Who can see what谁能看到什么
Why a colleague cannot see a screen you can — roles, menu access, and what your academy has switched on.为什么同事看不到你看得到的画面——角色、菜单权限,以及你的学院开启了什么。
这篇指南的正文目前只有英文版。标题、摘要与导览已翻译;内文仍在翻译中。
"It's not on my screen" has three possible causes, and they are fixed in different places. Working through them in order saves a lot of time.
1. Their role, at that branch
Roles are assigned per branch. Somebody can be a coach at one branch and an admin at another, and they get each branch's access separately.
Check Management → Users, open the person, and look at their role assignments. Someone who has moved branches and kept their old assignment is the commonest version of this problem.
See Add a staff user.
2. What your academy has unlocked for that role
Beyond roles, each academy controls which screens each role sees. Two academies with identical roles can have different menus.
The owner sets this: Settings → Organization → Role Permissions, a grid of roles down one side and pages across the other. Tick a box and everyone with that role gets the page; untick it and they lose it.
The same grid decides who may see staff phone numbers and email addresses. Whoever you have allowed to open the Users page sees them; everyone else sees names only. There is no second setting to keep in step with the first — and everyone always sees their own details, whatever their role.
3. Whether your academy has the capability at all
Some parts of the system are switched on per academy — the accounting sync is the clearest example. If your academy does not have it, nobody sees it, including the owner.
Hiding a menu is not security
The rules are enforced when the request reaches the system, not by hiding a link. Someone who types a URL for a screen they are not entitled to still gets nothing. This is always on; there is no switch that turns it off.
One case worth knowing because it surprises people: a coach cannot open the student directory or the staff directory, even by typing the address. The pickers a coach actually uses — the student search on Progress Updates, the register on their own dashboard — still work, because those only show the children in front of them.
Worth knowing for two reasons: you can trust the permissions, and you should not try to grant access by sharing a link.
Everything is recorded
Every change is logged against the person who made it, with what changed and when. Which is the real argument against sharing a login: a shared account turns an accurate record into a useless one.
Removing someone takes effect within a minute, even if they are signed in at the time. Taking a role away is just as fast. Nobody keeps reading the money screens for the rest of the week because their old login had not expired yet.
Sign-ins are recorded too. HR → Login Activity shows the owner who signed in, when, from where and on which browser — including the attempts that failed. Its Who has access now tab goes further and lists who is signed in at this moment, with an End beside each one that signs that person out on the spot. That is the tab to open the afternoon somebody leaves: taking the role away stops them doing anything, and ending the session shuts the window they already had open. Repeated wrong passwords against one account, or a flood from one place, are slowed down automatically, so a password cannot be guessed at will. It also flags any browser used by more than one staff account, which is usually a shared login you did not know about. See Add a staff user.
Related: Add a staff user · What is on the Configuration page.