Fixed role tiers never match a real organisation. A rostering coordinator who should not see pay rates, a finance officer who should not read progress notes, a team leader who approves timesheets but not payments — none of those fit neatly into admin, manager and staff.
Custom roles permissions — how it works
Roles are built from individual permissions rather than chosen from a list. Grant exactly the capabilities a job needs — view participants, edit rosters, approve timesheets, see financial reports, release payments — and assign that role to the people who do that job.
Permissions are enforced server-side, not by hiding menu items. A user without a capability cannot reach the data by navigating to it directly, which is the difference between a permission and a suggestion.
Why it matters for NDIS providers
Over-permissioning is the normal state of small organisations, and it is the reason a payroll error or a privacy breach can come from someone who was only trying to help. Roles that match jobs limit damage without limiting work.
- Built from capabilities: roles composed of individual permissions rather than fixed tiers.
- Enforced server-side: a hidden menu is not a permission; the data is genuinely unreachable.
- Matched to real jobs: the roles your organisation actually has, not three generic ones.
What's included
- Permission-level control. Capabilities granted individually rather than in bundles.
- Custom role definitions. Roles named and composed to match your structure.
- Server-side enforcement. Access checked at the API, not only in the interface.
- Sensitive data gating. Pay rates, financial reports and clinical notes controlled separately.
- Per-organisation roles. Your role definitions, not shared with any other organisation.
Who it's for
Any organisation past a handful of staff, and particularly those where administrative, clinical and financial responsibilities sit with different people. It also matters for privacy: participant health information should not be visible to everyone who can see a roster.
Getting started
Custom Roles & Permissions is included in your Rostery plan and works the moment your data is in — there is no separate module to buy or set up. Book a demo and we will show it on your own workflows, and use Rostery's “Smart Switch” data migration to bring your existing clients, staff, shifts and notes across from your current software in minutes.
Terms used on this page
Related capabilities
Source
The rules this feature works to are set by NDIS Quality and Safeguards Commission, which is the authority on them and is updated more often than any page here.

