All resources

Field guide

Team Roles and Permissions Guide

Get the right people in the right roles in 15 minutes — without locking yourself out or over-exposing case data.

15 min · 4 stepsNew admins onboarding a team, or existing admins doing a quarterly access review.

Outcome

A clean team list with correct roles, a documented partner-viewer access list, and an audit confirming nobody has more access than they need.

  1. Step 01 · 3 min

    Understand the roles

    AidGrid has three roles. Admin: full access including team management and case deletion. Coordinator: full operational access — triage, route, refer, resolve, manage resources — but no destructive deletes. Viewer: read-only on cases and reports, no edits, no exports of raw case data. Pick the lowest role that still lets the person do their job.

    • Two admins minimum (so vacation/illness doesn't lock you out)
    • Coordinators are the default for operations staff
    • Viewers used for partner agencies, board members, auditors
  2. Step 02 · 5 min

    Set up your team

    Settings → Team → Invite. Enter email, name, and role. Invitations expire after 7 days. For partner-org users who need to see cases referred to them, use the viewer role plus the 'partner' tag — they'll see only cases your org has actively referred to their org, not the full queue.

    • All operations staff invited with the correct role
    • Partner viewers tagged and limited to referred-to-them cases
    • Unaccepted invitations followed up on or revoked
  3. Step 03 · 4 min

    Configure permissions

    Most permissions are role-based and not individually configurable — that's by design, so access is predictable. The exceptions are: who can edit org settings (admins only), who receives 90+ urgency pages (configurable per coordinator in their profile), and which coordinators can resolve cases (default all coordinators; can be restricted to senior coordinators if you want a review gate).

    • 90+ urgency page list reviewed — at least one person always on-call
    • Resolve permission scoped if you want a senior-coordinator review gate
    • Org settings access confirmed limited to current admins
  4. Step 04 · 3 min

    Review access audit

    Settings → Audit log → filter by 'access events'. Review the last 30 days. Look for: former staff who still have active sessions, partner viewers who haven't logged in for 60+ days (revoke), repeated failed sign-ins (possible compromised credential — force password reset). Run this quarterly minimum.

    • Inactive accounts (60+ days no login) reviewed and revoked
    • Failed sign-in patterns investigated
    • Quarterly access review on the calendar

Next guide

Flash Flood Response Setup

45 min · 6 steps

Open next