Skip to content

Permissions Reference

This document explains how permissions work in StationOne and provides detailed reference matrices showing what each role can do.

StationOne uses a two-layer permission model:

  1. Role — determines the user’s administrative level and unit scope
  2. Feature Permissions — extend a non-admin user’s access to specific areas beyond their base role

Feature permissions can be granted to a user three ways:

  • Directly on a member’s profile (permanent)
  • Via an appointment (active only while the appointment is current)
  • Via a custom group (active only while the member belongs to the group)

A user’s effective access to a feature is the union of whatever they hold directly, through any active appointment, and through any custom group they belong to.

Every scope level (brigade, group, district, region) has two parallel roles:

  • An admin role — full, unrestricted access to that unit and everything beneath it in the hierarchy
  • A user role — limited to that single unit only (no descendant visibility), with access to specific features controlled by feature permissions
Admin track: Brigade Admin → Group Admin → District Admin → Region Admin → Organisation Admin → Super Admin
User track: Brigade User, Group User, District User, Region User

Higher-level admin roles inherit all capabilities of lower admin roles plus additional scope. The four user-track roles (brigade_user, group_user, district_user, region_user) behave identically to each other — the only difference is which unit level they sit at — and none of them see descendant units the way their admin counterparts do.

The unit hierarchy defines what data admin roles can access:

Brigade → Group → District → Region → Organisation

Admins at higher levels can see and manage data from all descendant units. User-track roles (brigade_user, group_user, district_user, region_user) only ever see resources belonging to their own unit — never descendants — regardless of which level that unit sits at.


Brigade User, Group User, District User, Region User (Member)

Section titled “Brigade User, Group User, District User, Region User (Member)”

Scope: A single unit only — the brigade, group, district, or region the member belongs to. No descendant units.

These four roles share identical behaviour; only their unit level differs. A user’s access to specific features is controlled by feature permissions — either granted directly on their profile, via an active appointment, or via a custom group. Without any feature permissions, a user has minimal read access only.

Base access (no feature permissions required):

  • View and update their own profile
  • View members in their own unit (name/summary only — full profile details require the users: view permission)
  • View vehicles, equipment, inspections, events, bookings, hoses, duty crews, and hydrants belonging to their own unit
  • View and consume stock items
  • Receive and respond to assigned actions

Additional access via feature permissions:

  • Create/manage vehicles, equipment, stock, hoses, hydrants, water points, pre-plans
  • Create and conduct training sessions; view training records
  • Approve inspections, bookings; create/manage inspection templates
  • View and manage BA equipment, availability, duty crew assignments
  • Manage attendance and create events
  • See the full Feature Permissions list for everything that can be granted

Use for: Operational members who need platform access but not full administrative control. Use appointments or custom groups to grant them the specific capabilities their role requires. Group User / District User / Region User are uncommon in practice — most organisations only use Brigade User at the operational level — but they exist for members formally attached to a group/district/region unit rather than a brigade.

Scope: Single brigade only

Full administrative access for brigade-level management. Brigade admins do not require feature permissions — they have unrestricted access to all features within their brigade.

Can do everything Brigade Users can, plus:

  • Create and edit members in their brigade
  • Award qualifications and endorsements
  • Endorse members on vehicles
  • Create and manage vehicles, equipment, and stock
  • Create and assign inspections; approve/reject inspection reviews
  • Create and edit unit-level inspection templates
  • Manage action items for their brigade
  • Create and manage events and training
  • Configure public access for brigade resources
  • Assign appointments to members; create and manage custom groups

Cannot:

  • Delete vehicles permanently (requires group/district/region/organisation admin or above)
  • Access members or resources from other brigades
  • Create or modify organisation-level (proforma) templates
  • Create inspection schedules
  • Access organisation-wide settings

Use for: Brigade officers, captains, and lieutenants managing daily brigade operations.

