permissions for individual staff accounts vs. work email accounts

Request:
Set clear permission rules for individual staff accounts versus company/work email accounts.

Individual staff accounts should have very limited access. These accounts are only meant for staff members to view their own schedule and the general planning/calendar view.

Context:
Individual staff accounts will be created using the staff member’s personal email address. These accounts are private staff accounts and should not have access to operational, customer, financial, catalog, or administrative information.

The purpose of these accounts is only to allow staff to see:

  • Their own individual planning for the upcoming 2 weeks

  • The general calendar/planning view for the upcoming 2 weeks, as shown in Attachment 4

They should not be able to view or access:

  • Customer profiles

  • Reservations, except where needed to understand their own assigned planning

  • Financial information

  • Payments

  • Catalog/product setup

  • Reports

  • System settings

  • Partner information

  • Any administrative modules

Goal:
Create a clear separation between private staff accounts and work email accounts, so staff can view the planning they need without having access to sensitive or unnecessary business information.

Suggested permission logic:
Accounts that do not use an @divefriendsbonaire.com email address should only have access to planning/calendar visibility.

Example:

  • Personal staff email address = limited access

  • @divefriendsbonaire.com work email address = access based on assigned role

Work email accounts:
All locations and departments have their own @divefriendsbonaire.com email addresses, for example:

These work email accounts should receive permissions based on their actual role and operational needs.

Important distinction:
The system should clearly distinguish between:

  1. Private staff accounts
    Used only for personal planning visibility.

  2. Work email accounts
    Used for operational work and role-based permissions.

Suggested access rules:

  • Private staff email accounts: planning/calendar view only

  • Location work email accounts: access based on location role and operational responsibilities

  • Department work email accounts: access based on department role

  • Management/admin accounts: broader permissions where needed

Open question:
Should the system automatically restrict permissions based on email domain, or should this be handled manually through roles?

Preferred logic:
As a default rule, any account that does not have an @divefriendsbonaire.com email domain should only be able to see the calendar/planning view, unless manually approved otherwise.

Please authenticate to join the conversation.

Upvoters
Status

Completed

Board
💡

Feature Request or Bug Report

Date

22 days ago

Author

Marketing Team

Subscribe to post

Get notified by email when there are changes.