PRESENTATION OVERVIEW
This document provides comprehensive system design, roles, protocols, and key features that make The Shepherd Network (TSN) ShepherdSync Scheduling System effective for volunteer scheduling.
SECTION 1: THE PROBLEM WE'RE SOLVING
Current Challenges
Before building this scheduling system, our process looked like this:
1. Manual Coordination: The Team Leader (TL) manually collected the availability from volunteers via email, phone calls, or sign-in sheets.
2. Document Management: Volunteer data entered onto paper, prone to errors and frustration.
3. Fairness Questions: No clear system for ensuring fair distribution of workload.
4. Communication Gaps: Volunteers had to text TL who then had to figure out who would work on a specific Sunday. TL would either self-assign or need to assist with finding a replacement. Usually because volunteer workers had to work or was too sick to make the effort.
5. Change Management: When someone can't make a shift, the entire schedule potentially needs reworking.
6. No Accountability: No clear audit trail of who made what decisions and why.
The Result: TL spent at least 80% of their time per quarter on scheduling, leading to exhaustion and sometimes frustration.
The Opportunity
We needed a system that would:
- Reduce administrative burden by 80%
- Ensure fair and transparent scheduling
- Provide real-time visibility to leadership
- Create complete accountability
- Make it easy for volunteers to submit availability and manage changes
- Support emergency situations when gap(s) occur
SECTION 2: SYSTEM OVERVIEW & DESIGN PRINCIPLES
Four Core Pillars
The Shepherd Network LLC, Automated Operations System (Scheduler) is built on four core principles:
Pillar 1: Automation
The system automatically generates fair schedules based on volunteer availability. Instead of manual coordination, the system processes availability data and creates schedules following established fairness rules. This reduces TL scheduling time per quarter. No manual approval steps are required as long as availability exists – the system is the sole decision-maker.
Pillar 2: Fairness
The fairness algorithm ensures balanced workload distribution. Volunteers who served recently get lower priority next time; volunteers who haven't served recently get higher priority. This creates a transparent, equitable system that volunteers understand and trust.
Additionally, TAG1 workers (full day services) get priority over TAG1A/TAG1B, and GAP1 workers get priority over GAP1A/GAP1B. This ensures our most committed volunteers are scheduled first. NOTE: For now, leadership has decided to only use TAG1/TAG2 and once we get Gap Workers (GW) then GAP1/GAP2.
Pillar 3: Transparency
Everyone sees the complete picture. Volunteers know their assignments weeks in advance. Leadership (TL, ATL/AcTL) and ADM have real-time visibility into gaps and pending changes. All access is logged with timestamps, creating an audit trail that shows exactly what happened and when.
Pillars 4: Accountability
Every action is logged with full details: who made the decision, what was decided, when the decision was decided, and why. This audit Trail file enables leadership to verify fairness, resolve disputes, and ensure protocols are followed.
System of Record
The web-portal CALENDAR/SCHEDULE is the OFFICIAL system of record. The system automatically generates the complete schedule following all protocols and fairness algorithm. After all required protocols are followed, the schedule is automatically locked and cannot be modified except through:
- Change Requests (CR) – Auto-approved when submitted. Creates a gap.
- Emergency Fill Protocol (EFP) – Activated when gaps occur after all phases are exhausted.
- Manual Override – The Team Leader (TL), or when needed the ADM (Administrator), can override a schedule after the EFP is exhausted, with documented reason.
All modifications are logged in the audit trail file with the documented reason and timestamp(s). This ensures the schedule is always accurate and traceable.
SECTION 3: ROLE STRUCTURE & RESPONSIBILITIES
The Six Roles
The system defines six clear roles, each with specific responsibilities and authority levels:
Team Leader (TL)
The TL is the primary program decision-maker for all scheduling matters. The TL:
- Oversees all scheduling phases and ensures protocols are followed
- Monitors system-generated schedules for gaps and issues
- Initiates Emergency Fill Protocol (EFP) Exhaustion when needed
- Makes manual overrides after all other automated options are exhausted (with documented reason)
- Manages gaps as a result of Change Requests and ensures fair handling
- Monitors volunteer engagement through training access analytics
- Communicates with volunteers about schedule changes
- Maintains accountability and fairness in all decisions
- Cannot assume the role of ADM
The TL accesses the system with their personal email + a secret 4-digit PIN, creating an audit trail file. The TL can view the complete audit trail and see who accessed training materials, when, and how long they spent – helping identify engaged, and responsible volunteers or irresponsible volunteers.
Assistant Team Leader (ATL) / Acting Team Leader (AcTL)
The ATL supports the TL in all scheduling functions. There can be up to four (4) ATLs, as the situation necessitates. The ATL:
- Helps monitor schedule gaps and coverage
- Participates in availability submission (goes through rotation process with TL)
- Supports TL in volunteer communication
- May serve as ADM if vacancy at organization occurs.
The AcTL:
- Follows all established protocols exactly
- Can initiate Emergency Fill Protocol Exhaustion, when needed
- Can make manual overrides after EFP is exhausted
- Can manage Change Requests following protocols
- Cannot operate outside of, and make independent decisions outside of protocols
- Authority ends when TL returns
- Cannot assume the ADM role.
