Reference
Event Management Role Access Matrix
Role expectations for Event Management routes, actions, sensitive records, and handoffs.
First created Last updated
Overview
Event Management access decides who can create events, change public pages, review registrations, operate check-in, handle finance-adjacent records, and manage staff or inventory. A role should match the work someone is trusted to do, not just the page they want to open.
The dashboard role model used for Event Management is centered on partner staff. Report-system roles are separate and should not be treated as permission to run event operations.
Role expectations
| Role | Expected Event Management access | Typical use |
|---|---|---|
partner_admin | Full partner-level operational access, including event setup and sensitive configuration. | Event leads, organization admins, release/certification owners. |
partner_operator | Event and rego operations access where partner has delegated operational work. | Registration staff, check-in leads, roster staff, POS operators, inventory operators. |
viewer | CMS-oriented read access, not a normal Event Management operator role. | Content reviewers who should not change event records. |
event_staff | Report-system staff role, not the primary EMS role. | Trust and Safety report work, not event setup. |
fph_admin | Platform-level administrator access where central support or certification requires it. | FPH support, platform operations, production certification. |
Access by work area
| Work area | Normal owner | Sensitive actions |
|---|---|---|
| Event creation and Details | Partner admin or event lead | Public status, event dates, venue address, image, public description. |
| Rego Config | Registration lead or partner admin | Prices, capacities, entitlements, ZEP/Discord/Telegram access, group rules. |
| Payments Config | Finance lead or partner admin | Payment accounts, QR codes, surcharge, VAT, refund rules, confirmation behavior. |
| Regos, upgrades, transfers, refunds | Registration and finance staff | Payment updates, approvals, declines, identity transfer, refund proof. |
| Check-In and Inclusion Claim | Check-in lead and trained event-day staff | Entry decisions, notes, flags, item claims. |
| Human Resources and roster | HR lead or volunteer coordinator | Staff records, volunteer decisions, shifts, subsidies. |
| Communications | Event lead or communications owner | Email/inbox audience, subject, markdown body, previews, sends. |
| Inventory and POS | Logistics or finance operators | Stock movement, item IDs, POS basket, payment method/account, sale submission. |
| Offline snapshots | Event lead, check-in lead, or LAN operator | Exported attendee data, imports, sync history, offline files. |
Sensitive records
| Record | Why access matters | Minimum handling rule |
|---|---|---|
| Attendee registrations | Contains identity, contact, tier, payment, and event access state. | Only staff doing registration, support, or check-in work should use it. |
| Payment accounts and QR codes | Directs attendee money to organizer accounts. | Review by a finance owner before opening paid rego. |
| Refund proof | Can include financial screenshots and account references. | Keep to finance/support staff. |
| Offline snapshot files | Can contain operational attendee data. | Export only for intended devices and track who received the file. |
| Volunteer applications | Contains applicant answers and contact details. | Share only with HR/volunteer reviewers. |
| Staff roster | Shows staff movements and coverage. | Share with event staff who need it for operations. |
Handoff rule
When assigning access-sensitive work, name the role, surface, event ID, and exact action. “Can you handle rego?” is too vague; “please review pending refunds in /ems/manage/refunds?id=... and do not approve above PHP X without finance review” is actionable.
Common mistakes
Do not give broad Event Management access just so someone can answer one question. Open the specific record together, capture the needed answer, and keep edit access limited to people responsible for the outcome.