Scope: Group and all brigades within the group

Can do everything Brigade Admins can, plus:

  • View and manage all brigades in their group
  • View and manage members, vehicles, and equipment across all group brigades
  • View inspections and manage actions across the group
  • Delete vehicles permanently within their hierarchy

Use for: Group officers managing multiple brigades.

Scope: District and all groups/brigades within the district

Can do everything Group Admins can, plus:

  • View and manage all groups and brigades in their district
  • District-wide reporting and oversight

Use for: District officers overseeing multiple groups.

Scope: Region and all districts/groups/brigades within the region

Can do everything District Admins can, plus:

  • View and manage all districts, groups, and brigades in their region
  • Regional reporting and oversight

Use for: Regional officers overseeing multiple districts.

Scope: Entire organisation

Can do everything Region Admins can, plus:

  • Create and manage all units (brigades, groups, districts, regions)
  • Create and manage inspection templates (including organisation-level proforma templates) and schedules
  • Create and configure qualification and endorsement types
  • Create and manage appointment types
  • Configure organisation-wide settings
  • Delete vehicles permanently and move them between units
  • Full reporting across the organisation

Use for: Organisation leadership and administrators managing the entire organisation.

Scope: System-wide (all organisations)

Can do everything Organisation Admins can, plus:

  • Access all organisations
  • Create and manage organisations
  • Configure system settings

Use for: Platform administrators and system operators only.


Feature permissions extend what a non-admin user (brigade_user, group_user, district_user, region_user) can access beyond their base role. They are granted:

  • Directly on a member’s profile (permanent)
  • Via an appointment (active only while the appointment is current)
  • Via a custom group (active only while the member belongs to the group)

A member’s effective permission for a feature is the union of all three sources. Admin roles (brigade admin and above) always have full access within their scope and are not affected by feature permissions.

Some features are only available when the corresponding module is enabled for the organisation/unit — these are marked below. Core features (no module gate) are always available.

Important: the actions listed below are the only checkpoints StationOne’s policies actually enforce. If a feature has no view action listed (e.g. Vehicles, Inspections, Events, Bookings, Hoses, Duty Crews, Hydrants), viewing that resource within a user’s own unit requires no feature permission at all — it’s part of everyone’s base access.

FeatureModule gatePermissionWhat it grants
VehiclesmanageCreate & edit vehicles
EventscreateCreate & edit events
manage_attendanceManage attendance
MembersviewView full member details
view_induction_plansView active induction plans
view_offboarding_plansView active offboarding plans
BookingsapproveApprove & reject bookings
InspectionsinspectionsapproveApprove & review inspections
manage_templatesCreate & edit inspection templates
Training & SkillstrainingviewView training records
createCreate & edit training records
manageManage member skills & attendance
Skills Maintenanceskills_maintenanceviewView skills maintenance plans & progress
manageCreate & edit plans and enrolment
sign_offSign off member skill completions
Breathing ApparatusbaviewView BA equipment
manageManage BA sets, cylinders & components
HydrantshydrantsmanageCreate & edit hydrants
manage_runsCreate & edit hydrant runs
Hose ManagementhosesmanageCreate, repair & assign hoses
Pre-Planspre_planscreateCreate & edit pre-plans
AvailabilityavailabilityviewView member availability
manageManage own & others’ availability
Duty Crewsduty_crewsmanageManage duty crew assignments
Water Pointswater_pointsviewView water points
manageCreate & edit water points
Brigade Activitiesbrigade_activitiesviewView brigade activities
createLog & edit brigade activities
ReportingviewView brigade reports
Stock ManagementmanageCreate, restock & manage stock items
Purchase Orderspurchase_ordersviewView purchase orders
manageCreate, edit & manage purchase orders
EquipmentmanageCreate & manage equipment
PPC & Equipment AllocationppcviewView PPC allocations
manageIssue, return & manage PPC items
LibrarylibrarycreateCreate articles and folders
updateEdit articles and folders
deleteDelete articles and folders
Development PlansviewView member development plans
manageCreate & edit member development plans

The list of feature permissions available to grant is filtered per-unit (or per-organisation for appointment types) to only the modules that are actually enabled — a unit without the Hydrants module enabled won’t show Hydrants permissions when configuring an appointment type or custom group.