The AcTL Is not a primary decision-maker – they are a protocol-follower who ensures the system continues to function when TL is unavailable.
The ATL, acting as the TL, has read-only access to the audit trail file and training analytics when the TL is unavailable. The AcTL is usually one (1) of the ATL.
Regular Volunteer Worker (RW)
RW are our regular volunteers, the primary support system, who submit availability and work regular scheduled assignments. RW:
- Submit availability during quarterly window
- Accept scheduled assignments
- Work assigned dates/times
- Submit Change Requests (CR) when unforeseen scheduling conflicts arise
- Update/maintain their profile information
- Review all training materials and updates submitted by leadership
- May assume the role of ADM if vacancy occurs
RW access the system with their personal email + a 4-digit PIN that they self-assign at registration. RW's can review the OFFICIAL web-portal calendar/schedule.
Gap Worker (GW)
GW are our backup volunteers, our secondary support system, who fill-in-the gaps when regular workers cannot. GW may not assume the role of TL, ATL, AcTL or ADM. GW:
- Submits availability with a GAP code (GAP1, GAP2), other GAP codes that are not currently available for use are GAP1A and GAP1B
- Accept gap assignments when offered
- Work assigned dates and times
- Submit Change Requests (CR) when conflict in the volunteer GW scheduling arise
- Update/maintain their profile information
- Are capped at three (3) services per quarter (prevents overload), with the exception of the EFP activations/process
GWs access the system the same as RWs with a personal email + a 4-digit PIN, they can view the official web portal calendar/schedule.
Administrator (ADM)
The ADM is primarily the system guardian and a security/technical resource. The ADM:
- Maintains the system configuration and technical infrastructure
- Provides technical support to TL, ATL, AcTL, RW, and GW
- Manages system roles and permissions
- Completes, reviews and implements training/protocol updates including those submitted by TL
- Monitors system health and performance
- Serves as last resort for gap filling (only when the TL/ATL are both unavailable and gap(s) remain. ADM may self-assign or activate the Break the Glass Protocol, which assigns workers to fill-in-the-gap(s).
- Makes decisions per established protocols as needed
The ADM accesses the system with personal email + a 4-digit PIN. The ADM can access all system functions and view the complete audit trail file.
IMPORTANT: The ADM is not primarily a program decision-maker unless performing dual roles as an ATL or AcTL. The ADM is a technical resource. When TL/AcTL are available, the TL/AcTL makes decisions. The ADM steps in only when needed for program related (e.g., EFP, Break the Glass Protocol) or for all technical/system related issues.
Role Separation Rules — 10 Non-Negotiable Rules
To ensure the system works effectively, we have established 10 non-negotiable rules:
- RW and GW are mutually exclusive: A volunteer cannot be both a RW and a GW.
- Leadership cannot be Gap Workers (GW): TL, ATL/AcTL cannot serve as GW. Additionally, TL and AcTL cannot be an ADM and ADM cannot be TL/AcTL.
- TAG1 gets priority: TAG1 availability scheduling for RW (Phase 1) are scheduled before TAG1A / TAG1B (the fairness algorithm applies within each tier).
- GAP1 gets the same priority as TAG1: GAP1 workers are scheduled before GAP1A / GAP1B (the fairness algorithm applies within each tier).
- All Change Requests (CR) are auto-approved: No denials. Gaps are created. Volunteers can always submit a scheduling change due to unforeseen circumstances using the CR protocol.
- GW capped at 3 services per quarter: GW are just that, workers that fill-in-the-gap(s). 3 services per quarter prevents overload for the GW and ensures fair distribution (with the exception of EFP activations).
- TL and ATL scheduled on different dates: Ensures leadership coverage across multiple Sundays. When both TL and ATL/AcTL are not available, the ADM steps into a leadership role.
- AcTL auto-activates when the TL is unavailable: The system automatically designates AcTL to maintain continuity. The AcTL is usually an ATL. Again, there can be more than one (1) ATL if determined necessary by leadership.
- Web portal calendar is the OFFICIAL system of record: Official schedule is locked and traceable. Follows established protocols.
- TL can manually override after EFP exhausted: Final authority to fill gaps when all other options fail. The ADM steps in only when the TL and AcTL are both unavailable.
As stated earlier, these rules are non-negotiable and built into the system to ensure fairness, accountability, and continuity.
SECTION 4: THE SEVEN-PHASE SCHEDULING PIPELINE
How the schedule is built end to end – and how every phase shows its live status on the ADM and TL/ATL dashboard.
Overview
The system follows a seven-phase pipeline to generate fair, complete schedules. Each phase has specific rules and protocols. Let's walk through each phase:
Phase 1: Availability Window of Submission
What happens: RW (phase 1) and GW (phase 3) submit their availability for the quarter. The TL and ATL also submit availability because they follow the phase 1 availability scheduling. The TL/ATL also may go through a rotation process later to fill-the-gap(s), if needed.
Timeline: Upon receipt of the automated SMS (text message) availability scheduling link workers have a 40-hours window to complete their availability per quarter.
Phase one workers, for each role (RW, TL, ATL), have from 5:00 AM ET on day one to 9:00 PM ET on day two to enter their availability into the scheduler system. Any dates not completed by the workers within their respective group (role) availability submission dates will be considered as gaps in the schedule.
