Roles & Access Control
Overview — Two Layers of Access
Access in NSCAT is decided by two independent layers, and most confusion about "why can't this person see that" comes from mixing them up.
1. Account roles — the COG Admin and Utility Admin checkboxes on a person's account. These decide which administration menus appear in the sidebar. Set them in Registering & Managing Users.
2. Activity assignment — whether a person is a Team Lead or Team Member on a specific activity, and what they may do inside it. Set these per activity in Properties.
An account role never grants access to an activity's contents, and an activity assignment never grants an administration menu. Someone can be a Utility Admin with no activity assignments, or a Team Member with no admin role at all.
|
HEADS UP The single most common support question — "I made them an admin but they still see Access Restricted" — is this distinction. Admin roles are not activity access. Add them to the activity's team in Properties. |
Layer 1 — Account Roles
The two admin checkboxes are independent. Neither implies the other, and COG Admin is not a superset of Utility Admin.
|
Area |
COG Admin |
Utility Admin |
|
Register a User / Manage User |
Yes |
Yes |
|
Add Utility |
Yes |
— |
|
Manage Utility |
Yes |
Yes |
|
Add ISF / Manage ISF |
Yes |
— |
|
Manage Activities (lock / unlock) |
Yes |
— |
|
Activity Feed |
Yes |
Yes |
|
Question Composer |
— |
Yes |
|
Theme Management |
— |
Yes |
|
Training Management |
— |
Yes |
|
Cultural Pattern Rank Order Report |
— |
Yes |
|
Trending Report |
— |
Yes |
|
Report Builder |
— |
Yes |
|
Lessons Learned Review |
No |
Yes |
|
GOOD TO KNOW Lessons Learned Review is hidden from COG Admins by design — it is a utility-level review. A COG Admin who cannot find it in the sidebar is seeing correct behaviour. |
Utility Admin is the write-access shortcut
Inside any activity, a Utility Admin is treated as having write access to everything — surveys, interviews, focus groups, observations, recommendations, lessons learned. They do not need to appear on the activity's team list at all.
|
HEADS UP Because of this, ticking Utility Admin is a broad grant. It bypasses every per-activity permission checkbox described below. Reserve it for people who genuinely administer the utility, not as a convenient way to give someone access to one activity. |
A Utility Admin is still scoped to their own utility
Editing an activity's team — adding Team Leads or Team Members, changing their permissions — additionally requires that the admin's own utility matches the activity's utility. A Utility Admin from a different utility sees those controls greyed out even though the activity is visible.
|
GOOD TO KNOW Team editing needs all three of: the Utility Admin role, a matching utility, and the activity unlocked. If the fields are disabled and the activity is unlocked, check the utility match first. |
Layer 2 — Activity Assignment
Open the activity's Properties page from its menu on the dashboard. Two separate lists control who works on it.
The Properties page, showing Team Leads and Team Members.
Team Leads
Team Leads is a simple list of user emails — no permission checkboxes. Being on it grants write access to everything in that activity, the same effective reach as a Utility Admin but scoped to this one activity.
Add people from the picker; remove them with the × on their chip.
|
PRO TIP Team Lead is the right role for the person running the assessment. It saves ticking fourteen checkboxes, and it is scoped to a single activity — much narrower than granting Utility Admin. |
|
GOOD TO KNOW A person cannot be both a Team Lead and a Team Member on the same activity — once they are on one list, the other list's picker stops offering them. |
Team Members
Team Members are added one at a time, each with their own Read / Write permissions per area of the activity:
|
Area |
Read |
Write |
Controls |
|
Interviews |
Yes |
Yes |
Opening interviews and entering interview responses. |
|
Focus Groups |
Yes |
Yes |
Opening focus groups and entering focus group responses. |
|
Survey Response |
Yes |
Yes |
Viewing and editing survey responses and their comments. |
|
Observations |
Yes |
Yes |
Viewing and recording observations. |
|
Recommendations |
Yes |
Yes |
Viewing and writing recommendations. |
|
Lessons Learned |
Yes |
Yes |
Viewing and writing lessons learned. |
|
Reports |
Yes |
— |
Viewing the activity's reports. Read-only — there is no Write for reports. |
|
GOOD TO KNOW Reports has a Read checkbox only. Reports are generated from the activity's data, so there is nothing to write. |
Read and Write are linked
The two checkboxes in each row are not independent — NSCAT keeps them consistent for you:
· Tick Write and Read is ticked automatically. You cannot have write without read.
· Untick Read and Write is unticked automatically.
So each area has three reachable states: no access, read only, or read and write.
Effective access, in order
When NSCAT decides whether someone may edit something in an activity, it checks in this order and stops at the first match:
3. Is the user a Utility Admin? → write access.
4. Is the user's email in Team Leads? → write access.
5. Is the user in Team Members? → use that area's Write flag.
6. Otherwise → no access. The activity's menu shows Access Restricted.
|
HEADS UP A COG Admin does not appear anywhere in that list. Being a COG Admin grants no write access inside an activity — a COG Admin who needs to edit activity content must also be a Utility Admin, a Team Lead, or an assigned Team Member. |
How Locking Overrides Everything
A locked activity is read-only for everyone, regardless of role or assignment. Save and delete buttons throughout the activity are disabled, and the activity's menu on the dashboard hides Properties entirely.
Only a COG Admin can lock or unlock, from Manage Activities in the sidebar. See Manage Activities.
|
HEADS UP Because locking hides Properties, you cannot change an activity's team while it is locked. To adjust access on a locked activity: have a COG Admin unlock it, make the change, then lock it again. |
Granting Access — Which Role to Use
|
The person needs to… |
Give them |
|
Run one assessment end to end |
Team Lead on that activity |
|
Take interview notes on one activity, nothing else |
Team Member with Interviews Read + Write |
|
Read an activity's reports without touching data |
Team Member with Reports Read only |
|
Curate questions and themes for the utility |
Utility Admin account role |
|
Run trending and CPRO reports across activities |
Utility Admin account role |
|
Maintain the ISF and lock activities |
COG Admin account role |
|
Administer the whole system day to day |
Both account roles |
|
PRO TIP Work from the narrowest layer up. Try a per-area Team Member, then Team Lead, and only reach for Utility Admin when the person's job really is utility-wide — it silently overrides every activity-level permission. |
Common Problems
|
What you see |
What it means |
|
Access Restricted on an activity menu |
No assignment on that activity. Add them in Properties. |
|
New admin menu missing after a role change |
The sidebar is built from the session token. Sign out and back in. |
|
Write won't stay ticked |
Read is unticked for that area. Tick Read first, or tick Write and let it pull Read in. |
|
Team Lead / Team Member fields greyed out |
One of: not a Utility Admin, a different utility than the activity, or the activity is locked. |
|
Properties missing from the activity menu |
The activity is locked. A COG Admin must unlock it. |
|
COG Admin cannot edit activity content |
Expected. COG Admin grants no in-activity write access — add Utility Admin or an activity assignment. |
|
Person cannot be added as a Team Member |
They are already a Team Lead on that activity. Remove them from that list first. |

No comments to display
No comments to display