Welcome to the AfterSchool21 Help Center

Find answers fast: Ask a question, search for keywords, or explore articles below.

Permissions by Security Role Report Guide

permissions_security_role_infographic_98dba1b3b86e42ae96708b022029.png

Overview & When to Use

The Permissions by Security Role report maps every defined security role to its access level across all system permission categories. It answers questions like: What can a Session Leader edit? Can a Partner view activity lists? 

Typical audience: System administrators, program coordinators, and others configuring or auditing role-based access.

Most useful when:

  • Onboarding a new customer and confirming role configurations match expectations.
  • Auditing access after a role change or support escalation.
  • Training staff on what each role can and cannot do within the platform.

How to Read the Report

  • Start with the role rows — each row represents one security role (e.g., Data Entry, District Administrator, Evaluator, Partner, Program Director, Session Leader, Site Coordinator, System Administrator
  • Read across the columns — columns represent individual permission categories grouped under broader sections including activitiesdashboardformsnotifications, and organizations. The report scrolls far to the right for more categories.
  • Use color as a quick signal — green cells indicate edit-level access, yellow/orange indicate view-only access, and red cells indicate denied access. This allows rapid visual scanning without reading every cell.
  • Focus on red cells first — denied permissions are the most operationally significant, especially for roles like Partner (denied nearly all activity permissions).
Permissions by Security Role.jpg

Key Metrics

Metric What It Measures How it is Calculated Notes
Section Top-level functional area of the platform System-defined labels that group related subsections. Not calculated. Additional sections may exist beyond the visible columns; scroll horizontally to view all.
Subsection A specific screen or feature within a Section — the granular point where access is granted or denied. Each subsection maps to a platform page or function and appears as a column. Not calculated. Examples: 
activities_dropin
forms_intake
notifications_list
Permissions Value The access level a Security Role has for a given Subsection. Pulled directly from the system's role configuration for each Role–Subsection pair. These are set by Pathwise; the default configuration can be changed upon request. Green = allow-edit
Yellow = allow-view 
Red = deny
System Administrator has allow-edit across all subsections; Partner is the most restricted.

 

Statuses, Colors, and Alerts

  • 🟢 allow-edit (green): The role has full read and write access to that permission area.
  • 🟡 allow-view (yellow/orange): The role can view but not modify records in that permission area.
  • 🔴 deny (red): The role has no access to that permission area.
  • There are no additional alert flags or status codes visible in this report beyond these three permission levels.

Notes, Limitations, and Related Reports

  • This report reflects permissions as currently configured in the system; it does not show historical permission changes or audit logs.
  • There is a column for each subsection as well as a column to the right of a section’s subsection. This column’s permission value indicates whether the access that role has for the entire section. In the example provided, the Partner role is unable to access any part of the Activities section of the system.

Report Filters (How to Slice the Data)

The filter panel for this report includes the following options:

  • Section — Filters the permission columns by their top-level section grouping (e.g., activities, notifications). Use this to focus on one functional area at a time.
  • SubSection — Filters within a section to a more specific grouping. Useful when a section contains many permission columns.
  • Tab — Filters by the tabs within participant record (address, participation, notes, etc.) 
  • Product — Filters the report to show permissions for a specific product only. Other Pathwise products may be available depending on system configuration and customer purchases.
  • Role — Filters the report to show only the selected security role(s). This is the most commonly used filter when reviewing permissions for a specific role during onboarding or a support inquiry.

All filters support “In List” selection, meaning multiple values can be selected simultaneously. A Reset button clears all active filters and Apply executes the filter selection.

To apply filters (not available for all reports), use the filter icon available at the top right of the report header. The filter options shown in this report are the same for all users.

To filter by additional fields that are not available on-screen, export the table to Excel, turn on filters for the header row (Data > Filter), and use Excel’s filter dropdowns. For a quick tutorial, see Microsoft’s “Filter data in a range or table” video on https://support.microsoft.com/.

Updated

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request