Permissions and devices

Access is per domain, per member: twelve domains, each at view or edit, layered on three broad tiers. A member who can't view a domain doesn't see its tab at all.

Tiers, then domains

Every member sits in a broad tier, with manager as the default for people you invite. On top of that, access is granted or withheld per domain, at view or edit level. The domains are story, schedule, budget, deals, media and the rest.

The tier is the starting point; the per-domain grants are how you get exact. A Production Designer who should edit everything in the art department but never see deal memos is two clicks, not a new role type.

Denied by default, and invisible

Reads are denied by default. Grant what somebody needs rather than removing what they don’t. The opposite approach fails the day a domain added next year turns out to be visible to everybody.

A member who can’t view a domain doesn’t see its tab: not greyed out, absent. That’s deliberate. A crew member shouldn’t learn from the tab strip that the production has a Deals tab, and a grip shouldn’t be able to infer the budget exists from a disabled button.

The server enforces this. A tab that doesn’t render also can’t be fetched, because hiding the tab while leaving the data reachable would be theatre.

Devices

Each member’s paired devices are listed, and any of them can be revoked immediately. Members can revoke their own from their account page; managers can revoke anyone’s on this production. Select mode handles several at once, which is what you want at wrap.

Revoke when a phone is lost or a day player finishes. It’s instant, and it doesn’t affect that person’s other devices or their access to your other productions.

Access is per production

A pairing or an invitation is scoped to one production. Somebody working on two of your shows has two grants, and revoking one leaves the other alone.

That’s why handing out a QR code on a call sheet is safe: the code admits a device to that production and nothing else.