Edmissa docs

Permissions

Understand how access affects pages, actions, and records.

Permissions control what a user can see and do in Edmissa. Most admins manage permissions through roles instead of changing individual permission keys.

Use this reference when you need to understand what a role setting means before assigning it to users.

Permission model

LayerWhat it controls
UserThe account that signs in to Edmissa.
RoleA reusable set of permissions assigned to one or more users.
Data access levelWhether a role has no access, view access, manage access, or full control for a data area.
Data scopeWhich records the access level applies to.
System settingWhether a role can manage configuration or administration areas.
LocationWhich branch or operating location the user belongs to.
SupervisorThe user's reporting relationship for team visibility.

Users can have more than one role. Their effective access is the combination of all assigned roles.

Data access levels

Access levelMeaningTypical use
No AccessThe user cannot use that data area.Hide work that is outside the role.
View OnlyThe user can view records within scope.Reviewers, managers, or read-only support.
Manage RecordsThe user can create, edit, and work with records within scope.Daily users who own assigned work.
Full ControlThe user has broad control, usually including delete, export, assignment, approval, or management actions when available.Managers and trusted admins.

Full Control usually requires Team or All scope. Use it only when the user should have broad operational authority.

Data scopes

ScopeMeaning
OwnRecords created by the user.
AssignedRecords assigned to or created by the user.
TeamRecords in the user's team or location context.
AllRecords across the organization.

Assigned is the safest starting point for counselors and consultants. Team is usually for managers. All is usually for owners, directors, and central admins.

Data areas

AreaWhat access affects
StudentsStudent profiles and student details.
Student RelationshipsRelationships between student profiles when your workspace uses linked student profiles.
Student GroupsStudent groups or related records when your workspace groups student work together.
ApplicationsApplication records, workflow stages, and application actions.
DocumentsUploaded files, document review, upload, download, export, and deletion when allowed.
TasksFollow-ups, assigned work, task completion, and task assignment when allowed.
ApprovalsApproval requests, approval decisions, and rejection actions when allowed.
CommentsComments and discussions on records.
Timeline & ActivityActivity history and timeline visibility.
Incoming LeadsLeads captured from public forms, webhooks, and integrations.
Support ReportsIn-app support or issue reports.

System setting areas

System setting access controls administration and configuration, not only data visibility.

CategorySettings
System AdministrationWorkspace settings, locations, users, roles, audit logs, debug tools, security, and compliance.
Configuration & CustomizationFields, form templates, document types, pipelines, checklists, automation, notification templates, reports, and dashboards.
CommunicationEmail templates, SMS configuration, webhooks, and API keys.
Advanced FeaturesBulk operations, data export, and global search.

Give User Management and Role Management only to trusted admins. A user who can manage roles can change the access of other users.

Role templates

TemplateUse it for
Business ExecutiveBroad access for owners and senior leaders.
Team ManagerTeam-level operational control for managers.
Case Handler/SpecialistAssigned-work access for counselors, consultants, and specialists.
Operations CoordinatorLimited coordination access for support users.

Templates are starting points. Review access levels, scopes, and system settings before assigning a role to real users.

Guardrails

GuardrailWhy it matters
Users need at least one roleA user without a role has no useful working access.
Active users normally need at least one locationLocation access helps Edmissa show the right records and assignments.
Multiple roles combine accessA narrow role plus a broad role may grant more access than expected.
Admin access is protectedThe Admin role should not be treated as a normal editable role.
Roles with assigned users cannot be deletedRemove or replace the role on users before deleting it.
Sensitive changes may require identity confirmationUser, role, password, activation, and deletion actions are privileged.
GuideUse it for
UsersConfigure account status, roles, locations, supervisors, passwords, and sessions.
RolesCreate and maintain reusable permission sets.
Permissions and scopeUnderstand how access levels, scopes, system settings, and combined roles work.
LocationsUnderstand how locations affect access and assignments.
Access and permissions troubleshootingDiagnose missing pages, disabled actions, and records that users cannot see.