There's a total of 4-days for all groups – phase 1 (RW) and phase 3 (GW) to submit their availability for the quarter. As an example: The schedule locks for RW group at 9 PM on day 2 and the schedule opens for GW group on day 3 at 5AM and closes at 9 PM on day 4, if there are GWs available.
If there's no volunteer workers assigned to GW group then the GW scheduling window is skipped and moves onto TL and ATL automated rotational scheduling (the fairness algorithm is off during the rotational scheduling).
Fairness algorithm: The system tracks when each volunteer last served. If worker1 served 14 days ago and Worker2 served 28 days ago, Worker2 gets priority scheduling because Worker2 has not served recently. Workers are scheduled fairly and transparently without any manual (Worker) intervention.
System tracking: Every submission is logged with a timestamp. TL is notified when availability is submitted.
KEY point: Volunteers may submit or change their availability any time before their scheduled deadline.
Volunteers access the scheduler system using the SMS link provided, or by entering this URL: scheduler.theshepherdnetwork.org. The Scheduler System can also be saved to volunteer's cell phone home screen as a TSN Icon. This is considered a Progressive Web-App. Follow these steps:
All Users:
Those having an iPhone, while still inside the TSN Scheduler web-app, go to the SAFARI app if necessary, select VIEW MORE, then scroll until you see ADD TO HOME SCREEN.
Those having an Android, while still inside the TSN Scheduler web-app, go to Chrome, scroll until you see ADD TO HOME SCREEN.
NOTE: The web-app is installed with The Shepherd Network (TSN) logo.
Phase 2: Reminder & Deadline
Purpose: Phase 2 ensures every worker receives a clear reminder before the availability submission window closes and confirms that the system deadline is applied consistently for every role.
Worker actions required:
RW, TL, and ATL workers
- Review the SMS reminder when received.
- Open the scheduler using the link provided in the SMS, accessing the TSN Icon, or by entering the scheduler web address directly.
- Confirm that all available dates and unavailable dates have been submitted.
- Make any final updates before the submission window closes.
- Understand that any date not submitted before the deadline will be treated as unavailable and will create a scheduling gap.
GW workers
At this time, there are no active GW workers assigned; however, the GW process remains part of phase 3 within the system for future use. When GW workers are active, they follow the same submission processes, and is part of the reminder process, as RW workers unless a GW-specific instruction is stated. GW are backup workers intended to fill gaps. If a GW wants to work more regularly, that individual should be moved from GW to RW.
TL and ATL
- Monitor the submission dashboard to verify which workers have completed availability.
- Encourage workers to submit before the deadline, if appropriate.
- Do not manually adjust worker availability unless the established protocol allows it and the action is documented.
- Review the pending submission list before the window closes.
ADM
- Confirm that the automated reminder process is functioning.
- Assist users who cannot access the scheduler.
- Resolve technical issues that prevent availability submission.
- Avoid making program decisions unless acting under an approved leadership role, established emergency protocol, or Break the Glass Protocols, or ADM emergency authority.
Automated system actions:
- The system sends automated SMS reminders to workers who have not completed availability.
- The system tracks whether each worker opened the scheduler link.
- The system records each submission, update, and timestamp in the audit trail.
- The system locks the availability window at the established deadline.
- The system treats any date not submitted before the deadline as unavailable, which creates a scheduling gap.
- The system prevents late entries after the window closes unless an authorized role uses an approved extended deadline protocol.
- The system updates the ADM dashboard and leadership visibility screens in real time.
Key rule: The scheduler exists to reduce unnecessary manual work and allow the system to complete as many steps as possible automatically. When a person must take action, the system is designed to guide that person clearly, reduce guesswork, and keep the process consistent, fair, and traceable.
Phase 3: Regular Worker Schedule Generation
Purpose: Phase 3 generates the primary schedule using RW availability and the fairness algorithm.
Worker actions required:
RW volunteers
- No manual action is required after availability is submitted.
- Review the schedule when it becomes available.
- Prepare to serve on assigned dates.
- Submit a Change Request if an unforeseen conflict arises after the schedule is generated.
TL
- Review the system-generated schedule for visibility and accountability.
- Confirm that the schedule follows the expected staffing pattern.
- Monitor any unfilled services or flagged gaps.
- Avoid manually changing assignments unless the approved manual override protocol applies.
ATL/AcTL — Assist the TL in reviewing the schedule. Monitor coverage needs when the TL is unavailable. Assist with monitoring system actions within approved authority.
ADM
- Confirm that the automated generation process completes successfully.
- Review technical errors, if any.
- Support leadership with system access or reporting questions.
Automated system actions:
- The system reviews all worker availability submitted during the approved window.
- The system applies role separation rules.
- Leadership has decided that, for now, only TAG1 and TAG2 will be used.
- The system applies the fairness algorithm within each eligible tag group.
- The system considers last-service dates so workers who have not served recently receive higher priority.
- The system assigns volunteers to available service dates.
- The system identifies any service dates that remain uncovered.
- The system creates a schedule record for every assignment.
- The system logs every assignment decision with the reason, date, time, and applicable fairness data.
- The system updates the web portal calendar as the official system of record.
