Access and permissions

Which permission each Calendar screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (19)

Permissions by screen

ScreenMenuPermission needed
OverviewCalendar > Overviewcalendar.view (appointments card filled only with calendar.appointment)
CalendarCalendar > Calendarcalendar.view (reading); calendar.edit to create, change and remember the view
Event dialogCalendar > open an eventcalendar.view to read; calendar.edit to answer, change, cancel
Event formCalendar > New Event / Editcalendar.edit
Repeating event scopeEvent dialog > Edit or Cancel event (repeating)calendar.edit
Layer cardCalendar > click a layer itemcalendar.view plus the owning module's view right
AppointmentsCalendar > Appointmentscalendar.appointment
Appointment cardAppointments > open a rowcalendar.appointment
Book an appointmentAppointments > Book appointmentcalendar.appointment
Appointment typeAppointments > New type / Editcalendar.appointment
ResourcesCalendar > Resourcescalendar.view to see; calendar.manage to add or change
ResourceResources > New resource / open a rowcalendar.manage
RemindersCalendar > Reminderscalendar.view
Meeting load by personCalendar > Reporting > Meeting load by personcalendar.report
Room and equipment utilisationCalendar > Reporting > Room and equipment utilisationcalendar.report
Appointments by type and outcomeCalendar > Reporting > Appointments by type and outcomecalendar.report
Upcoming appointmentsCalendar > Reporting > Upcoming appointmentscalendar.report
Calendar settingsCalendar > Configuration > Settingscalendar.manage
Shared calendarsCalendar > Configuration > Shared calendarscalendar.view to list; calendar.manage to add or change
Appointment typesCalendar > Configuration > Appointment typescalendar.appointment
Subscribe in other appsCalendar > Configuration > Subscribe in other appscalendar.view to see; calendar.edit to make or stop
Public booking pagePublic link /api/v1/public/book/<token> (no sign-in)None (unguessable token); type must be published and active, app installed
Customer manage pageManage link /api/v1/public/appointments/<token> (no sign-in)None (unguessable token)
ICS feedFeed address /api/v1/public/calendar/feed/<token>.icsNone (unguessable, revocable token)

All Calendar screens

RuleWhat the system does
Read-only user cannot add eventsRefused (403) by the route policy (calendar.edit needed); nothing saved

Configuration > Settings

RuleWhat the system does
Settings need calendar.manageMenu hidden; API refused 'Changing calendar settings needs the calendar.manage permission.'

Shared calendars

RuleWhat the system does
Shared calendars need calendar.manageRefused 'Creating a shared calendar needs the calendar.manage permission.' / 'Changing a shared calendar needs the calendar.manage permission.'

Resources

RuleWhat the system does
Rooms need calendar.manageRefused 'Changing rooms and equipment needs the calendar.manage permission.'

Appointments

RuleWhat the system does
Appointments need calendar.appointmentMenu hidden; 'Seeing appointments needs the calendar.appointment permission.'; changing a type 'Changing appointment types needs the calendar.appointment permission.'

Reporting

RuleWhat the system does
Reports need calendar.reportMenu hidden; 'Calendar reports needs the calendar.report permission.'

Calendar

RuleWhat the system does
Another person's personal calendar is never listedA's calendar not listed; A's event not shown; GET -> 'Event not found.' (404); only free/busy reveals A is busy
Company isolation'Event not found.' / 'Calendar not found.' / 'Resource not found.' / 'Appointment not found.' (404); row-level security on every a2n_cal_* table

Calendar / Event dialog / ICS

RuleWhat the system does
Private event masked everywhereAlways 'Busy' with time only; search does not find it; no location, link, notes or attendees anywhere

Event dialog

RuleWhat the system does
Attendees only answerButtons hidden; API 'Only the organiser or the calendar's editors change this event.' / '... cancel this event.'

Event form

RuleWhat the system does
Viewer of a shared calendar cannot write in itRefused: 'You only read this calendar.'
Room booked twice at the same momentOne saved, one 409 naming the other's booking (row lock)

Event form / Shared calendars / Appointment types

RuleWhat the system does
Only own-company people'A colleague attendee must belong to this company.' / 'A member must belong to this company.' / 'Staff must belong to this company.'

Calendar > layers

RuleWhat the system does
Layers follow the owning module's rightsHR shows only holidays and own leave; no payroll dates; Projects and Maintenance layers not offered; never anything the user could not open in that module

All Calendar routes

RuleWhat the system does
App turned off closes the routes'The Calendar app is not installed for this company.' (403); booking link 'Booking page not found' (404); other modules' calendars (e.g. Maintenance) still work

Public booking page

RuleWhat the system does
Unknown, unpublished or inactive link'Booking page not found' / 'This link is not valid, or it has been switched off.' (404)
Page reveals nothing elseOnly the type, free slots and the company name; no staff names or busy reasons; no script; headers Content-Security-Policy default-src 'none', X-Robots-Tag noindex, Cache-Control no-store, Referrer-Policy no-referrer
Bot honeypot'This request was not accepted.'; no booking
Two customers take one slot at onceOne booking; the other 'That time is no longer available. Choose another slot.'

Customer manage page

RuleWhat the system does
Manage link is the only key'Appointment not found' (404)

ICS feed

RuleWhat the system does
Revoked or departed user's feed closes'Not found' (404)

All records

RuleWhat the system does
Edit conflictTab 2 refused: 'This record changed since you opened it. Reload it and try again.'

Audit

RuleWhat the system does
Changes are auditedAudit entries calendar.event.created / updated / cancelled / answered, calendar.settings.saved, calendar.resource.saved, calendar.appointment_type.saved, calendar.appointment.booked / cancelled (by customer: actor system)