> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zionapp.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions

> The five built-in Zion roles, what each one can access, and how custom roles extend them

Zion has five built-in roles: administrator, supervisor, monitor, student, and parent. Every account holds exactly one of them. "Teaching staff" is the label Zion uses on screen for administrators, supervisors, and monitors together, not a separate role. There is no owner role inside a school. The console that manages Zion's own customer accounts belongs to the Zion team and sits outside any school's roles.

On top of the five built-in roles, administrators can create custom roles that give named people extra permissions. Custom roles only ever add to what someone can do. They never take anything away or replace the built-in role.

## The five roles

| Role          | Typical user                                     | Scope                                                  |
| ------------- | ------------------------------------------------ | ------------------------------------------------------ |
| Administrator | Principal, head of school, academic director     | Every learning centre and every feature in the school  |
| Supervisor    | Learning centre teacher, lead teacher            | Assigned learning centres only                         |
| Monitor       | Teaching assistant, part-time or volunteer staff | Assigned learning centres only                         |
| Student       | Enrolled student                                 | Own data only, through the student portal              |
| Parent        | Parent or guardian                               | Their own child's data only, through the parent portal |

<Note>
  Supervisors and monitors now carry the same set of permissions. The practical difference between them is the screens and dashboards each one is given, not what they are allowed to do with a student in front of them.
</Note>

## What each role can do

"Assigned centres" below means the person only ever sees data for the learning centres an administrator has put them in, no matter which filters they set on screen.

### Running the school

| Capability                                   | Administrator | Supervisor    | Monitor       | Student | Parent |
| -------------------------------------------- | ------------- | ------------- | ------------- | ------- | ------ |
| Edit the school profile, terms, and timezone | Yes           | No            | No            | No      | No     |
| Upload the school logo                       | Yes           | No            | No            | No      | No     |
| Create, edit, and archive learning centres   | Yes           | No            | No            | No      | No     |
| View learning centres                        | All           | Assigned only | Assigned only | No      | No     |
| Invite, edit, and deactivate staff           | Yes           | No            | No            | No      | No     |
| Assign supervisors and monitors to a centre  | Yes           | No            | No            | No      | No     |
| Create and manage custom roles               | Yes           | No            | No            | No      | No     |
| Open Settings                                | Yes           | No            | No            | No      | No     |

### Students and PACEs

| Capability                                           | Administrator | Supervisor       | Monitor          | Student  | Parent         |
| ---------------------------------------------------- | ------------- | ---------------- | ---------------- | -------- | -------------- |
| Add a student, import a roster, deactivate a student | Yes           | No               | No               | No       | No             |
| Move a student to a different centre                 | Yes           | No               | No               | No       | No             |
| Promote or graduate students in bulk                 | Yes           | No               | No               | No       | No             |
| Edit a student record                                | Yes           | Assigned centres | Assigned centres | No       | No             |
| View student rosters                                 | All centres   | Assigned centres | Assigned centres | No       | No             |
| Assign PACEs to a student                            | Yes           | Assigned centres | Assigned centres | No       | No             |
| Manage the PACE catalog and custom subjects          | Yes           | No               | No               | No       | No             |
| View their own or their child's data                 | All           | Assigned centres | Assigned centres | Own only | Own child only |

### Goal Check, grading, and attendance

| Capability                                 | Administrator | Supervisor       | Monitor          | Student  | Parent         |
| ------------------------------------------ | ------------- | ---------------- | ---------------- | -------- | -------------- |
| Set goals and mark progress                | All centres   | Assigned centres | Assigned centres | No       | No             |
| View Goal Check history                    | All           | Assigned centres | Assigned centres | Own only | Own child only |
| Export Goal Check data                     | Yes           | No               | No               | No       | No             |
| Enter and submit scores                    | All centres   | Assigned centres | Assigned centres | No       | No             |
| Moderate scores and set the pass threshold | Yes           | No               | No               | No       | No             |
| Mark and view attendance                   | All centres   | Assigned centres | Assigned centres | No       | No             |

### Calendar, reports, and stock

| Capability                                                | Administrator | Supervisor       | Monitor          | Student | Parent |
| --------------------------------------------------------- | ------------- | ---------------- | ---------------- | ------- | ------ |
| View the calendar                                         | Yes           | Yes              | Yes              | Yes     | Yes    |
| Create or delete a calendar event                         | Yes           | No               | No               | No      | No     |
| Generate and view reports                                 | All centres   | Assigned centres | Assigned centres | No      | No     |
| View reports across every centre, and share them by email | Yes           | No               | No               | No      | No     |
| Generate the weekly school-wide report                    | Yes           | No               | No               | No      | No     |
| View stock and check books in and out                     | Yes           | Yes              | Yes              | No      | No     |
| Receive stock and make adjustments                        | Yes           | No               | No               | No      | No     |

## Role details

### Administrator

Administrators have full access to every learning centre, every student, and every feature, including school settings, staff management, custom roles, and weekly school-wide reports. A school typically has one to three administrators.

