Module authorization levels

Review module authorization levels and required Staff site navigation access for Full staff users and Casual staff users.

Each Staff access area grants a Full staff user or Casual staff user permission to perform a function in the Staff site. These areas are assigned from a drop-down on a user's account Security tab, and each drop-down uses the same 0–8 numeric scale below — though no module uses every level.

Understanding how the level scale works

LevelNameWhat it generally adds
0No accessDefault. Grants no access to the area.
1Basic Display OnlyView-only access to a small set of records (for example, Fundraising gift requests).
2ReportsDashboards and reports for the area.
3Limited Entry/EditDay-to-day data entry on records that already exist (for example, entering gifts, managing enrollments).
4Full Entry/EditBroader entry/edit rights: processing, generating, and importing records.
5Table MaintenanceConfiguring the supporting tables and settings a module depends on (billing cycles, pricing groups, unit types).
6ReservedNot tied to any out-of-the-box functionality in any module.
7ReservedNot tied to any out-of-the-box functionality in any module.
8System SetupSystem-wide administrative functionality for the module.
📘

Note

Levels 6 and 7 are intentionally not covered below — they're numeric slots in the scale that no module ties to any out-of-the-box feature. If your organization has a custom need for them, they're available; otherwise you can ignore them.

Module areas and where to find them

Module names don't always match the Staff site menu section they control, which can make the tables below harder to scan than it should be. Use this as a lookup:

Module (drop-down name)Staff site menu section(s) it governs
CustomersCommunity (contacts, committees, duplicates), plus parts of Membership, Reports, and Settings
DuesMembership
EventsEvents
FundraisingFundraising
OrdersCommerce
FinanceFinance, plus parts of Commerce and Reports
CertificationCertification
SystemNo dedicated menu section — paired with the SysAdmin role and parts of Settings

System

The System authorization level grants system administration, as the SysAdmin role does. They are intrinsically paired: assigning a user System: 8 automatically adds them to the SysAdmin role; removing System: 8 automatically drops it.

Don't remove a user's SysAdmin role without also lowering their System level, and vice versa — parts of iMIS that check for administrator status will conflict with the parts that don't. If a SysAdmin also needs access to other Staff access areas, assign those manually; they are not automatically raised to level 8. See Assigning security credentials and staff access for more information.

Levels 0–7 in the System drop-down have no effect on out-of-the-box content. The only level that changes access is 8 – System Setup, which applies the SysAdmin role. Level 8 cannot be assigned to a Casual staff user.

Security sets

Beyond module authorization levels, some navigation items are also gated by a security set — a separate mechanism that controls who can see a folder, object, or navigation item at all, independent of what a user can do once there. See Security sets for the full list, including Administrators Full Control, Reporting Users Full Control, and the security groups used by Campaigns, Segmentation, RFM, and Process manager.

Out-of-the-box navigation

Full staff users and Casual staff users access the Staff site based on their authorization levels. These can be viewed and updated from RiSE > Site Builder > Manage sitemaps, selecting Staff site, then the Access settings tab, then expanding Staff module authorization levels.

📘

Note

Some functionality in the Staff site requires a license key. Contact ASI for more information.

The following tables outline the required authorization level a staff user must have to access each navigation item, organized by the Staff site menu section it appears under. See Module areas and where to find them above if a section name doesn't match the module drop-down you're looking for.

Community

📘

Note

See Contact account pages (Party.aspx) for more specific information about security when viewing contact and organization pages.

Navigation ItemSecurity SetLevel AssignmentLicense Required
DashboardAll Staff Full Control  
Engagement:   
  • Overall
    - Organizations
All Staff Full Control  
Find contactsAll Staff Full Control  
Add contactAll Staff Full Control  
Data integrityAll Staff Full Control  
Manage duplicatesAll Staff Full ControlCustomers: 8
OR
Events: 8
OR
Fundraising: 8
Note: There are two different versions of Duplicate Merge. Standard is available out-of-the-box, and Premium requires additional licensing. See Managing duplicate contacts for more information.
Duplicate merge logsAll Staff Full Control  
CommitteesAll Staff Full ControlCustomers: 5 
CommunitiesAll Staff Full Control Yes
Volunteers:   
  • Dashboard
    - Find volunteers
All Staff Full Control  
GroupsAll Staff Full Control  
Import contactsAll Staff Full Control  
Security:   
  • Users
All Staff Full ControlCustomers: 4 
  • Roles
Administrators Full Control  
📘

Note

The Customers: 5 level also enables the Assign purchaser to a group setting when defining products (also requires Orders: 4). This setting lives on the product record rather than in Community navigation, so it doesn't appear as its own row above.

