Permissions from assigned roles combine. Adding a narrower role does not subtract a permission granted by a broader role.
In the predefined Events catalog, Create Unique Tracking Links and Publish Event are both granted to Advanced Events Admin and the broader superadmin roles. Basic Events Admin does not receive the tracking-link creation permission in that catalog. Do not assume that adding Basic to Advanced removes publishing, or that an unverified per-user deny checkbox supplies the requested approval boundary.
For giving forms, Manage Unique Tracking Links and Tracking Pixels is supplied by Basic Form Admin, Communications Admin and broader form/superadmin roles. Those roles have other capabilities; they are not automatically tracking-only. For a narrower combination than the predefined roles offer, consult Support. Ask support to evaluate the needed separation of duties before granting a role with unwanted powers.
Manage API Keys includes viewing, generating and deactivating keys. It is not read-only. SFTP and other integration screens have separate authorization paths, so identify the actual integrations an IT colleague needs rather than promise a universal view-only integrations role. Do not expose integration credentials in a support ticket or grant a broad role solely because its name sounds suitable.
Backend event registration
Basic Events Admin is the narrowest predefined Events role that includes Manage Registrations for the newer administrator registration workflow. Give it the intended event scope and confirm the school's backend-registration feature is enabled. This role grants additional event capabilities; it is not a registration-only role. Refund Payments and Offline Registration uploads have separate permissions. A full event or no available tickets/packages can also disable Add Registration even for an authorized administrator.
Alumni-status-only access
The available constituent and volunteer roles expose more than a person’s alumni yes/no status. Constituent viewing and preview permissions expose broader record information, and volunteer search restrictions scope which people can be seen, not an alumni-only field view. Do not grant a broad administrator role for this purpose. Have an authorized data owner provide the minimal approved list or check the individual record, or review a product permission change if ongoing field-only access is required.
Reporting access across Online Giving and Events
For downloading Online Giving and Events reports, start with Reporting Admin plus Events Reporting Admin, scoped to the needed products/records. Reporting Admin includes donation/deposit reports and Manage Gifts viewing/export; it also permits sending receipts and recurring management links, so it is not a perfectly read-only gift role. Events Reporting Admin covers school-level event reports, event custom reports and event deposit reports. If the person also needs to mark deposits reconciled, that is a separate permission supplied by finance roles; do not add broader finance powers solely to download reports. Verify the final combination against the required tasks.
Events staff who should not edit or send
Events View Only Admin can view the event admin area outside Edit Event. Events Check-in Admin adds check-in/undo check-in for events and activities. Events Reporting Admin adds exports/custom-report management and NXT integration error actions, so it is not strictly view-only. Apply event/group scope and avoid content/communication roles where editing/sending is not intended. New-registration management is separate from read-only tracking. A reachable generic mailbox may be an account email, but email uniqueness means one account identity and audit trail; individual staff accounts provide clearer attribution.
Comments
0 comments
Please sign in to leave a comment.