Roles and permissions
Fieldbook has four account roles: Learner, Manager, Contributor, and Administrator. A role controls publishing and administration; explicit team responsibilities determine whose learning a Manager or Contributor can report on.
Four account roles
The permissions below apply to active, registered accounts. Adding someone to the roster before their first sign-in does not by itself activate their account access.
Every role can read published content, take Courses, save personal progress, and give feedback. Publishing and access to other people's progress differ:
| Role | Publish | Reports |
|---|---|---|
| Learner | No | No |
| Manager | No | Assigned teams |
| Contributor | Yes | If assigned as Manager |
| Administrator | Yes | All teams |
“Reports” means access to other people's learning progress. A Learner can still see their own course progress. Assigned reporting teams include the teams beneath them.
Everyone uses Updates, Courses, and Docs in the main navigation. Open Account menu for the additional work available to your role:
- Manager — My team’s progress: Review learning progress for explicitly assigned teams. The Manager role does not grant publishing, people management, or organization settings.
- Contributor — Manage content: Create, edit, publish, and unpublish Docs, Updates, and Courses; work with media; and review content and general feedback. Contributors can edit content created by other authors, including drafts. They can also delete content and restore recoverable deleted content.
- Administrator — Manage organization: Manage content alongside people and their roles, teams, learning groups, Course assignments, Docs navigation, organization settings, and organization-wide reporting. Reports are available here rather than through a separate My team’s progress entry.
A Contributor can place a doc in an existing section, but cannot administer the Docs navigation tree or its ordering. Course assignments, people management, and organization-wide settings remain Administrator responsibilities. Contributor access alone does not grant organization-wide reports.
Reporting needs an explicit team assignment
For a Manager or Contributor to see a team's reports, an Administrator must name them as that team's manager. The role label alone does not select a team: a Manager with no assigned teams has no reporting branch.
The assigned team and all its descendant teams are in scope. For example, managing Sales includes Sales teams beneath it, but does not include a separate Support branch. Membership in a reporting team or learning group does not itself make someone its manager.
A Contributor can also hold these team responsibilities. They then have both Manage content and My team’s progress, with the reports limited to their assigned branches. Their publishing access does not expand that reporting scope.
Content access, guests, and operators
- Published content is shared. Everyone allowed into an installation can read its published Updates, Docs, and Courses. Selecting teams or learning groups for relevance or assignments does not hide content from other admitted readers. An opinionated structure explains this design choice.
- A public guest has no account role. When public browsing is enabled, guests can read, take Courses, and give feedback. Their course progress stays in the browser until they sign in and save it to an account. Guests have no publishing, administration, team reports, or MCP tools.
- An infrastructure operator manages the services behind Fieldbook. Provider accounts, hosting, the database, and backups are separate from the four application roles. An Administrator role does not grant access to those external services. The same person can hold both responsibilities; The Fieldbook project explains what running an installation involves.
Connected AI clients follow role permissions
An optional Model Context Protocol (MCP) connection lets an AI client use Fieldbook tools. It requires an active, registered account and consent to the requested capabilities. That consent can narrow the available tools; it cannot give the client more authority than the account has.
- Learners currently have no MCP tools.
- Managers can approve reporting tools for their explicitly managed teams and descendants.
- Contributors can approve content, media, and feedback tools, plus scoped reporting when explicitly assigned to manage teams.
- Administrators can approve those tools plus Course assignment and organization-wide reporting capabilities.
MCP permissions are checked against the current role, team responsibilities, and the connection’s stored approvals. Capabilities not already approved require consent. If a connection was approved under a Manager or Contributor role, promotion to Administrator requires renewed consent before that connection can use Fieldbook tools.