Membership

📘

Note

See Contact account pages (Party.aspx) for more specific information about security when viewing contact and organization pages.

Navigation ItemSecurity SetLevel AssignmentLicense Required
DashboardAll Staff Full ControlCustomers: 2 
ChaptersAll Staff Full Control  
Renewals:   
  • Generate renewals
    - Issue notifications
All Staff Full ControlDues: 4 
  • Reverse open invoices
All Staff Full ControlDues: 4 
Manage expired membersAll Staff Full ControlDues: 8 
Automatic payments:   
  • Dashboard
    - Process payments
    - Review payments
All Staff Full ControlDues: 4Yes
  • Enrollments
All Staff Full ControlCustomers: 4Yes
Billing cyclesAll Staff Full ControlDues: 5 
Billing productsAll Staff Full ControlDues: 5 
Prorating rulesAll Staff Full ControlDues: 5 
Configuration wizardAdministrators Full Control  

Fundraising

Navigation ItemSecurity SetLevel AssignmentLicense Required
DashboardAll Staff Full ControlFundraising: 2Yes
Enter giftsAll Staff Full ControlFundraising: 3Yes
Gift requestsAll Staff Full ControlFundraising: 1 
Find giftsAll Staff Full ControlFundraising: 2Yes
Find gift itemsAll Staff Full Control Yes
Add gift itemAll Staff Full ControlFundraising: 5Yes
Moves management:   
  • Dashboard
All Staff Full ControlFundraising: 2Yes
  • My major donors
All Staff Full Control Yes
Automatic payments:   
  • Dashboard
    - Process payments
    - Review payments
    - Enrollments
All Staff Full ControlFundraising: 4Yes
Receipting:   
  • Issue receipts
    - Find issued receipts
    - Receipt logs
All Staff Full ControlFundraising: 3 
Tribute notification:   
  • Issue notifications
    - Find issued notifications
All Staff Full ControlFundraising: 3Yes
Gift AidAll Staff Full ControlFundraising: 3Yes
Reverse open pledgesAll Staff Full ControlFundraising: 3Yes
Reverse a gift, pledge, or installment pledge invoiceAll Staff Full ControlFundraising: 3
OR
Finance: 4
 
Recurring payments:   
  • Generate expected payments
    - Import payments
All Staff Full ControlFundraising: 4Yes
Import donationsAll Staff Full ControlFundraising: 4Yes
Premium setsAll Staff Full ControlFundraising: 4Yes
Adjustment logsAll Staff Full ControlFundraising: 3 

Events

Navigation ItemSecurity SetLevel AssignmentLicense Required
DashboardAll Staff Full ControlEvents: 2 
Find eventsAll Staff Full Control  
Find registrationsAll Staff Full Control  
Add eventAll Staff Full ControlEvents: 5 
CalendarAll Staff Full Control  
Issue event confirmationsAll Staff Full Control  
Manage templatesAll Staff Full ControlEvents: 5 
Event pricing group managementAll Staff Full ControlOrders: 5
OR only
Finance: 5
 
Settings > Events > Event resources (defining resource types)Administrators Full ControlEvents: 8 

Commerce

(Governed by the Orders module — see Module areas and where to find them.)

Navigation ItemSecurity SetLevel AssignmentLicense Required
DashboardAll Staff Full ControlOrders: 2 
Find productsAll Staff Full Control  
Add productAll Staff Full ControlOrders: 4 
Find ordersAll Staff Full ControlOrders: 2 
Process orders:   
  • Issue quotes
    - Convert quotes
    - Print shipping orders
    - Ship orders
    - Generate invoices
    - Release backorders
All Staff Full ControlOrders: 4 
PromotionsAll Staff Full ControlOrders: 5 
Pricing groupsAll Staff Full ControlOrders: 5,
Events: 5,
OR
Finance: 5
 
Inventory receiptsAll Staff Full ControlOrders: 4 
Cancel an order (not yet invoiced)All Staff Full ControlOrders: 4 
Adjust or reverse an order invoiceAll Staff Full ControlFinance: 4
OR
Orders: 4
 
Override the default order type in the cartAll Staff Full ControlOrders: 4 

Advertising

Navigation ItemSecurity SetLevel AssignmentLicense Required
DashboardAll Staff Full Control  
Media OrdersAll Staff Full Control  
Settings:   
  • Media assets
    - Representative - territory
    - Mapping
    - Production settings
All Staff Full Control  
📘

Note

Advertising isn't currently gated by a module authorization level — access is controlled only by the All Staff Full Control security set above.

