Roles determine what a person can see and do on the platform. Aerolync works with a single rule: all permissions come from roles. Someone who has platform access but no roles can log in and sees nothing. Grant a role and the matching parts of the platform appear.
You configure roles in Config > Roles and assign them to people on the Account tab of a relation.
How permissions work
Three things together decide what somebody can do:
| Layer | What it controls | Where you manage it |
|---|---|---|
| Platform access | Whether the person may enter the platform at all | Account tab of the relation |
| Your subscription | Which modules your organisation has (Fleet, Finance, Drive, ...) | Set by Aerolync for your organisation |
| Roles | What the person may do inside those modules | Config > Roles + the Account tab |
A permission only takes effect when all three allow it. A permission for a module your organisation does not have stays switched off in the role editor, with a note that it is not included in your subscription.
Multiple roles per person are allowed. The permissions are combined: a person receives every permission granted by any of their roles. Removing one role therefore does not remove a permission that another role also grants.
System roles
Every organisation starts with four roles that Aerolync maintains. You cannot rename or delete them, but you can adjust their permissions to fit your organisation.
| Role | Intended for |
|---|---|
| Administrator | Full access to every module your organisation has |
| Aerodrome Commander | Aerodrome operations: flight register, PPR, flights, kiosk |
| Flight Instructor | Instruction: scheduling, flight training, gradings |
| TKI | Theoretical knowledge instruction: TKI classes and sessions |
Assigning the Aerodrome Commander, Flight Instructor or TKI role also makes the person appear as such elsewhere in Aerolync -- for example in instructor selection lists in the scheduler and in the Pilot App.
Alongside these, you create as many roles of your own as you need: Treasurer, Secretary, Maintenance, Board member, and so on.
Permissions in a role
Permissions are grouped per module. Most modules have a view permission and one or more edit permissions; sensitive permissions are marked with a warning icon.
- View permissions show the module and its data. Someone with view rights on Fleet sees the aircraft, flight logs and defects, but changes nothing.
- Edit permissions allow changes. Edit always includes view, so you never need to switch on both.
- Sensitive permissions have consequences beyond the screen: sending invoices, releasing an aircraft to service, sending a mass mailing, exporting personal data, granting physical access, or managing roles. Grant these deliberately.
A few permissions are worth calling out:
| Permission | Why it matters |
|---|---|
| Relations > Manage access | Allows switching platform access on and off for other people |
| Roles > Assign roles to relations | Allows granting other people permissions |
| Roles > Create, edit & delete roles | Allows changing the permission structure itself |
| Finance > Create & send invoices | Sends real invoices to your relations |
| Aeromail > Send mass mailings | Irreversible: the mail goes out |
| Fleet > Release to Service | Changes the airworthiness status of an aircraft |
Creating a role
- Go to Config > Roles.
- Click Add role.
- Enter a name and, optionally, a short description.
- Switch on the permissions this role needs. Work per module: first the view permission, then the edit permissions that apply.
- Click Save.
Tip
Start with a role that is too limited rather than too broad. It is easier to add a permission when somebody reports something missing than to discover later that too many people had access to Finance.
Copying an existing role
- Go to Config > Roles and open the role you want to use as a starting point.
- Click Duplicate.
- Change the name and adjust the permissions.
- Click Save.
This is the quickest way to create variants, for example a Treasurer with and without invoicing rights.
Adjusting a system role
- Go to Config > Roles and open the system role.
- Adjust the permissions. The name stays fixed.
- Click Save.
Everyone who has that role is affected immediately. A change to the Flight Instructor role therefore applies to all instructors in your organisation.
Deleting a role
- Go to Config > Roles and open the role.
- Click Delete.
- If the role is still assigned to people, you are told how many. Confirm to remove the role from them as well.
System roles cannot be deleted.
Assigning roles to a person
- Open the relation and go to the Account tab.
- Make sure Platform Access is switched on. Without it the person cannot enter the platform, no matter which roles they have.
- Under Roles, click Assign Role and select the role.
- Repeat for any additional roles.
Use Show effective permissions to see exactly what the person can do once all their roles are combined.
Removing a role
- Open the relation and go to the Account tab.
- Find the role in the list and click the remove icon.
The person immediately loses every permission from that role, unless another one of their roles also grants it.
Common tasks
Give a treasurer access to finance only
- Create a Treasurer role.
- Switch on: Finance (view), transactions, invoices, wire transfers, and exports as needed.
- Switch on Relations (view) so the treasurer can look people up.
- Assign the role, and switch on Platform Access for the person.
The treasurer sees the Finance module and the relation list, and nothing else.
Let an instructor also do the bookkeeping
Do not extend the Flight Instructor role -- that would affect every instructor. Instead, assign this person the Treasurer role in addition to their Flight Instructor role. The permissions are combined.
Find out why someone cannot see something
- Open the relation and go to the Account tab.
- Check Platform Access.
- Click Show effective permissions and look for the module in question.
- If the module is missing entirely, your organisation may not have it in its subscription. Check Config > Roles: permissions for modules you do not have are shown greyed out.
Good practice
- Build roles around jobs, not around people. A "Treasurer" role stays usable when the treasurer changes; a role named after a person does not.
- Use multiple roles instead of exceptions. Somebody who instructs and does the bookkeeping gets two roles. That keeps both roles clean and reusable.
- Be sparing with the sensitive permissions. Invoicing, mass mailings, role management and physical access deserve a deliberate decision.
- Check the effective permissions after changes. The preview on the Account tab shows what someone can actually do, across all their roles at once.
- Keep at least two people with the Administrator role. That way your organisation is never locked out of its own platform.