Every team member holds one role, and the role decides what they can see and do. A role is edited under Account Settings > Permissions > Custom Roles and has four parts: a Scope of support (which participants the person can open), Has PHI access and Has Legal access (whether they see medical and legal fields), and one level per module, chosen from None, Viewer, Supporter, or Administrator. Account owners have broader access than custom roles, but protected records and workflow restrictions can still prevent an action. Participants are labelled Clients, Students, Residents, or Explorers depending on your account type, and the participant role has no module settings at all.
Who can do this, and where
Web app only, under Account Settings > Permissions, on the Custom Roles tab.
Anyone whose Account Settings module is Viewer or Administrator can open the page and read each role. Only Super Admins and roles whose Account Settings module is Administrator see Add Custom Role and the edit menu.
Family accounts have no Permissions tab. Their roles keep the defaults for family accounts.
Steps to add or edit a role
Open the menu under your profile photo or initials, choose Account Settings, then Permissions.
On the Custom Roles tab, click Add Custom Role. To change an existing role, open the menu at the right of its name and choose Edit Custom Role.
Enter a Name. Names must be unique within your account.
For a new role, choose Similar permissions as. The new role starts as a copy of that role's scope, PHI and Legal settings, and module levels. Pick a General Admin role to make an administrator-type role, or the supporter role (Mentor, Supporter, or Support) to make a supporter-type role. This cannot be changed later.
Choose the Scope of support: Restricted - Only own records, Designated - Assigned participants, or Full - All account records.
Tick Has PHI access and Has Legal access if the role should see those sections of participant profiles.
Under Module Access Controls, pick a level for each module.
Click Create Role or Update Role.
Assign people to the role from their profile: Edit Profile & Settings, then the Access tab, then the Role field.
The menu next to a role also offers Reset to Default, which puts the role's scope, PHI, Legal, and module levels back to the built-in defaults for its type, and Delete Custom Role, which appears only when nobody holds the role.
Scope of support
Scope decides which participants a person can find and open. Module levels decide what they can do once there.
Restricted: only their own records. The participant list shows nobody, so use it for roles that should not work with participants at all.
Designated: the participants listed under Supported Participants on the person's Access tab, or under Supporters on the participant's Access tab. This is the default for the supporter role.
Full: every participant in the account. This is the default for General Admin.
What the four levels mean
Each level is a fixed set of abilities. Not every module offers every level.
None: grants no module permissions. Personal records, shared records, and account-owner access can follow separate rules.
Viewer: generally grants viewing rather than module-management permissions. It is not a universal read-only guarantee: Forms response actions follow separate rules, described below. For most modules this opens the module's section on a participant's profile; for Account Settings, Announcements, Employers, and Mood Navigator it opens the module from the main navigation instead. Calendar and Time open from both.
Supporter: a working-access preset whose abilities vary by module. Many allow creating and editing participant records; Assessments, Forms, Groups, and Team differ. Use the module breakdown below rather than assuming the same actions everywhere.
Administrator: the highest module preset, usually including main-navigation access and deletion. Record-specific restrictions still apply.
Some modules use the levels differently:
Participants: Supporter opens the participant list and profiles within the person's scope. Administrator additionally allows adding, editing, and importing participants, and its delete permission is what allows discharging a participant.
Team: Supporter allows viewing and editing existing team members. Administrator additionally allows inviting and deleting team members. Editing participants' profiles also needs this module's edit permission.
Groups: Supporter opens Groups from the navigation and shows membership. Administrator manages groups. There is no Viewer level.
Reports: None or Administrator only. Administrator shows the Reporting link; which reports appear is set on the Report Access tab.
Pathway Authorization Invoices: None or Administrator only, because invoices carry billing data.
Levels offered by each module
Modules tied to a feature your account does not have are not listed in the editor.
