Roles and permissions
Student and staff pitches share one hub, but each pitch has an audience that controls who can see it. The leadership decision chooses an action; it is not a publication approval gate.
| Capability | Student | Staff | School leader | Trust leader |
|---|---|---|---|---|
| Create a pitch | Yes | Yes | Yes | Yes |
| Choose who can see a pitch (Staff only / Everyone) | No | Yes | Yes | Yes |
| See student pitches | Yes | Yes | Yes | Yes |
| See staff-only pitches | No | Yes | Yes | Yes |
| Upvote or add a critique | Visible pitches | Visible pitches | Visible pitches | Visible pitches |
| Step up into a Shape Up Crew | Visible pitches | Visible pitches | Visible pitches | Visible pitches |
| Decide a pitch (Quick Win / Shape Up / decline) | No | No | School only | Trust-wide |
| See engagement analytics | No | No | School only | Trust-wide |
Audience is a real visibility gate
Staff and leaders choose an audience when they pitch:
- Staff only (the default): visible to staff and leaders. Students never see it, cannot upvote it, and get a not-found page if they follow a direct link. This lets staff raise sensitive things โ a behaviour policy that is not working, a curriculum concern โ without it landing in a student feed.
- Everyone: visible to students and staff, the same as a student pitch.
Students always pitch to Everyone; they cannot create a staff-only pitch. Leaders still see and decide staff-only pitches so the ritual is unchanged.
The Owner role can preview these roles for testing. The preview changes both visible navigation and server-side permissions.
Parent voice is deferred. No parent-authored pitches or parent demo account are included in the current phase.