Key rule: The system is the primary scheduler. Manual intervention occurs only through approved exceptions such as Emergency Fill Exhaustion Protocol, Manual Override, Break the Glass, or other ADM emergency authority.
Gap Worker Schedule Generation
Purpose: GW Workers enter their availability immediately upon the close of the RW (TL/ATL) scheduling deadline. Phase 3 uses GW availability to fill remaining gaps after the RW schedule generation process is completed. At this time, there are no active GW workers; however, this section remains in the manual, so the process is ready if GW workers are added later.
GW volunteers: Submit availability during the GW availability window when the GW role is active. Follow the same basic submission steps as RW volunteers unless the system gives a GW-specific instruction. Review any assigned gap service dates. Serve as scheduled unless a conflict arises. Submit a Change Request if an unforeseen conflict occurs. Understand that GW are backup workers. If a GW wants more regular dates to work, the person should be changed from GW to RW.
TL: Review open gaps after RW scheduling. Monitor GW assignments produced by the system if GW workers are active. Ensure no GW is overloaded beyond the quarterly cap except during approved EFP activation.
ATL/AcTL: Support the TL in monitoring gap coverage. Assist with monitoring system actions within approved authority.
ADM: Confirm system rules are functioning correctly. Provide technical support if GW assignment logic fails or a dashboard issue appears.
Automated system actions:
- The system determines whether GW volunteers exist for the quarter.
- If no GW volunteers are assigned to the GW group, the system skips the GW scheduling window.
- If GW volunteers exist, the system opens the GW submission window according to the approved timeline.
- The system applies active GW priority rules as configured.
- The system applies fairness rules within each eligible GW group.
- The system checks each GW's quarterly service count.
- The system prevents GW volunteers from exceeding three services per quarter except during EFP activation.
- The system fills remaining gaps when eligible GW availability exists.
- The system logs every assignment and the reason for the assignment.
- The system updates the official web portal calendar.
Key rule: GW volunteers are backup workers. Their purpose is to fill schedule gaps without being overloaded or replacing the normal RW scheduling process. If a GW wants more regular service dates, the individual should be moved into the RW role.
Phase 4: TL and ATL Rotational Scheduling and Automated EFP
Purpose: Phase 4 schedules TL and ATL coverage while keeping leadership coverage distributed across different dates whenever possible. Phase 4 activates immediately at the end of GW phase, when there are active GWs. Be aware that Phase 5 begins the automated Emergency Fill Protocol when gaps remain.
Worker actions required:
TL
- Submit availability during the required window.
- Review leadership assignments after system processing.
- Ensure leadership coverage exists for the quarter.
- Take action only when gaps remain after the automated process.
- When neither the TL nor ATL is scheduled because no gap needs coverage, both should remain available by phone or text messaging for programmatic issues that may require a leadership decision or action.
- Not permitted to perform the role of ADM.
ATL
- Submit availability during the required window.
- Serve according to assigned leadership dates.
- Support the TL when available.
- When neither the TL nor ATL is scheduled because no gap needs coverage, both should remain available by phone or text messaging for programmatic issues that may require a leadership decision or action.
AcTL — Automatically becomes active when the TL is unavailable. Follow established protocols exactly. Assist with monitoring system actions within approved authority. Not permitted to perform the role of ADM.
ADM — Monitor leadership-role access and system activation logic. Assist with technical issues involving leadership permissions. When part of the volunteer workers, follows the phase one (1) availability scheduling procedures. Not permitted to be TL or AcTL.
Automated system actions:
- The system reviews TL and ATL availability.
- The system turns off the fairness algorithm for rotational leadership scheduling if required by protocol.
- The system attempts to schedule TL and ATL on different dates.
- The system identifies dates when TL is unavailable.
- The system automatically activates AcTL coverage when required.
- The system logs the reason for AcTL activation.
- The system updates the official calendar and dashboard.
- The system flags any date where no leadership coverage exists.
- If gaps remain after standard scheduling, the system automatically activates EFP.
- EFP sends SMS messages to all active workers and members.
- The first eligible responder or responders fill the gap or gaps.
- The system records the response, assignment, and outcome in the audit trail.
Key rule: TL and ATL should not be scheduled on the same date when avoidable. The purpose is to distribute leadership presence across the quarter. The automated EFP process is designed to resolve remaining gaps quickly without requiring unnecessary manual coordination.
Phase 6: EFP Review and Schedule TL/ATL (AcTL) Re-Run
Purpose: Phase 6 requires the system to re-run scheduling availability for the TL and ATL should either have reviewed and changed their availability during the initial EFP (before EFP Exhaustion). This gives the system another opportunity to fill remaining gaps before manual action is considered.
Worker actions required:
TL
- When notified of the EFP SMS, review remaining gaps and determine if your availability can change before the due date for EFP responses.
- Review worker availability shown by the system and determined if you (TL) can revise your availability in the system for available gap dates.
- Allow the system to re-run your scheduling before taking automatic action.
- Avoid informal leadership decisions and side agreements that are not entered into the system to be included as updates to protocol.
ATL/AcTL — Follow the same steps as TL, that are outlined in Phase 6, item 1 above. Support the TL in monitoring the EFP results following the EFP Exhaustion phase. Follow TL required actions when working as AcTL.
