Access and permissions
Which permission each Calendar screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (19)
Permissions by screenAll Calendar screensConfiguration > SettingsShared calendarsResourcesAppointmentsReportingCalendarCalendar / Event dialog / ICSEvent dialogEvent formEvent form / Shared calendars / Appointment typesCalendar > layersAll Calendar routesPublic booking pageCustomer manage pageICS feedAll recordsAudit
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| Overview | Calendar > Overview | calendar.view (appointments card filled only with calendar.appointment) |
| Calendar | Calendar > Calendar | calendar.view (reading); calendar.edit to create, change and remember the view |
| Event dialog | Calendar > open an event | calendar.view to read; calendar.edit to answer, change, cancel |
| Event form | Calendar > New Event / Edit | calendar.edit |
| Repeating event scope | Event dialog > Edit or Cancel event (repeating) | calendar.edit |
| Layer card | Calendar > click a layer item | calendar.view plus the owning module's view right |
| Appointments | Calendar > Appointments | calendar.appointment |
| Appointment card | Appointments > open a row | calendar.appointment |
| Book an appointment | Appointments > Book appointment | calendar.appointment |
| Appointment type | Appointments > New type / Edit | calendar.appointment |
| Resources | Calendar > Resources | calendar.view to see; calendar.manage to add or change |
| Resource | Resources > New resource / open a row | calendar.manage |
| Reminders | Calendar > Reminders | calendar.view |
| Meeting load by person | Calendar > Reporting > Meeting load by person | calendar.report |
| Room and equipment utilisation | Calendar > Reporting > Room and equipment utilisation | calendar.report |
| Appointments by type and outcome | Calendar > Reporting > Appointments by type and outcome | calendar.report |
| Upcoming appointments | Calendar > Reporting > Upcoming appointments | calendar.report |
| Calendar settings | Calendar > Configuration > Settings | calendar.manage |
| Shared calendars | Calendar > Configuration > Shared calendars | calendar.view to list; calendar.manage to add or change |
| Appointment types | Calendar > Configuration > Appointment types | calendar.appointment |
| Subscribe in other apps | Calendar > Configuration > Subscribe in other apps | calendar.view to see; calendar.edit to make or stop |
| Public booking page | Public link /api/v1/public/book/<token> (no sign-in) | None (unguessable token); type must be published and active, app installed |
| Customer manage page | Manage link /api/v1/public/appointments/<token> (no sign-in) | None (unguessable token) |
| ICS feed | Feed address /api/v1/public/calendar/feed/<token>.ics | None (unguessable, revocable token) |
All Calendar screens
| Rule | What the system does |
|---|---|
| Read-only user cannot add events | Refused (403) by the route policy (calendar.edit needed); nothing saved |
Configuration > Settings
| Rule | What the system does |
|---|---|
| Settings need calendar.manage | Menu hidden; API refused 'Changing calendar settings needs the calendar.manage permission.' |
Shared calendars
| Rule | What the system does |
|---|---|
| Shared calendars need calendar.manage | Refused 'Creating a shared calendar needs the calendar.manage permission.' / 'Changing a shared calendar needs the calendar.manage permission.' |
Resources
| Rule | What the system does |
|---|---|
| Rooms need calendar.manage | Refused 'Changing rooms and equipment needs the calendar.manage permission.' |
Appointments
| Rule | What the system does |
|---|---|
| Appointments need calendar.appointment | Menu hidden; 'Seeing appointments needs the calendar.appointment permission.'; changing a type 'Changing appointment types needs the calendar.appointment permission.' |
Reporting
| Rule | What the system does |
|---|---|
| Reports need calendar.report | Menu hidden; 'Calendar reports needs the calendar.report permission.' |
Calendar
| Rule | What the system does |
|---|---|
| Another person's personal calendar is never listed | A's calendar not listed; A's event not shown; GET -> 'Event not found.' (404); only free/busy reveals A is busy |
| Company isolation | 'Event not found.' / 'Calendar not found.' / 'Resource not found.' / 'Appointment not found.' (404); row-level security on every a2n_cal_* table |
Calendar / Event dialog / ICS
| Rule | What the system does |
|---|---|
| Private event masked everywhere | Always 'Busy' with time only; search does not find it; no location, link, notes or attendees anywhere |
Event dialog
| Rule | What the system does |
|---|---|
| Attendees only answer | Buttons hidden; API 'Only the organiser or the calendar's editors change this event.' / '... cancel this event.' |
Event form
| Rule | What the system does |
|---|---|
| Viewer of a shared calendar cannot write in it | Refused: 'You only read this calendar.' |
| Room booked twice at the same moment | One saved, one 409 naming the other's booking (row lock) |
Event form / Shared calendars / Appointment types
| Rule | What the system does |
|---|---|
| Only own-company people | 'A colleague attendee must belong to this company.' / 'A member must belong to this company.' / 'Staff must belong to this company.' |
Calendar > layers
| Rule | What the system does |
|---|---|
| Layers follow the owning module's rights | HR shows only holidays and own leave; no payroll dates; Projects and Maintenance layers not offered; never anything the user could not open in that module |
All Calendar routes
| Rule | What the system does |
|---|---|
| App turned off closes the routes | 'The Calendar app is not installed for this company.' (403); booking link 'Booking page not found' (404); other modules' calendars (e.g. Maintenance) still work |
Public booking page
| Rule | What the system does |
|---|---|
| Unknown, unpublished or inactive link | 'Booking page not found' / 'This link is not valid, or it has been switched off.' (404) |
| Page reveals nothing else | Only the type, free slots and the company name; no staff names or busy reasons; no script; headers Content-Security-Policy default-src 'none', X-Robots-Tag noindex, Cache-Control no-store, Referrer-Policy no-referrer |
| Bot honeypot | 'This request was not accepted.'; no booking |
| Two customers take one slot at once | One booking; the other 'That time is no longer available. Choose another slot.' |
Customer manage page
| Rule | What the system does |
|---|---|
| Manage link is the only key | 'Appointment not found' (404) |
ICS feed
| Rule | What the system does |
|---|---|
| Revoked or departed user's feed closes | 'Not found' (404) |
All records
| Rule | What the system does |
|---|---|
| Edit conflict | Tab 2 refused: 'This record changed since you opened it. Reload it and try again.' |
Audit
| Rule | What the system does |
|---|---|
| Changes are audited | Audit entries calendar.event.created / updated / cancelled / answered, calendar.settings.saved, calendar.resource.saved, calendar.appointment_type.saved, calendar.appointment.booked / cancelled (by customer: actor system) |