Purchase Orders module gate: most module gates check the acting unit — the unit an admin is currently viewing/impersonating, or a non-admin user’s own unit. Purchase Orders is an exception: on a specific purchase order (viewing, editing, approving, etc.) the gate checks the module setting on that PO’s own unit, not the admin’s acting unit. This means a group/district/region admin can still open and manage a purchase order belonging to a unit further down their hierarchy even if the Purchase Orders module happens to be disabled on their own home unit — matching what PurchaseOrderPolicy::Scope already allows them to see. Listing/reporting screens (which aren’t tied to one PO) still gate on the acting unit by default, but for group/district/region admins the gate is skipped instead if the Purchase Orders module is enabled on any unit in their hierarchy — so they aren’t locked out of listings/reports that the policy scope permits just because their own home unit has it disabled.

Article Library note: the Library feature permissions above control who can create/edit/delete articles generally. Individual article folders also have their own, separate per-folder access list (which users, appointment holders, or custom groups can see a given folder) that layers on top of these feature permissions.

Action items in StationOne are categorised by the area they relate to (vehicle, equipment, BA set, stock, etc.). A non-admin user only sees action items for categories they have the relevant feature permission for — except actions assigned to or flagged by them personally, which they can always see:

Action categoryPermission required
Vehiclevehicles: manage
Equipmentequipment: manage
BA Setba: view
Stock / PPE & Uniformstock: manage
Pre-Planpre_plans: create
Building & Maintenance, IT, OtherNo permission required
SuggestionAdmin roles only — never shown to non-admin users

Email notifications follow the same feature permission boundaries. A non-admin user only receives notification digests for the features they can access:

NotificationPermission required
Overdue inspection schedulesMatches the inspectable type: vehicles: manage for vehicles, equipment: manage for equipment, ba: view for BA sets
Expiring inspection itemsSame as above
Training notificationsAny training permission
Event notificationsAny events permission
Vehicle booking updatesBookings or vehicles permission

See Manage Email Notifications for more on notification preferences.


In the tables below, ✅† indicates the action is available to non-admin users who hold the appropriate feature permission (see footnote under each table). Where no permission is required, base access applies to any authenticated user in their own unit.

ActionBrigade/Group/District/Region UserBrigade AdminGroup Admin+Org AdminSuper Admin
View members in own unit (summary)
View full member details✅†
View members in hierarchy
Create members
Edit own profile
Edit members in unit
Archive/delete members
Grant platform access
Assign appointments
Create appointment types

Requires users: view.

ActionBrigade/Group/District/Region UserBrigade AdminGroup Admin+Org AdminSuper Admin
View vehicles in own unit
View vehicles in hierarchy
Create vehicles✅†
Edit vehicles✅†
Delete vehicles
Assign to different unit

Requires vehicles: manage. Viewing vehicles in your own unit requires no feature permission.

ActionBrigade/Group/District/Region UserBrigade AdminGroup Admin+Org AdminSuper Admin
View equipment in own unit
View equipment in hierarchy
Create equipment✅†
Edit equipment✅†
Delete equipment✅†❌‡

Requires equipment: manage. Unlike create/edit, deleting equipment is not extended to Group/District/Region Admins in the current policy — only Brigade Admin, Organisation Admin, and Super Admin (or a non-admin user with equipment: manage in their own unit) can delete equipment.