ADM — Confirm that the scheduling re-run is functioning as expected. Provide technical support if the system cannot process the EFP review or re-run.
Automated system actions:
- The system reviews EFP responses.
- The system compares remaining gaps against available workers.
- During the EFP process: The system re-runs TL/ATL scheduling logic using available data.
- The system records the re-run results in the audit trail.
- The system assigns eligible workers where possible.
- The system updates dashboards and the web portal calendar.
- The system identifies any gaps that remain after the re-run.
Key rule: The system must be given every reasonable opportunity to fill gaps before manual assignment is used.
Phase 7: EFP Exhaustion, Schedule Lock, and Publication
Purpose: Phase 7 confirms whether EFP has exhausted after every reasonable attempt to fill remaining gaps before the 72-hour schedule lockdown occurs. If gaps remain, leadership is notified. The Break the Glass protocol kicks in when 24 hours or less remain and there are still gaps to be filled. No manual updates or change requests can occur during the system lock-down.
Worker actions required as the result of the Official Quarter Scheduling:
RW, GW, TL, and ATL workers (Note: ADM follows phase 1 availability scheduling)
- Check the official calendar regularly.
- Arrive at least 30 minutes early before assigned service times.
- Confirm that computers and printers are up and running as expected.
- Ensure the correct date and service time are showing before the first check-in.
- Serve on assigned dates.
- Submit Change Requests as soon as a conflict becomes known.
- Keep profile information current.
- Review training material when leadership issues updates.
TL
- Monitor the dashboard regularly for Change Requests and gaps.
- Review any remaining gap after EFP has exhausted available attempts.
- Use Manual Override only if a gap remains after the automated steps have been exhausted.
- Self-assign or assign eligible workers, including ATL and/or RW, to fill remaining gaps when required.
- Communicate schedule changes clearly.
- Review training access analytics to identify engagement and accountability.
- Avoid using override as a convenience tool.
ATL/AcTL — Assist in monitoring and response. Act only within assigned authority when TL is unavailable. Document actions through the system. Assist with monitoring system actions within approved authority. When working as AcTL, follow same required actions as TL.
ADM — Monitor system health. Provide technical support. Maintain configuration and permissions. Support leadership when system errors or access issues occur. Perform Manual Override only when TL and AcTL are unavailable, when acting under an approved protocol, or when needing to activate the ADM "BREAK THE GLASS" rule of authority to prevent operation escalation by filling the gap when there are 24 hours or less remaining before the 72-hour system lock-down is activated.
Automated system actions:
- The system monitors schedule changes continuously.
- The system records every login, submission, Change Request, assignment, override, and system-generated action.
- The system updates dashboards in real time.
- The system tracks training access, including who accessed materials, when, and for how long.
- The system sends automated alerts when gaps are created or unresolved.
- The system maintains the audit trail file as the permanent record.
- The system keeps the official calendar current after approved changes are processed.
- The system automates EFP through SMS to all active workers and members.
- First eligible responder or responders fill the gap or gaps through the system.
- Only if gaps remain after Phase 7, EFP Exhaustion does the TL, or the ADM when TL and AcTL are not available, perform Manual Override to assign workers to fill gaps identified by the system and displayed on the TL and ADM dashboards.
- At the required lock-down point, the system locks the schedule, develops the final/official quarterly schedule, and posts the schedule to the system calendar where it becomes the official schedule of record.
- After publication, the Change Request protocol remains in place for unforeseen conflicts.
Key rule: Maintenance continues throughout the quarter. The schedule is not a one-time document; it is a live system record controlled by approved protocols and managed by the ADM.
THE GOAL is for Phases 5 through 7 to be rarely needed because a fully supportive, organized and available team, and a hopefully growing team, should complete the schedule during Phases 1 through 4.
Change Request Process
Purpose: A Change Request allows a worker to report an unforeseen/unplanned conflict after the schedule has been generated and locked.
Worker actions required:
Worker submitting the Change Request
- Log in using personal email and PIN.
- Select the assigned date that can no longer be worked and select UNAVAILABLE.
- Submit the Change Request as soon as the conflict is known.
- Provide the requested reason or explanation if prompted.
- Understand that the request is automatically approved and will create a gap that must be filled.
TL — Review the new gap created by the Change Request. Confirm that the gap is visible on the dashboard and the schedule. Allow the system to attempt automated approved filling steps. Monitor EFP and Manual Override only when required. Communicate with affected volunteers as needed.
ATL/AcTL — Monitor the Change Request if acting for the TL. Follow established protocols exactly. Adhere to the same action as required by the TL when performing AcTL duties.
ADM — Provide technical help if the request cannot be submitted. Avoid changing the program decision unless authorized by protocol or ADM emergency authority needs implemented.
Automated system actions:
- The system automatically approves all Change Requests.
- The system removes the worker from the affected assignment.
- The system creates a gap for the affected date and service.
- The system records who submitted the request, when it was submitted, the reason, and which assignment was affected.
- The system updates the official calendar.
- The system updates dashboards and gap indicators.
- The system triggers the appropriate automated gap-filling workflow.
Key rule: Change Requests are never denied. The system preserves volunteer accountability by logging the request while protecting volunteers from being forced to serve when an unforeseen or unplanned conflict occurs.
