Skip to main content

Set what each role can see and do

Custom roles under Account Settings > Permissions combine a scope of support, PHI and Legal access, and a level of None, Viewer, Supporter, or Administrator per module; what each level allows, what each module offers, and the pitfalls when editing a role.

Written by MaryGrace Flores

Every team member holds one role, and the role decides what they can see and do. A role is edited under Account Settings > Permissions > Custom Roles and has four parts: a Scope of support (which participants the person can open), Has PHI access and Has Legal access (whether they see medical and legal fields), and one level per module, chosen from None, Viewer, Supporter, or Administrator. Super Admins are not governed by these settings; they can do everything. Participants are labelled Clients, Students, Residents, or Explorers depending on your account type, and the participant role has no module settings at all.

Who can do this, and where

  • Web app only, under Account Settings > Permissions, on the Custom Roles tab.

  • Anyone whose Account Settings module is Viewer or Administrator can open the page and read each role. Only Super Admins and roles whose Account Settings module is Administrator see Add Custom Role and the edit menu.

  • Family accounts have no Permissions tab. Their roles keep the defaults for family accounts.

Steps to add or edit a role

  1. Open the menu under your profile photo or initials, choose Account Settings, then Permissions.

  2. On the Custom Roles tab, click Add Custom Role. To change an existing role, open the menu at the right of its name and choose Edit Custom Role.

  3. Enter a Name. Names must be unique within your account.

  4. For a new role, choose Similar permissions as. The new role starts as a copy of that role's scope, PHI and Legal settings, and module levels. Pick a General Admin role to make an administrator-type role, or the supporter role (Mentor, Supporter, or Support) to make a supporter-type role. This cannot be changed later.

  5. Choose the Scope of support: Restricted - Only own records, Designated - Assigned participants, or Full - All account records.

  6. Tick Has PHI access and Has Legal access if the role should see those sections of participant profiles.

  7. Under Module Access Controls, pick a level for each module.

  8. Click Create Role or Update Role.

Assign people to the role from their profile: Edit Profile & Settings, then the Access tab, then the Role field.

The menu next to a role also offers Reset to Default, which puts the role's scope, PHI, Legal, and module levels back to the built-in defaults for its type, and Delete Custom Role, which appears only when nobody holds the role.

Scope of support

Scope decides which participants a person can find and open. Module levels decide what they can do once there.

  • Restricted: only their own records. The participant list shows nobody, so use it for roles that should not work with participants at all.

  • Designated: the participants listed under Supported Participants on the person's Access tab, or under Supporters on the participant's Access tab. This is the default for the supporter role.

  • Full: every participant in the account. This is the default for General Admin.

What the four levels mean

Each level is a fixed set of abilities. Not every module offers every level.

  • None: the module is hidden and its records cannot be opened.

  • Viewer: read only. For most modules this opens the module's section on a participant's profile; for Account Settings, Announcements, Employers, and Mood Navigator it opens the module from the main navigation instead. Calendar and Time open from both.

  • Supporter: view, create, and edit records reached from a participant's profile. Pathways, Pathway Authorizations, and Routines also include delete at this level. Assessments at this level allows view and edit but not creating new assessment templates.

  • Administrator: everything, including opening the module from the main navigation and deleting records.

Some modules use the levels differently:

  • Participants: Supporter opens the participant list and profiles within the person's scope. Administrator additionally allows adding, editing, and importing participants, and its delete permission is what allows discharging a participant.

  • Team: Supporter allows viewing and editing existing team members. Administrator additionally allows inviting and deleting team members. Editing participants' profiles also needs this module's edit permission.

  • Groups: Supporter opens Groups from the navigation and shows membership. Administrator manages groups. There is no Viewer level.

  • Reports: None or Administrator only. Administrator shows the Reporting link; which reports appear is set on the Report Access tab.

  • Pathway Authorization Invoices: None or Administrator only, because invoices carry billing data.

Levels offered by each module

Modules tied to a feature your account does not have are not listed in the editor.

Module

Levels offered

Account Settings

None, Viewer, Administrator

Announcements

None, Viewer, Administrator

Assessments

None, Viewer, Supporter, Administrator

Calendar

None, Viewer, Supporter, Administrator

Documents

None, Viewer, Supporter, Administrator

Employers

None, Viewer, Administrator

Employment Tracking

None, Viewer, Administrator

Forms

None, Viewer, Supporter, Administrator

Goals

None, Viewer, Supporter, Administrator

Groups

None, Supporter, Administrator

Mood Navigator

None, Viewer, Administrator

Notes

None, Viewer, Supporter, Administrator

Participants

None, Supporter, Administrator

Pathway Authorization Invoices

None, Administrator

Pathway Authorizations

None, Viewer, Supporter, Administrator

Pathways

None, Viewer, Supporter, Administrator

Reports

None, Administrator

Routines

None, Viewer, Supporter, Administrator

Team

None, Supporter, Administrator

Time

None, Viewer, Supporter, Administrator

Notes and documents also carry their own access settings on each record, chosen when the record is created or edited. A role's Notes or Documents level lets people into the module, and the record's own access setting then decides whether they can open that particular note or document. To keep a participant from seeing a note in the mobile app, set the participant role to no access on that note.

