Roles List and Tasks

Tasks determine what each user can see and do in Education Management.

Each task may be enabled or disabled for various security roles. For example, multiple admin roles may be able to create emergency bulletins.

Users can be members of multiple roles. If a task is enabled for at least one of the user's roles, then the user has access to all data and actions for that task even if the task is disabled for one of the user's other roles.

Platform managers can assign roles to users. To view which roles are enabled for a user, you must have the platform manager role with the User profile (53405) or Manage login (53788) task enabled.

Configure Tasks

View task details including:

  • a description of what the task enables users to see and do.

  • whether the task is enabled or not enabled.

  • a list of other roles that have the task enabled.

Enable a task for a role

Disable a task for a role

Cloned Roles

Platform managers can clone a security role to assign it to a user. When you clone the role, you can omit some of the tasks from the original role. However, you can't add additional roles to the clone.

Clone an existing role to create a new role.

Delete a cloned role.

Note: Clones of the platform manager can't impersonate non-clone-platform managers; they can't grant themselves additional security access. We recommend schools grant the platform manager role sparingly. Most employees who are responsible for keeping user profile data updated should have the contact card manager role instead.

Multi-Factor Authentication (MFA)

When MFA is enforced for a user's security role, they must authenticate with two or more verification factors, such as

  • a password and a code received via SMS text message

  • or a password and a code from a mobile authentication app.

See  require MFA for a security role.

Role Reports

Security roles determine which reports their members can access, view, and run. To view which reports each role can access, see role reports.

Role Membership

Platform managers can view and manage which users belong to a role.

In Bulk

For an Individual

History

  • View a history of which roles a user has had over time. See user role history.

  • View a log of when users were added to or removed from a role's membership, and who made each change. See role audit history.