Skip to main content

Custom Permissions

Limited releaseWeb dashboard

Limited release: if a process of your own needs a permission the standard set does not have, our team can add one for you. You then grant it to roles like any other.

On the dashboard

See it in action

In Roles Management's Permission Catalogue, an administrator searches for a permission added for their organisation, Sign Off Incident Debriefs, and sees its id, description and the roles already holding it, beside the built-in permissions.

What it does

  • Ask our team for a permission that fits a process specific to your organisation.
  • Each one has a name, a description and a category, like the built-in permissions.
  • Grant it to roles in the same place you manage every other permission.
Who it’s for
Administrators
Works on
Web dashboard
Status
Limited release
Included in
Every plan

Why it matters

Roles, Permissions & Access Review

Prove Who Can See What — and Why

Role-based access built from permissions written in plain English, and a live Access Review that answers the awkward question without a spreadsheet.

Access control is the part of a procurement conversation where most systems get vague. "Role-based permissions" is easy to claim and hard to evidence, and the moment somebody asks "so who exactly can open this client's record, and how did they get that?", the honest answer in a lot of organisations is that nobody knows without going and looking.

Read+Respond builds roles from a documented catalogue of over two hundred permissions, each with a name and a plain-English description of exactly what it grants, grouped by area. Simple mode collapses them into capability groups with read, write and full tiers so an administrator is choosing between meaningful levels rather than ticking individual strings; the advanced view is still there when you need it. Grants that reach the whole organisation say so, irreversible actions are flagged as such, and permissions that do nothing without a companion grant declare that dependency instead of failing silently. Role feature flags control which pages a role can open at all, separately from what it can do once inside. Every change to a role is audited.

Access itself arrives by three routes, and Read+Respond keeps them visible rather than collapsing them into one. Organisation-wide, through a role. Directly, because the client, facility or form names that role or that person. Or temporarily, because someone is on a shift — which is how relief cover works without an administrator granting and then remembering to revoke.

Access Review is where it comes together. Pick a user, a client, a facility or a form template and see everyone who can reach it, with the reason attached to each name. It is computed live from current roles, permissions and rosters, not read from a stored list that drifts, so it is right at the moment you look. Filter to the people who only have access because of a shift and you can see the temporary grants for what they are. And the same page has a second face for everyone else: without the review permission, staff see My Access — the clients, facilities and forms they can reach and why — so the question can be answered without an administrator in the loop.

Compliance Registers & Tracking

Stay Audit-Ready, Every Day

Comprehensive compliance registers that automatically track regulatory requirements and flag gaps before they become issues.

Maintaining compliance is not a one-time effort — it requires continuous monitoring, evidence collection, and proactive gap management. Manual tracking is slow, error-prone, and stressful when an audit arrives.

Read+Respond provides pre-built compliance register templates for common regulations, with automated monitoring that tracks your status in real time. Gaps are flagged before they become issues.

When auditors arrive, your evidence is already organised, timestamped, and export-ready — turning what used to be weeks of preparation into a confident, straightforward process.