Every new organization starts on roles and capabilities. Older organizations are moved over one at a time. Until yours is, you still see the older Admin and Staff capability checkboxes.
Every membership in 360Player carries a role, and that role decides what the person can see and do in that group. A role is a named bundle of capabilities, and each capability has levels — so "can look at payments" and "can issue invoices" are two levels of one setting rather than two unrelated switches.
What a role is made of
Role type — Player, Staff or Admin. The type sets the starting capabilities and decides whether the role reaches into subgroups.
Title — what the role is called in your organization: Coach, Treasurer, Team manager.
Description — optional. It shows as a hover on the roles list, so it is the place to record why the role exists.
Capabilities — the individual permissions, grouped by area of the product.
Capability levels
A capability is not simply on or off. Most have a short ladder of levels, and each level includes everything below it.
Off — no access.
View — can see it.
Change — can see it and change it.
Manage — can also manage what belongs to other people.
Not every capability offers every level. Many have just one and are simply On or Off — Export members, Comment on Events and Chat, for example. Manage is offered on Team Calendar, Group Posts, Videos, Player development, Training activity, Game statistics and Tournaments, among others.
Who a person can see
Three capabilities in the Members group decide how much of your membership a person sees. "Their groups" means the groups their role reaches.
Members — View shows who is in their groups. Change also lets them add, remove and manage members.
Member profiles — View lets them open the profiles of members in their groups. Change also lets them edit, archive and merge them. Without it, they can see who is in a group but cannot open other members' profiles.
List all users in the organization — lets them see and search every member of the organization, wherever they sit, when picking people to add and when starting a chat. Without it, they only see and search the members of their own groups. Given in any group, it reaches the whole organization.
Role types and where they start
Player — participation. Sees their group, its calendar and posts, the training library, their own development records, and can comment on events.
Staff — view and change across the areas a coach or team lead works in: calendar, matches and statistics, training, video, player development, group posts.
Admin — everything Staff has, plus the organization itself: members, groups, roles, payments, registrations, scheduling and settings.
A fourth type, Owner, holds every capability and exists at the top of the organization. Owner roles cannot be created and Owner is not offered in the role editor. Only an Owner can make someone else an Owner — see Change a person's role or capabilities.
Whatever type you start from, the capabilities are yours to change. A Player-type role can be given more, and an Admin-type role can have capabilities taken away.
Three things called "default"
The word turns up in three different places, and they are not the same thing.
1. The roles you start with. Every organization is created with one role per type, named Player, Staff, Admin and Owner. These are sometimes called the default roles, but there is nothing special about them beyond being there first: they are ordinary roles, and you can rename them, change their capabilities or delete them once something else covers the type.
2. The Default label on the roles list. This is the one that has a real effect. Each type has exactly one role carrying the label, and that is the role a person is given when they are added to a group and nobody picks a role for them — a registration form, an import, a bulk add to a team. Change what the labelled role grants and you change what every future member of that type starts with.
Because there is exactly one per type, Set as default moves the label rather than adding a second one. The role that had it loses it. A role carrying the label cannot be deleted until another role takes it over.
3. "The role default" on a person's capability screen. When you adjust capabilities for one person, what their role grants is the default. A card with changes shows Changed, and Reset to the role default puts that card back. It has nothing to do with the Default label — it just means "whatever this person's role says".
How access travels through your groups
A role sits on one membership, in one group. What happens in the groups below it depends on the type.
Staff and Admin roles reach down. Whatever the role grants in a group, it grants in every group beneath it, however deep. An Admin in Academy is an Admin in Girls and in G15.
Player roles do not. A Player-type role applies only in the group it is attached to.
Organization only capabilities work only at the top. Capabilities marked Organization only in the role editor — payments, registration forms, schedule templates, websites and a few more — do nothing unless the role is given on the top-level group.
This is why organization-wide work — payments, registration forms, roles themselves — is done from a membership in the top-level group.
Legal guardians follow their child's memberships, but only where the child's role is Player-type. A guardian never inherits a Staff or Admin role.
Adjust access for one person
You can give one person more or less than their role grants, on a single membership — see Change a person's role or capabilities. Anything set that way applies only in the group where you set it — it does not reach into subgroups the way the role itself does. When the extra access has to cover a whole branch of the organization, put the person on a role that grants it, attached at the top of that branch.
Where roles are managed
Open the top-level group of your organization and go to Settings > Roles. The entry only appears if you hold the Roles capability yourself. That is also where you build new ones — see Create a custom role.
Roles is the capability that unlocks the others. Anyone with Change on Roles can grant any capability to anyone, including themselves. Keep it to the people who are meant to decide access.
If you do not see Settings > Roles
Every new organization starts on roles. Older organizations are moved over one at a time. Until yours is, access is set with the older capability checkboxes on each user — see Assign capabilities to an admin or staff member. Nothing is lost in the switch: admins and staff keep the access they already had.
