Roles and participants

The account roles, external participants, and shared-device or public-entry contexts involved in Oto.

Account roles

The account hierarchy. Permissions and scope determine which duties each person can perform.

Platform Administrator

Platform administrator responsible for operators, branches, platform users, and platform settings.

What they do

  • manage operators and branches
  • manage platform users and settings

Access limits

  • Can manage every operator on the platform.

Operator Administrator

Administrator responsible for one operator and its branches, configuration, administrators, integrations, and people administration.

What they do

  • manage operator branches and administrators
  • configure operator policies
  • govern people administration
  • manage integrations

Access limits

  • Can manage only the assigned operator and its branches.

Branch Manager

Manager responsible for one or more assigned branches. Branch-level duties may include staffing, check-ins, events, issues, scheduling, timekeeping, and reporting.

What they do

  • manage branch operations
  • review team work and timekeeping
  • manage check-ins and events
  • resolve operational issues

Access limits

  • Can manage only their assigned branches.

Line Manager

Manager responsible for assigned departments or teams within a branch. Their permissions depend on their scope and assigned management duties.

What they do

  • coordinate an assigned department or team
  • assign and review work
  • manage permitted operational content
  • handle team enquiries and exceptions

Access limits

  • Can manage only their assigned branches, departments, and teams.

Staff Member

Staff account used to complete assigned work and employee self-service within the person’s branch and department scope.

What they do

  • complete assigned work
  • execute check-ins and events
  • access knowledge and learning
  • view own schedule and vouchers

Access limits

  • Can work only in assigned branches and work areas.

Advisor

Non-employee professional with a separately governed login, department, and branch access lifecycle.

What they do

  • access assigned operational modules
  • work within assigned department and branch
  • maintain advisor account security

Access limits

  • Can work only in the branches and departments assigned to the advisor account.

Customers and external participants

People who use customer or public workflows. The same person may participate as a member, parent, guest, supplier contact, or signer.

Member / Customer

A globally recognized customer whose normalized phone recalls tier verification, saved children, preferred contact channel, wallet, bookings, and cross-branch activity.

What they do

  • identify by normalized phone
  • buy admission and products
  • use wallet or promotions
  • manage bookings and saved children

Access limits

  • Can access only their own customer records and public customer workflows.

Parent / Guardian

Parent or guardian registering and checking in children, managing party invitations and menus, and providing guardian consents through scoped links.

What they do

  • register a child for camp
  • manage party invitations
  • submit menu and RSVP information
  • check a child in or out

Access limits

  • Can access only their own registrations, linked children, invitations, and public forms.

Guest / Invitee

Public invitee who responds to one event invitation and submits only attendance and dietary information requested for that invitation.

What they do

  • respond to an invitation
  • provide party size and menu details
  • check in when invited

Access limits

  • Can access only the invitation opened through their guest link.

Supplier Contact

External supplier using a supplier access link to review permitted Fix reports for selected branches, comment, and mark work complete.

What they do

  • review permitted Fix reports
  • submit comments and completion updates

Access limits

  • Can access only the branches and Fix reports available through the supplier link.
  • Cannot access internal Oto functions outside the supplier workflow.

Pending Staff Member

A pending staff member who reviews and signs an assigned employment document before or during onboarding.

What they do

  • review assigned document
  • provide signature and consent
  • receive signing confirmation

Access limits

  • Can review and sign only the employment document assigned to them.
  • Does not receive general staff access until a staff account and its roles are created.

Interaction contexts

Shared-device and public-entry contexts rather than separate kinds of person.

Employee Kiosk Context

The context in which an employee uses a shared branch device for clocking or identity enrollment. This is not a separate account role.

What they do

  • clock in and out
  • submit missed or unscheduled event
  • enroll approved identity evidence

Access limits

  • The shared device exposes only employee kiosk actions for its activated branch.

Reception Visitor Context

The context in which a visitor uses a reception device or check-in link for one visit. This is not an account role.

What they do

  • begin a permitted reception check-in
  • submit minimal visit information

Access limits

  • The visitor can submit only the check-in form opened for the current visit and branch.