Marketing

Navigation ItemSecurity SetLicense Required
Communication dashboardEveryone Full Control 
Advanced emailAll Staff Full ControlYes
Communication templatesAll Staff Full Control 
Communication logsAll Staff Full Control 
Campaigns:  
  • Track campaigns
  • Define campaigns
  • Define inserts
  • Record responses
  • View output
  • Import source codes
Campaign Users Full Control 
  • Settings
Campaign Admins Full Control 
Segmentation:  
  • Define segments
Segmentation Users Full ControlYes
  • Settings
Segmentation Admins Full ControlYes
RFM:  
  • Run analytics
RFM Users Full ControlYes
  • Settings
RFM Admins Full ControlYes
Process manager:  
  • Projects
  • Tasks
Opportunity Users Full ControlYes
  • Settings
Opportunity Admins Full ControlYes
📘

Note

Marketing isn't gated by a module authorization level — access is controlled by the security groups listed above. See Security sets for how to assign them.

Certification

Navigation ItemSecurity SetLevel AssignmentLicense Required
Enrollments:   
  • By program
  • By enrollee
All Staff Full ControlCertification: 3Yes
  • Inactive enrollments
All Staff Full ControlCertification: 4Yes
Pending approvals:   
  • Requirement completions
  • Program completions
All Staff Full ControlCertification: 3Yes
Define programs:   
  • Program components
  • Program groups
  • Experience programs
  • Certification programs
All Staff Full ControlCertification: 4Yes
  • Unit types
All Staff Full ControlCertification: 5Yes
ProvidersAll Staff Full ControlCertification: 3Yes

Finance

Navigation ItemSecurity SetLevel AssignmentLicense Required
DashboardEveryone Full ControlFinance: 2 
InvoicesAll Staff Full ControlFinance: 2 
Pay Central:   
  • Dashboard
  • Find payments
All Staff Full ControlFinance: 2 
  • Automatic payment transactions
  • Pay Central Live
Administrators Full ControlFinance: 2 
Batches (find or post)All Staff Full ControlFinance: 2 
Batches (create, edit, or delete)All Staff Full ControlFinance: 3 
Closing procedures:   
  • Credit invoices
  • Invoice write-offs
  • General ledger export
All Staff Full ControlFinance: 4 

Reports

Navigation ItemSecurity SetLevel AssignmentLicense Required
Report WriterReporting Users Full Control  
All reportsAdministrators Full Control  
Contact reportsReporting Users Full ControlCustomers: 2 
Membership reportsReporting Users Full ControlCustomers: 2 
Fundraising reportsReporting Users Full ControlFundraising: 2Yes
Event reportsReporting Users Full ControlEvents: 2 
Commerce reportsReporting Users Full ControlOrders: 2 
Accounting reportsReporting Users Full ControlCustomers: 2Yes
Certification reportsReporting Users Full Control Yes
Content reportsAdministrators Full Control  

RiSE

📘

Note

If you are not a SysAdmin, you must be at least a Full staff user who belongs to at least one content authority group to have access to certain areas of RiSE. Public users who are members of a content authority group cannot access RiSE, but they can interact with content records by using Easy Edit. See Administering security for more information about Full and Public user access.

Navigation ItemSecurity SetLicense Required
DashboardAdministrators Full Control 
Site Builder:  
  • Manage sitemaps
Administrators Full Control
OR
Full user who also belongs to at least one content authority group
 
  • Manage websites
Administrators Full Control 
  • Manage shortcuts
Administrators Full Control
OR
Full staff user or Casual staff user who also belongs to at least one content authority group
 
Page Builder:  
  • Manage content
  • Manage layouts
  • Manage images
  • Manage files
  • Task list
Administrators Full Control
OR
Full staff user or Casual staff user who also belongs to at least one content authority group
 
