Aplauso combines a standard role, optional organization role template, explicit capabilities, and assignment scope. A role name alone is not proof that a person can see or change every record at that level.
Standard Role Hierarchy
| Role | Level | Typical scope |
|---|---|---|
| Employee | 10 | Personal profile and assigned service work |
| Front Desk | 20 | Guest-facing operational access |
| Manager | 30 | Assigned team reporting and recovery |
| Outlet Admin | 40 | One assigned service point |
| Department Admin | 50 | One assigned department |
| Property Admin | 60 | One assigned location |
| Regional Admin | 70 | Organization-wide people and location management |
| System Admin | 100 | Internal platform administration |
Higher numeric roles are used in authorization checks, but access is still constrained by organization, location, department, service-point, and data-class assignments. Business role templates can grant a governed capability set for one of those scopes.
Common Capabilities
Business pages check capabilities such as inviting people, managing roles, managing structure, viewing finance, or performing recovery actions. If a page is visible but an action is disabled, your account may have read access without the required management capability.
Personal earnings, profile, privacy, and payment access are separate from business administration. Do not use a business role to infer ownership of an employee wallet or permission to view banking details.
Assign or Change Access
An operator needs the people.role_admin capability and may manage only people inside their scope. They cannot manage their own role from the team screen or assign a role at or above their own standard level.
- Open Business > Team.
- Select the team member.
- Use the available role or assignment action.
- Verify the resulting role, template, and scope shown in the team record.
For a new person, create a scoped invitation. For an existing person who needs another location or department, use the business assignment workflow approved by the organization.
When Access Looks Wrong
Confirm the signed-in identity, organization, location, assignment, role template, and capabilities. Ask an authorized business administrator to correct the record. Aplauso Support can investigate access behavior but should not grant broader business scope without organization authorization.