Skip to main content

Roles & Permissions

Understanding what each role can do in ResponderOne.

Every department starts with two built-in roles — Member and Admin — and can add any number of custom roles with hand-picked permissions.

Built-in Roles

FeatureMemberAdmin
View published resourcesYesYes
Use mobile appYesYes
Manage resourcesNoYes
Publish resource changesNoYes
Manage documentsNoYes
Invite team membersNoYes
Manage existing membersNoYes
Change member rolesNoYes
Remove membersNoYes
Edit department settings (name & logo)NoYes
Create and manage rolesNoYes

The built-in roles can't be renamed or deleted, but their permissions can be adjusted.

Member

Members are the standard view-only users in your department. This role is appropriate for:

  • Field personnel who need to access protocols
  • Staff who only need to view resources
  • Anyone who doesn't need to edit content

Members can:

  • View all published resources, documents, and pages
  • Access the mobile app with offline support

Members cannot:

  • Edit or publish resources
  • Invite or manage other members
  • Change department settings

When members sign in to the web portal, they land on the Resources view — the management screens stay hidden.

Admin

Admins have full access to every feature. This role is appropriate for:

  • Department leadership
  • Training officers
  • IT/technology staff
  • Anyone responsible for maintaining content

Custom Roles

If the two built-in roles aren't enough — say you want training officers who can edit resources but not publish them — create a custom role:

  1. Navigate to Roles under the Entity Management section of the sidebar
  2. Click Create Role
  3. Give it a name, pick a color and icon, and select its permissions
  4. Click Create Role to save

Permissions are granular — separate keys cover viewing, creating, editing, publishing, and deleting across Resources, Documents, Members, Roles, Settings, and Pages. A few things to know:

  • Dependencies are handled for you. Granting an edit permission automatically includes the matching view permission; the editor locks it and shows why
  • You can only grant permissions you hold yourself — no one can create a role more powerful than their own
  • Duplicate an existing role from its menu to use it as a starting point
  • A role can't be deleted while members or pending invitations still use it — reassign them first. Deleting is confirmed and can be undone from the toast
  • Your department always keeps at least one role that can manage roles — ResponderOne blocks changes that would remove the last one

Choosing the Right Role

Make someone an Admin if they need to:

  • Update protocols and resources regularly
  • Manage who has access to the department
  • Configure settings

Keep someone as a Member if they:

  • Only need to read/view content
  • Shouldn't have edit access
  • Are field staff using the mobile app

Create a custom role when:

  • Someone needs a specific slice of access — like editing resources without publishing, or managing documents only
tip

Start with fewer administrators. You can always promote members later if needed.