Account-type defaults

These apply when a role is created and when you choose Reset to Default.

  • CRP accounts: the supporter role gets full Employers and Routines access, and has PHI and Legal access turned on.

  • Family accounts: Announcements, Assessments, Time, Employers, Employment Tracking, Forms, Goals, Groups, Pathways, Pathway Authorizations, Pathway Authorization Invoices, and Reports are off for every role. Routines stays on: administrators manage routines and supporters view them.

  • All other accounts: General Admin is Administrator on every module with Full scope; the supporter role is Designated scope, has no PHI or Legal access, and works at the participant level in each module.

Limits and what the errors mean

  • Saving a role rewrites every module to the level shown in its dropdown. The built-in supporter role has a few modules with more abilities than any single level represents, and the editor shows the closest matching level. In particular the default supporter role shows Mood Navigator and Pathway Authorization Invoices as None and Employment Tracking as Viewer even though it can record moods, work with invoices, and edit employment from a participant's profile. Saving the role for any reason, even renaming it, writes those lower levels back. If a default role works as you want, leave it alone, and use Reset to Default to recover the built-in abilities.

  • "Default roles cannot be deleted." The roles your account came with are marked Default and cannot be removed.

  • "Roles assigned to users cannot be deleted." Move everyone to another role from their Access tab first. The Delete Custom Role option is hidden while anyone holds the role.

  • "Name has already been taken" on the form: another role in your account uses that name.

  • No Add Custom Role button or edit menu. Your Account Settings module is Viewer, or your account is a family account.

  • A role is permanently administrator-type or supporter-type, decided by the role chosen under Similar permissions as. Only supporter-type roles show the Enable Web Access and Web Access Enabled toggles; administrator-type roles always have web access.

  • Default roles cannot be renamed or changed to a different type. Their permissions can be edited, subject to the rewrite warning above.

  • Report access is separate. Setting Reports to Administrator shows the Reporting link, but each report must still be ticked for the role on the Report Access tab.

FAQ

What is the difference between Viewer, Supporter, and Administrator?
Viewer is read only. Supporter can view, create, and edit records from a participant's profile, and for Pathways, Pathway Authorizations, and Routines it can also delete. Administrator can do everything, including opening the module from the main navigation and deleting records. Not every module offers every level; Groups, Participants, and Team have no Viewer, and Reports and Pathway Authorization Invoices have only None and Administrator.

Which permission lets someone discharge a participant?
The delete permission of the Participants module, which only the Administrator level includes. Administrators can also discharge any participant they can open. Deleting a participant instead needs the delete permission of the Team module.

Can a supporter see every participant?
Yes, if the role's Scope of support is Full. Create a custom role based on the supporter role, set Scope of support to Full, and assign the person to it. Their web access stays optional because the role is still a supporter-type role.

Why did a role lose abilities after I edited it?
Saving writes the level shown in each dropdown, and the built-in supporter role holds a few abilities the dropdowns cannot express. Its Mood Navigator and Pathway Authorization Invoices dropdowns show None and Employment Tracking shows Viewer, so saving removes those abilities. Use Reset to Default on the role to restore them.

Why is a module missing from the role editor?
Modules only appear when their feature is enabled for your account, for example Pathways, Forms, Assessments, Goal Tracking, Mood Navigator, Groups, Employment Tracking, or Time. Family accounts also do not show the Permissions page. Contact the Equip team to enable a feature.

What do Has PHI access and Has Legal access control?
Has PHI access shows the Medical Information section of participant profiles, including Medicaid number and disability types, and the Equip Card tab. Has Legal access shows the Legal Information section, including the Social Security number, guardianship, and any custom fields placed there. Super Admins have both; General Admin has both; the supporter role has both only on CRP accounts.

Why can a team member with Notes set to Administrator not open an older note?
Every note and document carries its own access settings, written for the roles that existed when the record was created. A new role is not on those records, so it opens the module and finds them empty. Records created after the role exists include it. Edit an older note's access settings to add the role.

Can I give web access to someone in a General Admin role but not the mobile app?
Yes. Web access is always on for administrator-type roles. Turn off Mobile Access Enabled on the person's Access tab to keep them out of the mobile app.

Related

  • What do the role names mean?

  • Control which reports each role can run

  • Mobile App Permissions Reference

  • Inviting Your Team

  • Assigning Participants to Supporters

Did this answer your question?