Theme Builder:  
  • Website templates
Administrators Full Control
OR
Full staff user or Casual staff user who also belongs to at least one content authority group
Yes
  • Website layouts
Administrators Full Control
OR
Full staff user or Casual staff user who also belongs to at least one content authority group
Yes
  • Themes
Administrators Full ControlYes
  • Task list
Administrators Full Control
OR
Full staff user or Casual staff user who also belongs to at least one content authority group
Yes
Tagging:  
  • Tags
  • Tagged list formats
Administrators Full Control
OR
Full staff user or Casual staff user who also belongs to at least one content authority group
 
Maintenance:  
  • Publishing servers
  • User defined fields
  • Content types
  • Navigation areas
  • Content authority groups
  • Query audit
Administrators Full Control 
Style Guide:  
  • Base elements
  • Forms
  • Icons
  • Utilities
Administrators Full Control 
Intelligent Query ArchitectAdministrators Full Control 
Business Object DesignerAdministrators Full Control 
Form Builder:  
  • Form library
  • Approval queue
  • Health check
  • Form groups
  • Migrate forms
Administrators Full ControlNote: There are two different versions of Form Builder. Standard is available out-of-the-box, and Premium requires additional licensing. See Form Builder FAQ for more information.
Panel Designer:  
  • Panel definitions
  • Panel sources
Administrators Full Control 
Process automationAdministrators Full ControlNote: There are two different versions of Process automation. Standard is available out-of-the-box, and Premium requires additional licensing. See Creating and using scheduled tasks and Creating and using alerts for more information.
ScoringAdministrators Full ControlNote: There are two different versions of Scoring. Standard is available out-of-the-box, and Premium requires additional licensing. See Scoring for more information.
Document systemAdministrators Full Control 
Workflow:  
  • Workflow viewer
  • Workflow items
  • Monitor processes
Administrators Full Control 
Task viewerAdministrators Full Control 
Upgrade logAdministrators Full Control 

Settings

Navigation ItemSecurity SetLevel AssignmentLicense Required
About iMISAdministrators Full Control  
OrganizationAdministrators Full Control  
Contacts:   
  • General
  • Contact security
  • Communication preferences
  • Account management
  • Authentication
  • Open ID Connect
  • Social media
  • Client applications
Administrators Full ControlCustomers: 5 
  • Customer types
  • Activity types
Administrators Full ControlCustomers: 8 
  • Committee positions
Administrators Full ControlCustomers: 5 
  • Committee minutes
Administrators Full ControlCustomers: 5 
  • Relationship types
Administrators Full ControlCustomers: 5 
  • System options
Administrators Full ControlCustomers: 8 
Addresses:   
  • Address formats
  • States and provinces
  • Countries
Administrators Full ControlCustomers: 5 
CommunitiesAdministrators Full ControlCustomers: 5 
MembershipAdministrators Full ControlDues: 5 
Fundraising:   
  • General
  • Gift Aid (UK)
  • Tribute types
Administrators Full ControlFundraising: 5 
Events:   
  • General
  • Resource types
Administrators Full ControlEvents: 8 
Commerce:   
  • General
  • Order types
  • Product categories
  • Shipping
  • Zones
Administrators Full ControlOrders: 5 
  • System options
Administrators Full ControlOrders: 8 
Finance:   
  • General
  • Financial entities
Administrators Full ControlFinance: 8 
  • Due to/due from
  • GL accounts
  • Pay Central
  • Tax categories
  • Tax codes
  • Tax by zip code
  • VAT exceptions
Administrators Full ControlFinance: 5 
  • Terms
Administrators Full ControlFinance: 5 
  • Aging
Administrators Full ControlFinance: 8 
RiSE:   
  • Quick setup
  • Page builder configuration
  • Search configuration
  • Indexing
  • Process automation
  • Workflow configuration
  • Report formats
  • Recent history
Administrators Full Control  
Language translation:   
  • General
  • Translation cultures
Administrators Full Control Yes
General lookup tablesAdministrators Full ControlSystem: 5 
Email settingsAdministrators Full Control  
Change notificationsAdministrators Full Control  
AIAdministrators Full Control  
Settings AuditAdministrators Full Control  

Help

Navigation ItemSecurity SetLevel AssignmentLicense Required
DocumentationEveryone Full Control  
SupportEveryone Full Control  
Learning HubEveryone Full Control  
MarketplaceAll Staff Full Control  
Enhance iMISEveryone Full Control  

Did this page help you?