Emergency Fill Exhaustion Protocol
Purpose: Emergency Fill Exhaustion Protocol is used when a service gap remains after standard scheduling and replacement options have been exhausted.
Worker actions required:
TL — Confirm that a gap exists after the EFP Automated process is complete. Confirm that normal automated options have been exhausted. Monitor the automated EFP results. Allow the system to assign the first eligible responder or responders. Document any manual decision if the EFP does not resolve the gap.
ATL/AcTL — AcTL assist only when authorized or when TL is unavailable. Follow the same steps required of TL. Document actions clearly.
RW and GW volunteers — Review the emergency message if received. Respond only if available and willing to fill the gap. Confirm acceptance through the system rather than informal communication. It is imperative that the system performs the protocols and that only occurs when everyone follows the same protocols.
ADM — Step in only if TL and ATL/AcTL are unavailable, if a technical issue prevents the process from working, or if ADM emergency authority is required. Support the automated EFP process. Use BREAK THE GLASS authority only under the defined emergency conditions.
Automated system actions:
- The system identifies the open gap.
- The system verifies that standard scheduling options have been exhausted.
- The system automatically sends emergency SMS messages to all active workers and members.
- The system tracks responses.
- The system assigns the first eligible responder or responders to the gap or gaps.
- The system prevents ineligible workers from being assigned if role rules prohibit the assignment.
- The system updates the calendar when the gap is filled.
- The system logs the EFP activation, notification time, worker response, assignment decision, and final outcome.
- The system flags unresolved gaps for leadership attention.
Key rule: EFP is automated and should resolve remaining gaps with minimal manual coordination. Manual Override is used only when the automated process has exhausted available options and gaps still remain.
Manual Override Process
Purpose: Manual Override is the final option when a gap remains after the Emergency Fill Protocol has been exhausted.
Worker actions required:
TL — Confirm that the gap remains unresolved. Confirm that EFP has been exhausted. Select the worker or coverage option to fill the gap. Enter a documented reason for the override. Confirm the override through the system. Avoid using override as a convenience tool.
AcTL — Use Manual Override only when TL is unavailable and authority has transferred. Follow the same documentation requirements as TL. Avoid using override as a convenience tool.
ADM — Use Manual Override only when TL and AcTL are unavailable, when acting under an ADM approved protocol, or when needing to activate the ADM "BREAK THE GLASS" rule of authority to prevent operation escalation by filling the gap when there are 24 hours or less remaining before the 72-hour system lock-down is activated. Document the reason clearly. Avoid using override as a convenience tool.
Automated system actions:
- The system verifies that the user has authority to override.
- The system records the override reason.
- The system updates the official calendar.
- The system marks the assignment as manually overridden.
- The system records the timestamp and person who performed the override.
- The system preserves the audit trail for later review.
Key rule: Manual Override is a last-resort tool. It exists to preserve coverage, not to bypass the system's automated features.
TSN Scheduler — Emergency Gap-Fill and Calendar Publication Protocol
Purpose: This protocol defines final gap alerts, ADM emergency authority, schedule locking, and calendar publication.
1. 36-Hour Final Gap Alert
When: 36 hours prior to the scheduled 72-hours system lockdown. This is 96 hours to 72 hours before the quarter starts.
Who receives it: ADM, TL, ATL at all levels, and RW receive the alert by both email and SMS.
What it contains:
- Quarter name.
- Quarter start date.
- A numbered list of every unfilled slot.
- Date and service time for each unfilled slot.
- A call to action with the EFP link.
Purpose: The alert provides a final urgent push to fill gaps before the schedule locks.
Deduplication: The alert fires only once per quarter.
2. BREAK THE GLASS — ADM Emergency Authority
What: BREAK THE GLASS is the ADM's emergency override authority to automatically fill all remaining gaps.
When available: The BREAK THE GLASS action is available when there are 24 hours or less remaining before the 72-hour system lock-down activates. This is the window from 96 hours to 72 hours before the quarter starts.
How it works: (One Example)
For each gap, the system selects the available worker (Worker A) with the fewest assignments that quarter but who's availability schedule is limited. The candidate pool includes RW, TL, or ATL.
EXAMPLE: If the selected worker (Worker A) has a scheduling conflict with filling current gap slots, the system attempts to rearrange coverage by finding a replacement for the vacant slot(s). This could be for instances when the worker with the fewest assignments can only work on a particular Sunday in a given month but is available to fulfill a slot on a Sunday that another worker (Worker B) has been scheduled to fulfill. According to Worker B's availability schedule, the worker is available on other gap dates. The system will automatically remove Worker B, who is occupying a slot, and fill it with Worker A, since this worker has the least amount of assignments but by doing so fills-a-gap in the schedule.
- No worker is moved if the move violates the worker's submitted availability.
- The system checks the availability of every affected worker before making any change.
- If one rearrangement does not work, the system checks other possible adjustments and acts according to the approved logic.
- TL and ATL are included in both the candidate pool and the rearrangement process.