ActionBrigade/Group/District/Region UserBrigade AdminGroup Admin+Org AdminSuper Admin
View inspections in own unit (listing)
Create & conduct inspections
Delete inspections✅ (own unit)
Approve/reject inspections✅†

Requires inspections: approve (or inspections: manage_templates). Viewing and conducting inspections require no feature permission — any authenticated user can conduct inspections against their own unit’s resources. Deleting and approving/rejecting inspections are not extended to Group/District/Region Admins — only Brigade Admin, Organisation Admin, and Super Admin can delete or approve/reject an inspection; this is narrower than most other resources in this reference, so double-check in app/policies/inspection_policy.rb if you’re relying on it.

ActionBrigade/Group/District/Region UserBrigade AdminGroup Admin+Org AdminSuper Admin
View templates
Create/edit unit templates✅†
Create/edit org (proforma) templates
Delete templates✅ (own unit)
Create/edit schedules

Requires inspections: manage_templates. Note: Group/District/Region Admins cannot create, edit, or delete unit templates at all under the current policy — template management is limited to Brigade Admins (their own unit), Organisation Admins, and Super Admins.

ActionBrigade/Group/District/Region UserBrigade AdminGroup Admin+Org AdminSuper Admin
View actions (feature-matched)✅†
Create actions manually
Resolve/close actions✅‡✅ (own unit)❌§✅ (own org)
Reopen actions✅ (own unit)❌§✅ (own org)
Delete actions✅ (own unit)

Non-admin users see only actions in categories matching their feature permissions (see Feature Permissions and Actions), plus any action assigned to or flagged by them personally regardless of category. Non-admin users can resolve/close an action if it’s assigned to them personally, or if it’s in a category they hold feature permission for, in their own unit. § Group/District/Region Admins are not currently granted action management rights beyond an action assigned to them personally — this is narrower than most other resources in this reference (create/resolve/reopen/delete all key off brigade_admin?/organisation_admin?/super_admin? specifically rather than the full admin hierarchy). Note also that Delete actions is not available to Organisation Admin — only Brigade Admin (own unit) and Super Admin can delete an action. Verify current behaviour in app/policies/action_policy.rb before relying on this for a permissions-sensitive workflow.

ActionBrigade/Group/District/Region UserBrigade AdminGroup Admin+Org AdminSuper Admin
View stock items
Consume stock (record usage)
Create stock items✅†
Edit/restock stock items✅†
Delete stock items✅†❌‡

Requires stock: manage. Unlike create/edit, deleting stock items is not extended to Group/District/Region Admins in the current policy — only Brigade Admin, Organisation Admin, and Super Admin (or a non-admin user with stock: manage in their own unit) can delete a stock item.

ActionBrigade/Group/District/Region UserBrigade AdminGroup Admin+Org AdminSuper Admin
View events in own unit
Create/edit events✅†
Manage attendance✅‡
Delete events✅†

Requires events: create (in own unit), or being the event’s original creator. Viewing events in your own unit requires no feature permission. Requires events: manage_attendance.

ActionBrigade/Group/District/Region UserBrigade AdminGroup Admin+Org AdminSuper Admin
View qualifications
Award/remove qualifications
View endorsements
Award/remove endorsements
Configure types

Awarding/removing qualifications and endorsements is admin-only in all cases — there is no feature permission that extends this to non-admin users.


When the system checks whether a user can perform an action:

1. Is user Super Admin?
└─ Yes → Allow
2. Does user have required admin role (Brigade Admin or higher)?
└─ Yes → Check scope (is resource in user's unit hierarchy?)
└─ Yes → Allow
└─ No → Deny
3. Is user a non-admin user (brigade_user/group_user/district_user/region_user)?
└─ Is the action gated by a feature permission at all?
└─ No → Allow if resource is in the user's own unit
└─ Yes → Does user hold the required feature permission?
(via direct grant, active appointment, OR custom group membership)
└─ No → Deny
└─ Yes → Is resource in user's own unit?
└─ No → Deny
└─ Yes → Allow

User: Captain Smith, Brigade Admin at Tyabb Fire Brigade

Can access:

  • All members, vehicles, equipment, and resources at Tyabb
  • All inspections and actions for Tyabb resources
  • All events at Tyabb

