# Roles and permissions

Student and staff pitches share one hub, but each pitch has an audience that controls who can see it. The leadership decision chooses an action; it is not a publication approval gate.

| Capability | Student | Staff | School leader | Trust leader |
|---|---:|---:|---:|---:|
| Create a pitch | Yes | Yes | Yes | Yes |
| Choose who can see a pitch (Staff only / Everyone) | No | Yes | Yes | Yes |
| See student pitches | Yes | Yes | Yes | Yes |
| See staff-only pitches | No | Yes | Yes | Yes |
| Upvote or add a critique | Visible pitches | Visible pitches | Visible pitches | Visible pitches |
| Step up into a Shape Up Crew | Visible pitches | Visible pitches | Visible pitches | Visible pitches |
| Decide a pitch (Quick Win / Shape Up / decline) | No | No | School only | Trust-wide |
| See engagement analytics | No | No | School only | Trust-wide |

## Audience is a real visibility gate

Staff and leaders choose an audience when they pitch:

- **Staff only** (the default): visible to staff and leaders. Students never see it, cannot upvote it, and get a not-found page if they follow a direct link. This lets staff raise sensitive things — a behaviour policy that is not working, a curriculum concern — without it landing in a student feed.
- **Everyone**: visible to students and staff, the same as a student pitch.

Students always pitch to **Everyone**; they cannot create a staff-only pitch. Leaders still see and decide staff-only pitches so the ritual is unchanged.

The Owner role can preview these roles for testing. The preview changes both visible navigation and server-side permissions.

Parent voice is deferred. No parent-authored pitches or parent demo account are included in the current phase.