Below are the three scenarios considered to create this protocol:
- Case 1 (Direct fill): A is available for the gap and has no conflict → assign directly. (unchanged)
- Case 2 (Same-date conflict): A is available for the gap but assigned to another service on the same date → find a replacement for A's existing slot, then move A to the gap. (unchanged)
- Case 3 (Rearrangement — the missing piece): A is NOT available for the gap → search all currently-filled slots for one where A IS available and is held by worker B, where B IS available for the gap. If B also has no same-date conflict on the gap date, execute the swap: release B from their slot, assign A to B's old slot, assign B to the gap.
Access: The BREAK THE GLASS action is available only to ADM from the Control Center Scheduler tab. The action requires confirmation and a written reason.
Audit: Every action is logged as a manual override record and preserved in the full audit trail.
3. Schedule Lock and Calendar Publication Flow
- 72 hours before quarter start: The system force-locks the schedule even if gaps remain.
- Immediately after lock: ADM receives an SMS to review the schedule for accuracy and remaining gaps.
- ADM authorization: ADM can manually authorize the calendar (schedule) from the Control Center at any time after lock.
- 31 hours before start: If ADM has not authorized the calendar, the system automatically authorizes it.
- 30 hours before start: The calendar is published. All assignments sync to the official Google Calendar, and an SMS blast goes to all members. Official Schedule Active.
- Friday/Saturday exception: If the 30-hour mark falls on a Friday or Saturday, the calendar publishes at 1:00 PM ET on the Friday before the quarter starts.
Dashboard Functions
Purpose: Dashboards give each role the information needed to perform assigned responsibilities without exposing unnecessary controls.
Volunteer dashboards — RW/GW (Workers) can:
- View their profile.
- Submit availability.
- Review assigned dates.
- Submit Change Requests.
- View the official schedule.
- Access and Acknowledge training materials when available.
TL dashboard — The TL can:
- View the full schedule.
- Monitor availability submissions.
- View schedule gaps.
- Track Change Requests.
- Monitor automated EFP results.
- Perform Manual Override after required steps are exhausted.
- Review training access analytics.
- Review audit trail records.
ATL/AcTL dashboard — The ATL or AcTL can:
- View schedule status.
- Monitor gaps.
- Support communication and coverage.
- Assist with monitoring system actions within approved authority.
- Act for the TL when the TL is unavailable.
ADM dashboard — The ADM can:
- Manage system configuration.
- Review technical system health.
- Manage roles and permissions.
- View complete audit trail records.
- Review dashboards for all scheduling phases.
- Support access and troubleshooting.
- Manage ADM-assigned system actions.
- Activate BREAK THE GLASS emergency authority when the defined conditions are met.
Automated dashboard actions:
- The system updates submission status in real time.
- The system displays open gaps.
- The system identifies pending or completed Change Requests.
- The system displays locked schedule status.
- The system records dashboard access.
- The system tracks training access analytics.
- The system provides leadership visibility into scheduling progress.
- The system displays EFP, EFP exhaustion, Manual Override, and calendar publication status.
Audit Trail File
Purpose: The audit trail file creates accountability by recording every meaningful system action.
The audit trail records:
- User logins.
- Availability submissions.
- Availability edits before deadline.
- Schedule generation results.
- Worker assignments.
- Gap creation.
- Change Requests.
- EFP activation.
- Emergency responses.
- EFP exhaustion.
- Scheduling re-run results.
- Manual Overrides.
- BREAK THE GLASS actions.
- Training material access.
- Profile updates.
- System-generated notifications.
- Role or permission changes.
- Schedule lock and calendar publication events.
Worker responsibilities:
- Users must log in with their own credentials. Never share credentials.
- Users must not share PINs.
- Leadership must document reasons for overrides and emergency decisions.
- ADM must protect system security, scheduler role access and preserve data integrity.
- Volunteers must use the system rather than informal communication when the action affects the schedule.
Automated system responsibilities:
- The system records the user, date, time, action, and affected schedule record.
- The system preserves the audit trail file for leadership review.
- The system supports accountability, dispute resolution, and fairness verification as long as appropriate protocols are followed and adhered to.
Key rule: If it affects the schedule, it must be in the system.
Notifications and Communication
Purpose: Notifications keep volunteers and leadership informed at each important step.
Automated notifications may include:
- Availability window opening message.
- Availability reminder message.
- Deadline warning.
- Schedule publication notice.
- Assignment notification.
- Change Request confirmation.
- Gap alert to leadership.
- EFP message to active workers and members.
- 36-hour final gap alert.
- Schedule lock notification.
- ADM review notification.
- Calendar publication SMS blast. Official Schedule Active.
- Training update notice.
Worker communication rules:
- Volunteers should use the system for schedule-related actions.
- TL may provide clarification, encouragement, or reminders.
- Informal texts are not official decisions and do not replace system actions.
- Leadership should direct workers back to the official scheduler when a schedule change is needed.
- ADM should communicate technical instructions clearly and avoid making program decisions unless authorized by protocol or ADM emergency authority, including the Break the Glass protocol.
Key rule: Communication supports the system, but the official record remains the web portal calendar, official calendar publication, and audit trail file.
Training Materials and Access Tracking
Purpose: Training materials help workers understand the scheduler, the role expectations, and ministry procedures.
Worker actions required:
RW and GW
- Review assigned training materials.
- Revisit training(s) and the user manual when updates are issued and anytime there is confusion or the need to remember policy and protocol.
