Field & Field Action Permissions
Fields on a user's profile are readable by other members defined within GatherPack.
Benefits from #269
Use Cases
- Dietary restrictions may not be appropriate to view among student members
- Other sensitive parent-supplied fields (medical/healthcare info, travel
medications, special instructions)
- Academic eligibility: broad read access including the student, but write
access limited to a specific role rather than any manager
Necessary Flexibility
- Actions: read and write independently configurable per field
- Access level: Admin, Manager (scoped to shared team, not org-wide), Member
- Relationship binding: guardian-to-student access, which will need a way to mark
which relationship types actually confer it, since relationship types are
currently just admin-defined labels
- Full concealment from a specific person (not just read-only), for cases like a
field visible to a guardian and staff but hidden from the student
Other Thoughts
- Are there other policy/permission components readily available to tackle this?
- Permissions for non-data-related items like taking actions?
Field & Field Action Permissions
Fields on a user's profile are readable by other members defined within GatherPack.
Benefits from #269
Use Cases
medications, special instructions)
access limited to a specific role rather than any manager
Necessary Flexibility
which relationship types actually confer it, since relationship types are
currently just admin-defined labels
field visible to a guardian and staff but hidden from the student
Other Thoughts