Roles, module scope, and least-privilege access

Assign responsibility without creating dozens of roles, and keep each person inside the modules they need.

9 min readUpdated 8 September 2026

In short

Roles define what a person can do; module scope defines where they can do it. Use Owner, Admin, Editor, or Viewer and grant the narrowest useful module set.

On this page

Two layers of access

Scoutzy separates responsibility from operational area. This keeps four understandable roles while still supporting precise access.

  • Role: governance, management, editing, or reading capability.
  • Module scope: Attendees, Attendance, Inventory, or a combination.
  • Project access: direct membership or assignment through a Team.
  • No access: a Team member can be excluded from one Project without leaving the Team.

What each role is for

Choose a role based on accountability, not seniority outside Scoutzy.

  • Owner: full governance, ownership transfer, export, and permanent deletion.
  • Admin: settings, lower roles, and module changes without permanent data deletion.
  • Editor: creates and updates operational data in assigned modules.
  • Viewer: reads assigned modules without changing data.

Run an access review

Review access after leadership changes, before sensitive data is added, and at the end of an operating period.

Step by step

  1. 1Confirm the current Owner.
  2. 2Remove people who no longer work on the Project.
  3. 3Reduce Admins who only perform operational work to Editor.
  4. 4Remove module scopes that are no longer needed.
  5. 5Use Viewer for historical reporting access.
  6. 6Verify one lower-privilege account against the expected screens.

Useful access patterns

A small set of repeatable patterns covers most real teams.

  • Programme lead: Admin for Attendees and Attendance.
  • Event volunteer: Editor for Attendance, with Attendees included as required.
  • Equipment steward: Editor for Inventory only.
  • Committee observer: Viewer for selected reporting modules.
  • Temporary helper: Editor for the minimum module, then remove access after the event.

Put this into practice

Use this browser-only checklist during your next review.

0/5

Common questions

Why can someone see the Project but not a module?

Their role may not include that module, or the module may be disabled for the whole Project.

What happens to access when a module is disabled?

The module disappears immediately. Its old scope is ignored and removed the next time access is saved.

Continue learning