Field guide
Team Roles and Permissions Guide
Get the right people in the right roles in 15 minutes — without locking yourself out or over-exposing case data.
Outcome
A clean team list with correct roles, a documented partner-viewer access list, and an audit confirming nobody has more access than they need.
- Step 01 · 3 min
Understand the roles
AidGrid has three roles. Admin: full access including team management and case deletion. Coordinator: full operational access — triage, route, refer, resolve, manage resources — but no destructive deletes. Viewer: read-only on cases and reports, no edits, no exports of raw case data. Pick the lowest role that still lets the person do their job.
- Two admins minimum (so vacation/illness doesn't lock you out)
- Coordinators are the default for operations staff
- Viewers used for partner agencies, board members, auditors
- Step 02 · 5 min
Set up your team
Settings → Team → Invite. Enter email, name, and role. Invitations expire after 7 days. For partner-org users who need to see cases referred to them, use the viewer role plus the 'partner' tag — they'll see only cases your org has actively referred to their org, not the full queue.
- All operations staff invited with the correct role
- Partner viewers tagged and limited to referred-to-them cases
- Unaccepted invitations followed up on or revoked
- Step 03 · 4 min
Configure permissions
Most permissions are role-based and not individually configurable — that's by design, so access is predictable. The exceptions are: who can edit org settings (admins only), who receives 90+ urgency pages (configurable per coordinator in their profile), and which coordinators can resolve cases (default all coordinators; can be restricted to senior coordinators if you want a review gate).
- 90+ urgency page list reviewed — at least one person always on-call
- Resolve permission scoped if you want a senior-coordinator review gate
- Org settings access confirmed limited to current admins
- Step 04 · 3 min
Review access audit
Settings → Audit log → filter by 'access events'. Review the last 30 days. Look for: former staff who still have active sessions, partner viewers who haven't logged in for 60+ days (revoke), repeated failed sign-ins (possible compromised credential — force password reset). Run this quarterly minimum.
- Inactive accounts (60+ days no login) reviewed and revoked
- Failed sign-in patterns investigated
- Quarterly access review on the calendar
Next guide
Flash Flood Response Setup
45 min · 6 steps