Scope
Oto separates operator and branch operations while allowing the documented global member lookup. Visits, sales, payments, stock, events, bookings, check-ins, and device activity remain associated with the branch where they occurred.
Design
Users work within their permitted operator and branch scope. Screens show only the personal information needed for the current workflow. During public camp registration, saved family and child details remain hidden until the visitor enters the six-digit code sent to the supplied phone number. Consent and privacy actions appear where the source workflow requires them.
Failure handling
A user outside the permitted operator, branch, or record scope cannot view or change the protected information. An incorrect or expired camp verification code does not reveal or update saved family details.
Requirements
- Users see only operator and branch records within their permitted scope.
- Global member lookup and branch-owned operational records follow the documented POS rules.
- Sensitive personal information is limited to the users and workflows that require it.
- A public camp visitor must enter the six-digit code sent to the supplied phone number before Oto shows or changes a returning family’s saved details.
- Consent, correction, export, and deletion actions are available where a source workflow requires them.
Verification
- Test cross-operator and cross-branch access for applicable workflows.
- Test the visible personal information and privacy actions required by child, employee, member, guest, and supplier workflows.