A spreadsheet can lock who edits it.
It can't lock who sees it.
Staff Directory is one record — name, title, department, photo — with every field gated by who's asking, decided on the server before it reaches the screen. Restricted fields aren't hidden in the interface; they never leave the server for a tier that shouldn't see them.
Built from the record everyone else already trusts.
The directory isn't a second staff list — it's a view onto the same staff identity the rest of the platform uses, with a search box and an access tier in front of it.
- 01One staff record
Name, title, department, and photo — the same staff identity the rest of the platform already uses, not a second roster to keep current.
- 02Search finds the person
Look up staff by name or department without knowing an extension or a building map first.
- 03Club advisor terms carry dates
An advisor's term is one record with a start date and an optional end date — not a new row every fall. A multi-year term stays one entry across rollover.
- 04The tier decides the view
The same directory renders differently depending on who's looking — some fields are there, some aren't, decided before the response leaves the server.
Same directory, tier-shaped.
A directory-only lookup shows the fields anyone in the building can share. A restricted field doesn't get blurred out — it never leaves the server for that tier.
A term that started before rollover is still one record after it.
Inside Staff Directory.
Every staff member — name, title, department, and photo — on the same staff identity the rest of the platform reads and writes.
Find the right person without already knowing where they sit.
An advisor's term is a start date and an optional end date on one record — not a new row entered every school year. A multi-year term survives rollover intact.
A directory-only tier sees name, title, department, email, and photo — and nothing else. A detailed tier sees more. An editor tier can update records. The tier is decided per person, not per screen.
Date of birth, personal phone, emergency contacts, and identifiers are withheld from the directory-only tier by the server before the response is built — not merely hidden in the interface.
Built to replace a spreadsheet with a script bolted on.
I ran this on real staff for a year — a Google Sheet with Apps Script bolted on for search. Sheets can lock who edits a file. They can't lock who sees a tab, so a restricted field was one click away from anyone with the link. It hit other ceilings too: no way to archive someone who left, no way to filter for who advises which club. Staff Directory replaced it: photos so the front office knows who they're looking at, access enforced on the server instead of asking people not to look.
One more view on the staff record.
Staff Directory sits alongside Teacher Coverage and Staff Attendance in Staff Operations, reading the same staff identity and the same Core.
Show us how your office looks someone up.
Bring the person who fields the phone calls. If Staff Directory doesn't answer their first question, we want to know why.
