Roles and participants
The account roles, external participants, and shared-device or public-entry contexts involved in Oto.
Platform Administrator
Platform administrator responsible for operators, branches, platform users, and platform settings.
What they do
- manage operators and branches
- manage platform users and settings
Access limits
- Can manage every operator on the platform.
Operator Administrator
Administrator responsible for one operator and its branches, configuration, administrators, integrations, and people administration.
What they do
- manage operator branches and administrators
- configure operator policies
- govern people administration
- manage integrations
Access limits
- Can manage only the assigned operator and its branches.
Branch Manager
Manager responsible for one or more assigned branches. Branch-level duties may include staffing, check-ins, events, issues, scheduling, timekeeping, and reporting.
What they do
- manage branch operations
- review team work and timekeeping
- manage check-ins and events
- resolve operational issues
Access limits
- Can manage only their assigned branches.
Line Manager
Manager responsible for assigned departments or teams within a branch. Their permissions depend on their scope and assigned management duties.
What they do
- coordinate an assigned department or team
- assign and review work
- manage permitted operational content
- handle team enquiries and exceptions
Access limits
- Can manage only their assigned branches, departments, and teams.
Staff Member
Staff account used to complete assigned work and employee self-service within the person’s branch and department scope.
What they do
- complete assigned work
- execute check-ins and events
- access knowledge and learning
- view own schedule and vouchers
Access limits
- Can work only in assigned branches and work areas.
Advisor
Non-employee professional with a separately governed login, department, and branch access lifecycle.
What they do
- access assigned operational modules
- work within assigned department and branch
- maintain advisor account security
Access limits
- Can work only in the branches and departments assigned to the advisor account.
Customers and external participants
People who use customer or public workflows. The same person may participate as a member, parent, guest, supplier contact, or signer.
Member / Customer
A globally recognized customer whose normalized phone recalls tier verification, saved children, preferred contact channel, wallet, bookings, and cross-branch activity.
What they do
- identify by normalized phone
- buy admission and products
- use wallet or promotions
- manage bookings and saved children
Access limits
- Can access only their own customer records and public customer workflows.
Parent / Guardian
Parent or guardian registering and checking in children, managing party invitations and menus, and providing guardian consents through scoped links.
What they do
- register a child for camp
- manage party invitations
- submit menu and RSVP information
- check a child in or out
Access limits
- Can access only their own registrations, linked children, invitations, and public forms.
Guest / Invitee
Public invitee who responds to one event invitation and submits only attendance and dietary information requested for that invitation.
What they do
- respond to an invitation
- provide party size and menu details
- check in when invited
Access limits
- Can access only the invitation opened through their guest link.
Supplier Contact
External supplier using a supplier access link to review permitted Fix reports for selected branches, comment, and mark work complete.
What they do
- review permitted Fix reports
- submit comments and completion updates
Access limits
- Can access only the branches and Fix reports available through the supplier link.
- Cannot access internal Oto functions outside the supplier workflow.
Pending Staff Member
A pending staff member who reviews and signs an assigned employment document before or during onboarding.
What they do
- review assigned document
- provide signature and consent
- receive signing confirmation
Access limits
- Can review and sign only the employment document assigned to them.
- Does not receive general staff access until a staff account and its roles are created.
Employee Kiosk Context
The context in which an employee uses a shared branch device for clocking or identity enrollment. This is not a separate account role.
What they do
- clock in and out
- submit missed or unscheduled event
- enroll approved identity evidence
Access limits
- The shared device exposes only employee kiosk actions for its activated branch.
Reception Visitor Context
The context in which a visitor uses a reception device or check-in link for one visit. This is not an account role.
What they do
- begin a permitted reception check-in
- submit minimal visit information
Access limits
- The visitor can submit only the check-in form opened for the current visit and branch.