Organisation · Permissions
Roles & permissions
Roles are templates of permissions. System templates are immutable.
- 🔒 System templateFederation administratorfederation_admin
- 🔒 System templateDistrict administratordistrict_admin
- 🔒 System templateClub administratorclub_admin
- 🔒 System templateCompetition directorcompetition_manager
- Custom roleClub treasurerclub_treasurer
Assign a role to a principal in a scope. Roles are additive.
- anna.lindberg@malmobk.seClub administrator · org_node · MALMO
- 0b1d-…-serviceCompetition director · tenant
- agent://ranking-botDistrict administrator · org_node · SKANE
Requests for role assignment. The approval flow is handled in Cases.
- 🕘 Pending Open in Cases →Club treasurerorg_node · MALMO
- ✓ Approved Open in Cases →Competition directortenant
- ✕ Rejected Open in Cases →District administratororg_node · GBG
Club treasurer
🔒 System template (read-only)Tick permissions per namespace. The whole set is saved (replaces the previous).
An unknown permission at save gives an error (no silent swallowing).
Time-limited roles end on their own — e.g. competition director for a single event.
- ActiveCompetition director · karin.akesson@almvikpk.seEvent · Sommarslaget 2026 · until 16 Aug 2026 23:59
- ActiveSecretariat · johan.berg@nordvikbk.seEvent · DM Skåne · until 6 Jul 2026 20:00
- ExpiredCompetition director · sara.holm@sjostadpk.seEvent · The Spring Meet · until 12 May 2026
Delegation of authority — let an assistant act in your place, time-limited or until further notice. Everything the assistant does is logged on both.
- ActiveFederation administrator (you) → assistent@svenskboule.seMember cases + licences · 1 Jul – 31 Aug 2026 (holiday)
- ActiveDistrict admin West → vice@bdvast.seSanctioning in the district · Until further notice
Duplicate protection: the same delegation twice gives an error instead of a silent copy.
An answer to "why may/may not this person do this?" — without guessing.
CHECK ACCESS
✓ ALLOWED
Granted via Club administrator (assigned in OrgNode MALMO) — the role inherits competition.sanction from the template.
✕ DENIED
None of the person's roles grant the permission in that scope. Closest: Club administrator in NORDVIK (wrong OrgNode). Everything is denied until something explicitly allows (deny by default).
ROLE TREE WITH INHERITANCE
Federation administrator ├─ inherits District administrator │ ├─ inherits Club administrator │ │ └─ admin.members.manage · competition.create │ └─ competition.sanction · org-node.suspend └─ tenant-config.manage · admin.roles.manage
⚠ A missing or circular inheritance reference is marked in the tree instead of hidden. Wildcards (e.g. competition:*) are shown expanded so you see exactly what they cover.