Rostery
Security

Custom Roles & Permissions

Permissions that match how you actually work

  • Roles you define
  • Segregation of duties
  • Support workers see only their own
  • Access that matches the job
Roles built from individual permissions, not fixed tiers

Fixed role tiers never match a real organisation. A rostering coordinator who should not see pay rates, a finance officer who should not read progress notes, a team leader who approves timesheets but not payments — none of those fit neatly into admin, manager and staff.

Custom roles permissions — how it works

Roles are built from individual permissions rather than chosen from a list. Grant exactly the capabilities a job needs — view participants, edit rosters, approve timesheets, see financial reports, release payments — and assign that role to the people who do that job.

Permissions are enforced server-side, not by hiding menu items. A user without a capability cannot reach the data by navigating to it directly, which is the difference between a permission and a suggestion.

Why it matters for NDIS providers

Over-permissioning is the normal state of small organisations, and it is the reason a payroll error or a privacy breach can come from someone who was only trying to help. Roles that match jobs limit damage without limiting work.

  • Built from capabilities: roles composed of individual permissions rather than fixed tiers.
  • Enforced server-side: a hidden menu is not a permission; the data is genuinely unreachable.
  • Matched to real jobs: the roles your organisation actually has, not three generic ones.

What's included

  • Permission-level control. Capabilities granted individually rather than in bundles.
  • Custom role definitions. Roles named and composed to match your structure.
  • Server-side enforcement. Access checked at the API, not only in the interface.
  • Sensitive data gating. Pay rates, financial reports and clinical notes controlled separately.
  • Per-organisation roles. Your role definitions, not shared with any other organisation.

Who it's for

Any organisation past a handful of staff, and particularly those where administrative, clinical and financial responsibilities sit with different people. It also matters for privacy: participant health information should not be visible to everyone who can see a roster.

Getting started

Custom Roles & Permissions is included in your Rostery plan and works the moment your data is in — there is no separate module to buy or set up. Book a demo and we will show it on your own workflows, and use Rostery's “Smart Switch” data migration to bring your existing clients, staff, shifts and notes across from your current software in minutes.

Terms used on this page

Related capabilities

Source

The rules this feature works to are set by NDIS Quality and Safeguards Commission, which is the authority on them and is updated more often than any page here.

Why teams love Custom Roles & Permissions

Roles you define

Per-function permissions rather than a fixed list of job titles.

Segregation of duties

Approver cannot be payer; whoever changed bank details cannot verify them.

Support workers see only their own

Their shifts, their notes, their documents — nothing else.

Access that matches the job

Not three tiers that force over-permissioning.

Privacy by construction

Health information limited to the people who need it.

Custom Roles & Permissions — questions

Yes. Financial visibility is a separate capability from rostering, so a coordinator can build a roster without seeing what anyone earns. That separation is one of the more common reasons organisations move away from fixed role tiers.

Ready when you are

Ready to transform your NDIS operations?

See Rostery running on your own rosters, funding and award rules — not a canned tour. Join 600+ providers already using it.

Guided walkthroughYour own dataNo obligation

No setup fees · No obligation · Australian data storage