Roles and Permissions in Depth
The four Spatiko team roles, what each can see and do by default, and how to fine-tune an individual member's access permission-by-permission.
Last updated
Every team member in Spatiko has a role, and every role comes with a default set of permissions. If the defaults don’t fit a specific person, you can adjust their permissions individually without changing their role.
The four roles
Spatiko has four fixed roles: Owner, Admin, Photographer, and Assistant. You can’t create custom roles — instead, you customize permissions for individual members within these four. For an overview of what each role is meant for, see team and roles.
What each role gets by default
Assistant is view-only: viewing orders, clients, catalog, and delivery galleries.
Photographer includes everything Assistant has, plus the ability to create orders and clients, manage delivery galleries, and work their own shoots — toggling item and deliverable completion, moving a shoot’s scheduled time, and moving an order through its workflow stages (cancellation isn’t included). Photographers can also upload and organize photos, floor plans, videos, and content links on their own orders, and see analytics for their own shoots, earnings, and workload — never business-wide numbers or other members’ figures.
Admin includes everything Photographer has, plus full administrative reach: seeing and fully managing every order in the business (pricing, items, schedule, status, contacts, discounts, travel fees, and cancellation), archiving orders, managing the team and catalog, business-wide analytics, seeing the full calendar, managing business settings, billing, integrations, and payments, and handling invoices. Removing a team member is the one exception — that stays owner-only, even for Admins.
Owner has every permission, unconditionally, and always will — even if something went wrong with a stored permission list, the Owner still passes every permission check. The Owner’s role and permissions can’t be edited, reduced, or transferred through the app.
Customizing an individual member’s permissions
If you have team management access, open a member’s Permissions tab to toggle any permission on or off for them specifically — overriding their role’s defaults. Each toggle shows whether it’s part of the role’s default set or a custom change you’ve made, and you can reset a member back to their role’s defaults with one click.
A few rules to keep in mind:
- Changing a member’s role resets all of their custom permission toggles back to the new role’s defaults — it doesn’t carry over your previous customizations.
- Nobody can edit their own role or permissions, even if they hold team management access. This prevents a member from locking everyone else out.
- The Owner’s row is locked — there’s nothing to customize.
For the day-to-day mechanics of inviting people and changing roles, see inviting and managing team members.
The reschedule permission
Moving a shoot’s scheduled time is split out as its own permission, separate from full order management. It authorizes changing only the shoot’s start and end time — nothing else. If an update also changes the assigned photographer, items, notes, label, or completion state, the broader order-management permission is required instead.
This is why Photographers get the reschedule permission by default: it lets a photographer drag their own shoot to a new time on the calendar without also giving them the ability to reassign themselves off it or change pricing and items. See assigning shoots to your team for how scheduling and assignment fit together.
Viewing your own work vs. everyone’s
Several permissions come in a narrow and a wide version. Basic order viewing only shows orders a member is assigned to as photographer; seeing every order in the business requires the wider permission. The same pattern applies to media management — it’s scoped to a member’s own assigned orders unless they also have the wider viewing permission — and to analytics, where the basic version shows a member their own shoots, earnings, and workload, while the business-wide version shows total revenue and every member’s numbers.
Changing a member’s role and customizing individual permissions are team-management features available on higher paid plans — see pricing. On plans without team management, roles and their permissions stay at their defaults.
Permission checks happen on the server for every action, not just in the interface — hiding a button is a convenience, not the security boundary.