### Supervisor

Supervisors run the learning centres they are assigned to. They set goals, mark Goal Check progress, enter scores, mark attendance, log behaviour, verify homework, check books in and out, and generate reports for their own centres. They cannot admit or remove students, move a student between centres, create centres, invite staff, create calendar events, or open Settings, and they never see data from a centre they are not assigned to.

### Monitor

Monitors hold the same permissions as supervisors and work the same way within their assigned centres. The role exists so a school can distinguish a lead teacher from a teaching assistant or volunteer, and the two see slightly different screens and dashboards. Like supervisors, monitors cannot admit or remove students, create calendar events, or open Settings.

### Student

Students sign in to the student portal and see their own goals, progress, PACE assignments, grades, homework, attendance, calendar, and activities, along with their own profile page. What they see is read-only and limited to their own record.

### Parent

Parents sign in to the parent portal and see their child's progress, attendance, homework, behaviour, grades, and report cards, and can book meetings with their child's teacher. What they see is read-only and limited to their own child.

Parents only get access when a staff member deliberately invites them. Adding a parent email to a student record does not create the link. An administrator or supervisor can see which invitations are still outstanding, send them again, revoke one that has not been accepted, and detach a parent who was linked to the wrong student.

## Custom roles

Administrators can layer custom roles on top of a user's built-in role from **Settings > Roles**. A custom role is a named set of permission keys that gets added to whatever the user already has through their built-in role.

<Steps>
  <Step title="Open Settings, then Roles">
    Administrators can reach this page.
  </Step>

  <Step title="Create a role">
    Choose **New role**, name it, add a description, and tick the permissions you want it to grant.
  </Step>

  <Step title="Give the role to someone">
    On that person's record, under **Assigned Roles**, add the custom role. It sits on top of their built-in role rather than replacing it.
  </Step>

  <Step title="Check the result">
    Their **Effective Permissions** card shows everything they can now do, and where each permission came from.
  </Step>
</Steps>

Every built-in role also appears in the same list, so you can see exactly what makes up the administrator, supervisor, monitor, student, and parent sets. These are marked with a System badge. They cannot be renamed or deleted, but you can copy one to create a version you can change. If you delete a custom role that people still hold, Zion tells you how many people are affected before you confirm.

<Note>
  An administrator cannot use custom roles to grant someone more than they hold themselves.
</Note>

Every change to a role or its permissions is recorded, and you can filter that history by who made the change from **Settings**, **Roles**, **View audit log**.

## What you can grant

Permissions are grouped by area of the app. Administrators hold all of them. Supervisors and monitors hold a smaller set limited to their own centres. Students and parents can only view their own data and the calendar.

| Area       | What you can grant                                                                 |
| ---------- | ---------------------------------------------------------------------------------- |
| Students   | View, add, edit, remove, view every centre, assign PACEs                           |
| Goal Check | View, set goals, mark progress, view every centre, export                          |
| Grading    | View, submit scores, moderate, view every centre                                   |
| Attendance | Mark, view, view every centre                                                      |
| Calendar   | View, create a centre event, create a school-wide event, delete any event          |
| Reports    | View, generate, view every centre, share                                           |
| Settings   | Open Settings, edit the school profile, manage users, manage terms, manage centres |
| Roles      | View roles, manage roles                                                           |
| Stock      | View, manage, check out                                                            |

<Warning>
  A few of these are listed ahead of being switched on, including viewing Goal Check, grading, attendance, and reports across every centre. Where that is the case, the role editor shows the option as Coming soon rather than offering it as something you can actually grant today.
</Warning>

## Related resources

<CardGroup cols={2}>
  <Card title="Teaching staff and users" icon="users" href="/features/organization/teaching-staff-and-users">
    Invite staff, assign roles, and manage user accounts
  </Card>

  <Card title="Learning centres" icon="graduation-cap" href="/features/organization/learning-centres">
    Assign supervisors and monitors to centres for access control
  </Card>

  <Card title="Roles and permissions" icon="sliders" href="/features/organization/roles-and-permissions">
    Detailed walkthrough of creating and managing custom roles
  </Card>

  <Card title="Staff management guide" icon="users" href="/guides/administrator/staff-management">
    How administrators invite staff and assign roles day to day
  </Card>
</CardGroup>
