Menu Close

Security Roles

Atlas access and security is controlled through the use of system roles. Users are assigned to a set of roles that provide access to the data and features required to perform their job tasks. Some roles grant broad access that cross multiple areas of Atlas, such as Base View and Affiliate Admin. Other roles control access to very specific features, such as MRN Access and Appeal Admin.

All users will be assigned to one and only one of the following base roles:

  • Base View – Most common base role
  • IPC Base – BWH IPC users
  • Affiliate Admin and Affiliate Manager – The few users who require “full affiliate access” to Atlas; only MGB users will have full access to Atlas (system administrator)

Descriptions of each role are included in the following tables:

View Roles

RoleDescriptionDependencies & Related Roles
Base ViewView most constituent details, tiles, planning calendar, appeals, revenue, events, designations, purposes, campaigns, naming opportunities, Development WorkspaceAll users will have Base View, IPC Base (BWH only), Affiliate Admin, or Affiliate Manager.
Epic Confidential Visits ViewAccess to confidential patient data including:

*Patient records that are flagged as confidential on the Patient tab of constituents
*The "Epic patient visits - restricted" query view
*Patient records on constituents with the Staff constituency
*UPDATES PLANNED FOR Q4CY20: Refer to details here: http://phdevdoc.wpengine.com/encyclopedia/patient-patient-detail/
Must also have Patient View
Interaction ViewView constituent interactions.
Patient ViewView patient data
Prospect ViewView the Prospect and Fundraiser tab on constituents, fundraising plan details
Wealth and Ratings ViewView wealth and ratings area
Client Services RestrictedDenies access to interaction notes of specific notes types (for MGH, denied note types include Client Services Consultation Detail and Client Services Contact Detail)

Constituent Management Roles

RoleDescriptionDependencies & Related Roles
Constituent StaffManage constituent details including Fundraiser constituency, contact details (except address), personal info, interests, event restrictions, relationships, prospect status, flag prospect, communication preferences, educational history; can also review event invitee list, add research requests, manage group members
Constituent AdminManage Constituent data integrity workspace, add/remove spouses, manage constituencies and alternate lookup IDs, decease and inactivate constituentsMust also have Constituent Staff
Constituent AddAdd individual and organization records; will be assigned with sites for BWH users
Group AdminAdd group/committee records
Interaction ManagementAdd, edit, delete constituent interactions; interactions will be site-secured for BWHMust also have Interaction View.
Address AdminAdd/edit/delete constituent addresses
MRN AccessAccess to alternate lookup IDs with MRNs
Alternate Lookup ID AdminManage alternate lookup IDs on constituents
Name Format AdminManage name formats
Constituent Attributes AdminManage constituent attributes on constituent records
Constituent MergeRun constituent merge processes, merge 2 constituents on an ad-hoc basis
Constituent DeleteDelete constituent records
Constituent Documentation Manage Constituent Documentation for individual and group constituents
Constituent AuditAccess the Constituent history tab

Gift Processing Roles

RoleDescriptionDependencies & Related Roles
Gift ProcessingAdd/update revenue via batch; manage revenue, tributes, recognition defaults, appeals, matching gifts, benefits, receipts; run credit cards, BrightVine Data LoaderMust also have Batch and Import and Gift Support.
Revenue AdjustmentsAdjust payments and pledgesMust also have Gift Processing
Gift Processing ManagerRun post to GL, global pledge write-off, recurring gift status processes; add and update purpose and designation records; general ledger setupMust also have Gift Processing.
Gift Processing Reporting Run Gift processing related reports. May be assigned to non-development staff (e.g., finance staff) without other roles except Base view
Gift SupportAdd/Edit/Delete revenue attributes, solicitors, documents, recognition credits, campaigns, and business units

Prospect Management & Research Roles

RoleDescriptionDependencies & Related Roles
Prospect StaffManage fundraising and stewardship plans, prospect status, flag prospect, opportunities, contact reports, prospect teams, funding interests, research requests, referrals; access to My Fundraiser Page, FROG; add research requestsMust also have Prospect View
Prospect AdminAssign prospects in bulk, manage prospects in bulk, Fundraising Teams ManagementMust also have Prospect Staff
Prospect AssignmentAssign/unassign prospect managers, access Manage prospect assignment requests areaMust also have Prospect Staff
ResearchManage Wealth and ratings data, wealth screenings, research lists, research tools; access My prospect research page; manage educational institutions in the Educational CatalogMust also have Prospect Staff
Research Request Cancel/DeleteCancel & delete research requests, including prospect assignment and stewardship report requests
Planned GivingManage planned gifts, add planned gifts as revenue
Constituent MappingAccess to constituent mapping, manage mapping instances
Opportunity RevenueLink existing revenue to opportunitiesMust also have Prospect Staff
Solicitor GoalView solicitor goals tab
Mailing List Admin Enable Mailing list review via My FundraiserMust also have Prospect Staff