Module | Levels offered |
Account Settings | None, Viewer, Administrator |
Announcements | None, Viewer, Administrator |
Assessments | None, Viewer, Supporter, Administrator |
Calendar | None, Viewer, Supporter, Administrator |
Documents | None, Viewer, Supporter, Administrator |
Employers | None, Viewer, Administrator |
Employment Tracking | None, Viewer, Administrator |
Forms | None, Viewer, Supporter, Administrator |
Goals | None, Viewer, Supporter, Administrator |
Groups | None, Supporter, Administrator |
Mood Navigator | None, Viewer, Administrator |
Notes | None, Viewer, Supporter, Administrator |
Participants | None, Supporter, Administrator |
Pathway Authorization Invoices | None, Administrator |
Pathway Authorizations | None, Viewer, Supporter, Administrator |
Pathways | None, Viewer, Supporter, Administrator |
Reports | None, Administrator |
Routines | None, Viewer, Supporter, Administrator |
Team | None, Supporter, Administrator |
Time | None, Viewer, Supporter, Administrator |
Notes and documents also carry their own access settings on each record, chosen when the record is created or edited. A role's Notes or Documents level lets people into the module, and the record's own access setting then decides whether they can open that particular note or document. To keep a participant from seeing a note in the mobile app, set the participant role to no access on that note.
What access means in each module
Use this section when choosing a level for a role. These are the levels selected in the role editor; built-in roles can have additional permissions, as explained under Account-type defaults and Limits below. None selects no module permissions. A module level does not expand someone's scope of support, enable an unavailable feature, or remove a record's own restrictions.
Account Settings
Viewer: read account settings, including the roles and permissions page.
Administrator: change account settings and manage custom roles and their permissions.
Supporter: not offered. Give Viewer to someone who needs to check configuration without changing it.
Announcements
Viewer: open Announcements and read announcements available to the person.
Administrator: create, edit, schedule, publish, unpublish, and delete announcements.
Supporter: not offered. Choose Administrator for team members responsible for sending organizational announcements.
Assessments
Viewer: view assessments reached through an accessible participant's profile.
Supporter: adds assessment editing permission; it does not grant creation of new assessment templates or access to the main assessment library.
Administrator: manage the assessment library, including creating, editing, and deleting assessments.
Starting, sharing, and completing a response also depends on the assessment's settings and the response's permissions and status.
Calendar
Viewer: open the main Calendar and participant calendars and view accessible events.
Supporter: adds creating and editing events. Event ownership and participant relationships also affect access and deletion; this is not a blanket prohibition on deleting an event someone created.
Administrator: adds the module's delete permission. The person's scope and the event's access rules still matter.
Documents
Viewer: access documents through participant profiles, subject to each document's access settings.
Supporter: adds uploading and editing participant documents.
Administrator: adds the main Documents library and the module's delete permission.
A participant document's own access settings also control viewing, editing, and deletion. Documents generated from forms have additional form-access and deletion restrictions. Selecting Administrator here does not make every document unrestricted.
Employers
Viewer: open the employer directory and read employer information.
Administrator: add, edit, and delete employers and manage employer information.
Supporter: not offered in the dropdown. The built-in CRP supporter role has additional employer permissions by default.
Employment Tracking
Viewer: view employment records through an accessible participant's profile.
Administrator: create, edit, and delete employment records, including job dates, pay, employer, and supervisor details.
Supporter: not offered in the dropdown, even though a built-in supporter role can have employment-management permissions. Review the warning about saving built-in roles below.
This module controls participant employment records; Employers separately controls the employer directory.
Forms
Viewer: access forms from participant profiles. This does not make form responses read-only. A team member who can reach a participant's response page still sees Fill Form and can create a response. Eligible responses can also be edited; response creation and editing do not use the Forms module's create/edit flags.
Supporter: also provides participant-profile access. Although this preset contains create/edit flags, it does not add a response-writing boundary beyond Viewer and does not allow creating or editing form templates.
Administrator: adds main Forms library access and permission to create, edit, and delete form templates.
Response actions follow separate rules: account and feature access, participant access, form restrictions, approval, signatures, and response status still matter. Awaiting Approval and Approved responses are locked; a Denied response can be edited only by its responder when otherwise permitted. A sub-account cannot edit or delete a shared form owned by its umbrella account.
