Skip to content
Resources

Roles and permissions

Ashby controls access by role, location, and — for families — which children they are linked to. Here is every role and what they can see.

All resources

How access works

Signing in only proves who you are. What you can do comes from your membership in the organization — checked on every request, not stored forever in a login token. If someone is removed or a guardian’s access to a child is revoked, the next request respects that change.

Your center’s data is isolated from every other center. Within your organization, permissions go further: some staff only see certain locations or classrooms, and some roles only see certain fields on a child’s record (for example, allergies but not home address).

Organization roles

These apply across the whole business (all locations).

  • Owner — the legal signatory. Can do everything an org admin can, plus accept legal agreements, own the Ashby billing relationship, and offboard or delete the organization.
  • Org admin — day-to-day HQ operations for multi-location operators. Nearly full access, but not owner-only legal and billing-ownership actions. Single-site centers often never need this role.

Location roles

These staff are assigned to one or more locations. Educators are further limited to the rooms they work in.

  • Director — runs the site: staff, enrollment, incidents, licensing, and full child records for that location.
  • Assistant director — same operational reach as a director, without hiring and compensation details.
  • Educator — classroom staff. Sees children in assigned rooms, including medical detail needed for care. Does not see children outside those rooms.
  • Front desk — check-in and checkout, tours, phones. Enough identity to move children through the day — not medical or incident detail.
  • Food service — allergies and dietary restrictions so meals are safe. Does not see addresses or incident reports.
  • Transport — roster and emergency contacts for their route. Not a general medical view.

Family role

  • Guardian — a parent or caregiver with a login. Access is per child: someone may have full rights for one child and restricted rights for a sibling. That link lives on the child’s guardian relationship, not on a blanket “parent” switch.

Authorized pickups and emergency contacts are contact records. They do not need an Ashby login and are not roles.

What is not a separate role

Lead teacher vs aide is a property of the room assignment (a room has a lead). Substitute or floater vs permanent staff is an employment type on the staff profile. Modeling those as extra roles would complicate permissions without changing what people can actually do.

In-home providers

If you are a one-person in-home daycare, you are typically the owner — and that is enough. Ashby does not force an org chart. Roles collapse to one person without ceremony.

Field-level privacy

Two people can open the same child and see different fields. Food service needs allergies (sensitive data) but must not see home address. Front desk needs enough to check a child in, not medical notes. When a field is missing on screen, treat it as “not authorized,” not “empty.”

Ashby staff (platform)

Ashby employees use a separate admin console. They are not a role inside your center. Default views are operational aggregates only. Any access to child-sensitive data requires an explicit break-glass step with a recorded reason and an audit entry.

Start now — be live in 5 minutes

Ashby is built for small US centers and in-home daycares. Open an account, set up your rooms, and run the day — without a long onboarding project.