- Follow instructions provided by leadership.
TL
- Monitor training access analytics.
- Identify workers who may need follow-up.
- Review user manual as needed.
- Submit training or protocol updates to ADM when changes are needed.
ADM
- Upload or update training materials as approved.
- Maintain access controls.
- Ensure training resources remain available.
- Review user manual as needed.
Automated system actions:
- The system records who accessed training materials.
- The system records when training materials were accessed.
- The system may track duration or completion indicators when available.
- The system provides analytics to leadership.
- The system preserves training access records in the audit trail file.
Key rule: Training access analytics are statistics used to support engagement and accountability, not to shame or embarrass volunteers and should not be used as such.
Profile Management
Purpose: Accurate profile information ensures correct communication, access, and scheduling.
Worker actions required:
- Workers must keep email, phone number, role, and availability information current.
- Workers must use their own PIN.
- Workers should notify leadership or ADM if contact information changes.
- ADM should update role or permission information as needed.
Automated system actions:
- The system stores profile data.
- The system uses profile information to determine role access.
- The system uses phone and email information for notifications.
- The system logs profile updates.
- The system prevents unauthorized role changes.
Key rule: Incorrect profile information can prevent proper scheduling and communication.
Security and Access
Purpose: System access must protect the integrity of the schedule and the privacy of volunteers.
Access rules:
- Every user must use their own credentials: Email and PIN.
- Credentials should not be shared.
- Users should log out when finished on shared devices.
- ADM manages role access and permissions.
- TL, ATL, AcTL, RW, and GW receive access based on role.
- Users should report access problems immediately.
Automated system actions:
- The system validates email and PIN credentials.
- The system assigns permissions based on role.
- The system logs successful access.
- The system may record failed access attempts and when to temporarily suspend access based on failed security attempts.
- The system limits users to approved functions.
- The system protects the locked schedule from unauthorized edits.
Key rule: Role-based access ensures each person can do what is required and cannot do what is outside their authority.
Troubleshooting Guide
If a volunteer cannot access the scheduler:
- Confirm the correct email address is being used.
- Confirm the correct PIN is being entered.
- Try opening the scheduler link again.
- If the SMS link does not work, enter the scheduler web address directly.
- Contact ADM for technical support if access still fails.
If availability was submitted incorrectly:
- If the availability window is still open, the worker may update the submission.
- If the window has closed, the worker must follow the approved process.
- Leadership should not make informal changes outside the system.
If a worker cannot serve an assigned date:
- Submit a Change Request.
- Do not rely only on a text message or verbal notice.
- The system will create a gap and trigger the appropriate process.
If a gap remains open:
- The system continues approved gap-filling steps.
- EFP automatically sends SMS messages to active workers and members.
- The first eligible responder or responders fill the gap.
- If gaps remain after EFP exhaustion, TL may use Manual Override.
- If TL and AcTL are unavailable or ADM emergency authority is required, ADM may act under approved protocol.
If the official calendar appears incorrect:
- TL or ADM should compare the calendar with the audit trail file.
- ADM should investigate technical display issues.
- Leadership should not create a separate unofficial schedule.
If a user has the wrong role:
- Notify ADM.
- ADM reviews and corrects permissions as needed.
- The system logs the role change.
Quarterly Operating Checklist
Before the quarter begins:
- ADM confirms system configuration.
- TL confirms the list of RW, GW, ATL, and AcTL workers.
- ADM confirms SMS and dashboard functions.
- Training materials are reviewed and updated if needed.
- Availability window dates are confirmed.
During the availability window:
- Workers submit availability.
- The system sends reminders.
- TL monitors submissions.
- ADM supports access issues.
- The system locks submissions at the deadline and follows protocols.
During schedule generation:
- The system processes RW availability.
- The system processes GW availability if applicable.
- The system applies role rules and fairness logic.
- The system schedules TL and ATL rotation.
- The system activates automated EFP if gaps remain.
- The system re-runs scheduling after EFP review when required.
- Gaps are flagged.
Before schedule lock and publication:
- EFP exhaustion is reviewed.
- TL acts only if remaining gaps require Manual Override.
- ADM may activate BREAK THE GLASS under defined emergency conditions.
- The system force-locks the schedule at 72 hours before the quarter starts.
- ADM receives the system completed schedule review SMS after lock to determine accuracy.
- Calendar authorization and publication follow the required timeline.
After schedule publication:
- Workers review assignments.
- TL monitors gaps and Change Requests.
- ADM confirms calendar access.
- The schedule remains locked except through approved processes.
- The published calendar becomes the official schedule of record.
During the quarter:
- Workers serve assigned dates.
- Workers arrive at least 30 minutes early and confirm computers turn on and work, printers have paper, turned on and work, accurate computer date, and accurate service time before first check-in.
- Change Requests are submitted when needed.
- EFP is used for unresolved gaps.
- Manual Override is used only as a last resort.
- Audit trail and training access remain available for review.
After the quarter:
- TL reviews fairness and gap outcomes.
- ADM reviews system performance.
- Leadership identifies necessary protocol updates and notifies ADM.
- Training materials are updated as needed.
- The next quarter's schedule cycle begins. The process starts over.
END OF USER MANUAL – 07.07.2026