Do not choose Forms: Viewer as a way to prevent a team member from submitting or editing responses. Contact Equip if you need response access that is strictly read-only.
Goals
Viewer: view goals for accessible participants.
Supporter: create and edit participant goals and work with their waypoints and progress, subject to the relevant record permissions.
Administrator: adds the module's delete permission and main-module access.
Scope of support still determines whose goals the person can work with.
Groups
Supporter: open Groups and view accessible groups and membership.
Administrator: create, edit, and delete groups and manage membership and chat settings.
Viewer: not offered.
Group chat has separate conversation and message permissions. Message authors, group leaders, and authorized moderators can have message actions that are different from their ability to edit the group itself.
Mood Navigator
Viewer: open Mood Navigator and view accessible mood information.
Administrator: adds creating, editing, and deleting mood records, subject to record-specific permissions.
Supporter: not offered in the dropdown. The built-in supporter role can have participant-level Mood Navigator permissions that do not match any dropdown option.
Mood authorship and scope can affect editing. Notification subscriptions and schedules are separate settings, not permission levels.
Notes
Viewer: open notes through participant profiles, subject to the note's access settings.
Supporter: create and edit participant notes when the note's permissions allow it.
Administrator: adds the main Notes area and the module's delete permission.
Private notes, notes to oneself, and the access controls saved on individual notes have additional rules. A module level alone does not describe access to every note.
Participants
Supporter: open the participant list and profiles within the person's scope of support.
Administrator: adds participant creation and import permissions. Participant discharge uses this module's delete permission, with additional administrator rules.
Viewer: not offered.
Profile editing and participant deletion also involve Team permissions. PHI and Legal access separately control sensitive profile sections.
Pathways
Viewer: view pathways through accessible participant profiles.
Supporter: create, edit, and delete participant-level pathway records where the record's rules allow it.
Administrator: adds main Pathways library access and management.
Authorizations and invoices have their own module settings. Pathways access alone is not a substitute for those permissions.
Pathway Authorizations
Viewer: view authorizations for accessible participants.
Supporter and Administrator: both dropdown presets include view, create, edit, delete, and navigation permissions for authorizations.
Participant access and record protection still apply. An invoiced authorization cannot be deleted simply by increasing the role's level.
Pathway Authorization Invoices
Administrator: grants invoice-module view, create, edit, delete, and navigation permissions, subject to invoice and participant-access rules.
Viewer and Supporter: not offered; the dropdown offers only None and Administrator.
Invoice access is separate from Pathways and Pathway Authorizations. Review it explicitly for staff who handle billing.
Reports
Administrator: enables the Reporting area.
Viewer and Supporter: not offered; the dropdown offers only None and Administrator.
Then configure Permissions > Report Access. Tick the individual reports this role should be allowed to run; the module level alone does not select those reports.
Routines
Viewer: view routines through accessible participant profiles.
Supporter: create, edit, and delete participant-level routines where permitted.
Administrator: adds the main Routines library and library management.
Built-in CRP supporters have broader routine-library access. Family accounts have different defaults, described below.
Team
Supporter: view and edit existing team members where permitted.
Administrator: adds the Team area and permissions to invite and delete team members.
Viewer: not offered.
This module also participates in participant profile editing and participant deletion. Check both Participants and Team when diagnosing a missing profile action.
Time
Viewer: read accessible time entries from Time and participant profiles.
Supporter: create entries and edit or delete their own entries, within the applicable participant and account rules.
Administrator: can also edit and delete other people's entries within the role's permitted scope.
Increasing Time access does not expand the person's caseload or bypass the account's time-entry rules. The feature must be enabled for the account.
Account-type defaults
These apply when a role is created and when you choose Reset to Default.
CRP accounts: the supporter role gets full Employers and Routines access, and has PHI and Legal access turned on.
Family accounts: Announcements, Assessments, Time, Employers, Employment Tracking, Forms, Goals, Groups, Pathways, Pathway Authorizations, Pathway Authorization Invoices, and Reports are off for every role. Routines stays on: administrators manage routines and supporters view them.
