Empty matrices produce roles that can't do their job.",[28,901,903],{"id":902},"turn-on-the-areas-the-role-needs","Turn on the areas the role needs",[11,905,906],{},"Each area has a master toggle. The editor enforces parent-first ordering — a child permission can't take effect while its parent is off.",[28,908,910],{"id":909},"set-the-scope-for-each-area","Set the scope for each area",[11,912,913],{},"Only surfaces with end-to-end enforcement offer a scope picker, so every option you're shown actually does something.",[28,915,917],{"id":916},"preview-it","Preview it",[11,919,920,921,924],{},"Use ",[15,922,923],{},"View as"," to see the app exactly as that role sees it. This is the step people skip and then regret.",[28,926,928],{"id":927},"assign-it","Assign it",[11,930,931,932,109],{},"Set the role on each team member under ",[15,933,693],{},[20,935,937],{"id":936},"what-the-sidebar-tells-you","What the sidebar tells you",[11,939,940,941,944],{},"Every nav item is capability-gated, so people only see what they can open. An ",[15,942,943],{},"eye icon"," beside a link means view-only access — you can read the page but not change anything. It saves a click into a page where every button is disabled.",[150,946,947],{},[11,948,949],{},"Hiding a link is presentation. The real gate is on the server: every endpoint re-checks the capability and the scope. Restoring a hidden link in the browser gets you an error, not access.",[20,951,953],{"id":952},"multi-factor-authentication","Multi-factor authentication",[11,955,956],{},"Owners can require multi-factor authentication for the business. Once enforced, everyone is prompted to enrol at sign-in.",[20,958,960],{"id":959},"suspending-and-offboarding","Suspending and offboarding",[707,962,963,969],{},[710,964,965,968],{},[15,966,967],{},"Suspend"," locks someone out immediately while keeping their record and history intact",[710,970,971,974],{},[15,972,973],{},"Archive"," runs a reassignment wizard so their upcoming appointments and open work move to someone else before the record is closed",[11,976,977],{},"Neither deletes their history. Past sales, appointments and timesheets stay attached to them for reporting and payroll.",[20,979,981],{"id":980},"auditing","Auditing",[11,983,984,987],{},[15,985,986],{},"Settings → Compliance → Audit log"," records who did what and when — role changes, permission changes, refunds, voids, merges, deletions. Audit access is its own capability, so a compliance reviewer can read it without being an admin.",{"title":185,"searchDepth":186,"depth":186,"links":989},[990,991,995,996,1003,1004,1005,1006],{"id":572,"depth":186,"text":573},{"id":639,"depth":186,"text":640,"children":992},[993,994],{"id":646,"depth":191,"text":647},{"id":761,"depth":191,"text":762},{"id":844,"depth":186,"text":845},{"id":889,"depth":186,"text":890,"children":997},[998,999,1000,1001,1002],{"id":895,"depth":191,"text":896},{"id":902,"depth":191,"text":903},{"id":909,"depth":191,"text":910},{"id":916,"depth":191,"text":917},{"id":927,"depth":191,"text":928},{"id":936,"depth":186,"text":937},{"id":952,"depth":186,"text":953},{"id":959,"depth":186,"text":960},{"id":980,"depth":186,"text":981},"The four starting roles, the two axes that control access, and how to build a custom role without locking yourself out.","i-lucide-shield-check",[],{},[1012,1013],"\u002Fhelp\u002Fteam\u002Fshifts-timesheets-and-time-off","\u002Fhelp\u002Fgrowth\u002Ffind-and-read-a-report",{"title":559,"description":1007},"help\u002Fsettings\u002Froles-and-permissions","2026-09-01","TENSZfd1Unekw8skVK5ZgEABdPfFFfQpo8przNdYK7o",1790218961106]