Cannot access:

  • Resources from other brigades
  • Organisation-wide settings or proforma templates

User: Captain Jones, Group Admin for District 8 Group

Can access:

  • All brigades in District 8 Group (e.g., Tyabb, Somerville, Hastings)
  • All members, vehicles, equipment, inspections, and actions across those brigades
  • Deleting vehicles permanently within the group’s hierarchy

Cannot access:

  • Brigades in other groups
  • Organisation-wide templates or settings

User: Alex, Brigade User at Tyabb — appointed as Stores Officer

Can access:

  • Own profile
  • All stock items at Tyabb (create, restock, manage — via stock: manage permission)
  • Action items in the stock and PPE categories
  • Notifications about stock-related items
  • Viewing vehicles, inspections, and events at Tyabb (base access — no permission needed)

Cannot access:

  • Creating/editing vehicles, approving inspections (unless separately granted)
  • Resources from other brigades
  • Admin features

User: Priya, Group User at District 8 Group — granted duty_crews: manage directly on her profile

Can access:

  • Her own profile
  • Duty crew assignments belonging to the Group unit itself (not the brigades beneath it)

Cannot access:

  • Brigades within the group (a Group User does not inherit descendant visibility the way a Group Admin does)
  • Anything not covered by her granted feature permissions

Assign the minimum access level needed for each member’s responsibilities.

  • Operational members with no admin duties: Brigade User + appropriate feature permissions via appointment or custom group
  • Brigade officers: Brigade Admin
  • Group/district/region officers: corresponding admin role
  • Organisation leadership: Organisation Admin
  • Platform operators only: Super Admin

Appointments vs. Custom Groups for Functional Access

Section titled “Appointments vs. Custom Groups for Functional Access”

Rather than promoting a member to brigade admin to give them access to a specific area, grant feature permissions via an appointment type or a custom group instead of a full admin role. This:

  • Keeps the role level appropriate
  • Creates a clear record of who held which position and when

Choose based on how the access should behave:

  • Appointments — best for a single functional role with a defined tenure (e.g. Stores Officer, Training Officer). Access is automatically revoked when the appointment ends.
  • Custom groups — best for standing sets of members who need the same permissions indefinitely (e.g. “Senior Firefighters”), without the appointment-tenure semantics. Access lasts as long as membership in the group.

See Appointments & Feature Permissions for full details.

When a member’s role or appointment changes:

  1. End any appointments that no longer apply, and remove them from any custom groups whose permissions no longer fit
  2. Assign the new role or appointment
  3. If promoting to an admin role, feature permissions are cleared automatically
  4. Verify access is correct with the member

Regularly review:

  • Active appointments — are all still current?
  • Custom group membership — does everyone in each group still need those permissions?
  • Direct feature permission grants — are these still needed, or should they be appointment- or group-based?
  • Admin role assignments — does each admin still need that level of access?

Need: Member needs to conduct inspections and view brigade resources.

Solution: Role brigade_user. Conducting inspections and viewing vehicles/equipment/events require no feature permission — they’re part of base access within the member’s own unit.

Need: Member takes on responsibility for managing stock and PPE.

Solution: Appointment with stock: manage permission. Member gains stock management access for the duration of the appointment without needing a full admin role.

Need: Member coordinates training sessions and tracks member attendance.

Solution: Appointment with training: create and training: manage permissions.

Need: A standing group of experienced members should be able to approve inspections and bookings indefinitely, without a defined end date like an appointment implies.

Solution: Custom group with inspections: approve and bookings: approve permissions. Add/remove members as their status changes; permissions apply immediately on membership.

Need: Existing brigade user promoted to captain.

Solution: Change role from brigade_user to brigade_admin. Any existing feature permissions are cleared automatically — they are no longer needed.

Need: Member moving from Tyabb to Somerville.

Solution: Update unit assignment. Role and qualifications transfer. End and reassign any active appointments, and update custom group membership, in the new brigade.