All other accounts: General Admin is Administrator on every module with Full scope; the supporter role is Designated scope, has no PHI or Legal access, and works at the participant level in each module.
Limits and what the errors mean
Saving a role rewrites every module to the level shown in its dropdown. The built-in supporter role has a few modules with more abilities than any single level represents, and the editor shows the closest matching level. In particular the default supporter role shows Mood Navigator and Pathway Authorization Invoices as None and Employment Tracking as Viewer even though it can record moods, work with invoices, and edit employment from a participant's profile. Saving the role for any reason, even renaming it, writes those lower levels back. If a default role works as you want, leave it alone, and use Reset to Default to recover the built-in abilities.
"Default roles cannot be deleted." The roles your account came with are marked Default and cannot be removed.
"Roles assigned to users cannot be deleted." Move everyone to another role from their Access tab first. The Delete Custom Role option is hidden while anyone holds the role.
"Name has already been taken" on the form: another role in your account uses that name.
No Add Custom Role button or edit menu. Your Account Settings module is Viewer, or your account is a family account.
A role is permanently administrator-type or supporter-type, decided by the role chosen under Similar permissions as. Only supporter-type roles show the Enable Web Access and Web Access Enabled toggles; administrator-type roles always have web access.
Default roles cannot be renamed or changed to a different type. Their permissions can be edited, subject to the rewrite warning above.
Report access is separate. Setting Reports to Administrator shows the Reporting link, but each report must still be ticked for the role on the Report Access tab.
FAQ
What is the difference between Viewer, Supporter, and Administrator?
Viewer generally provides read access, but Forms responses are an exception: Viewer does not prevent filling or editing eligible responses. Supporter provides working access, with different actions in each module; see the module-by-module breakdown above. Administrator is the highest module preset and usually includes main-navigation access and deletion; record-specific restrictions still apply. Not every module offers every level; Groups, Participants, and Team have no Viewer, and Reports and Pathway Authorization Invoices have only None and Administrator.
Which permission lets someone discharge a participant?
The delete permission of the Participants module, which only the Administrator level includes. Administrators can also discharge any participant they can open. Deleting a participant instead needs the delete permission of the Team module.
Can a supporter see every participant?
Yes, if the role's Scope of support is Full. Create a custom role based on the supporter role, set Scope of support to Full, and assign the person to it. Their web access stays optional because the role is still a supporter-type role.
Why did a role lose abilities after I edited it?
Saving writes the level shown in each dropdown, and the built-in supporter role holds a few abilities the dropdowns cannot express. Its Mood Navigator and Pathway Authorization Invoices dropdowns show None and Employment Tracking shows Viewer, so saving removes those abilities. Use Reset to Default on the role to restore them.
Why is a module missing from the role editor?
Modules only appear when their feature is enabled for your account, for example Pathways, Forms, Assessments, Goal Tracking, Mood Navigator, Groups, Employment Tracking, or Time. Family accounts also do not show the Permissions page. Contact the Equip team to enable a feature.
What do Has PHI access and Has Legal access control?
Has PHI access shows the Medical Information section of participant profiles, including Medicaid number and disability types, and the Equip Card tab. Has Legal access shows the Legal Information section, including the Social Security number, guardianship, and any custom fields placed there. Super Admins have both; General Admin has both; the supporter role has both only on CRP accounts.
Why can a team member with Notes set to Administrator not open an older note?
Every note and document carries its own access settings, written for the roles that existed when the record was created. A new role is not on those records, so it opens the module and finds them empty. Records created after the role exists include it. Edit an older note's access settings to add the role.
Can I give web access to someone in a General Admin role but not the mobile app?
Yes. Web access is always on for administrator-type roles. Turn off Mobile Access Enabled on the person's Access tab to keep them out of the mobile app.
Related
What do the role names mean?
Control which reports each role can run
Mobile App Permissions Reference
Inviting Your Team
Assigning Participants to Supporters