Stewardship Roles

RoleDescriptionDependencies & Related Roles
Stewardship StaffManage custom acknowledgements and stewardship report requests
Stewardship ManagerManage stewardship plans and naming opportunities; manage specific purpose details including Financial Info, Recipients, Naming opportunities, Stewardship, Documentation, and Goals
Recognition Program MembershipManage recognition program membership
Interaction RevenueLink existing revenue to interactionsMust also have Interactions
Purpose AttributesManage attributes on purposes

Event Management Roles

RoleDescriptionDependencies & Related Roles
Event ManagerAdd events, event management templates, locations, registration types, restrictions types; manage event coordinators and tasks, fundraising teams, speakers, expenses, registration options, event preferences
Event SeatingAssign seats
Event AttendanceManage RSVPs and waitlists; update attendance status per invitee; event registrant batch entry; view benefitsMust also have Batch and Import
Event Invitation AdminAdd and process event invitations

Marketing & Communication Roles

RoleDescriptionDependencies & Related Roles
Direct MarketingManage marketing efforts, segments, packages, seeds, vendors, donor challenges; view source codes
General CorrespondenceManage general correspondence processes and correspondence codes
Revenue CommunicationsManage revenue communication processes including acknowledgements and reminders
Ad-hoc CommunicationsAdd ad-hoc general correspondence and appeals on a constituent's Communications tab

Other Admin & Miscellaneous Roles

RoleDescriptionDependencies & Related Roles
Affiliate AdminFull system access EXCLUDING:

*Page designer and shell design
*Add attribute categories
*Manage revenue and recognition reporting filters
*Run Data Warehouse processes
*Schedule business processes
*Maintain system roles
*Add application users

Affiliate Admins can manage roles assignments on existing users.
Epic Confidential Visits is the only other role that might be required for users with Affiliate Admin
Affiliate ManagerFull system access EXCLUDING the features listed for Affiliate Admin as well as these unused features:
*Treasury
*Web
*Foundations
*Auction Events
*Membership
*Appeal Mailings

Epic Confidential Visits is the only other role that might be required for users with Affiliate Manager
Appeal AdminAdd appeals
Batch and ImportAccess batch entry and import tasks; specific batch types are granted through other roles
Query and ExportAccess the Information library, queries, and KPIs; manage export processes; query source views are granted through other roles
Campaign ManagerAdd and manage campaign records
Volunteer ManagerFull access to the Volunteers functional area
Grant ManagerFull access to the Foundations functional area minus Credit rules setup
Outlook IntegrationStandard role included with BrightVine Outlook Integration
Global ChangesAdd and manage global changes. Global change instances that should not be accessed by non-Affiliate Admins should be restricted to the Affiliate Admin role. Refer to http://phdevdoc.wpengine.com/encyclopedia/security-administration-tips-gotchas/#business_process for more details.
Smart Query DefinitionsAdd new smart query definitions based on ad-hoc queries
IPC BaseAccess to view and manage:

*Contact details
*Alternate lookup IDs including MRNs
*Aliases
*Relationships
*Selections (view only)
IPC users will also require Interactions, Patient View, Epic Confidential Visits, and Constituent Add
User ManagerAdd, edit, and inactivate application users. This role will only be used by MGB users who are not System Administrators. Affiliate users will not be able to add application users even if they are assigned to this role because specific features have been denied in the Affiliate Admin, Base View, and IPC Base roles.

Atlas Portal Roles

RoleDescriptionDependencies & Related Roles
Portal Admin Access all Atlas Portal tabs and the Atlas ID Identification Processes.
Portal UserCan assign Partners ID to constituents and access the Atlas ID Identification review page. Portal View
Portal ViewCan view all Atlas Portal tabs and search for constituents across database. Can only search databases where they already a User record.

Leave a Reply