Personas and Roles

Security roles control which tasks users can access. Roles enable schools to group similar users together, including for communication purposes.

A user's personas are based on their enrollment, current roles, and past roles. For example, a user with the "Past teacher" role maintains the "Faculty" persona.

To add or remove a persona from a user, edit the user's:

Constituent personas and solution capabilities automatically group tasks for quick access in the "persona menu."

  • Constituent Persona: Parent, Faculty, Alum, Student and Friend.

  • Capabilities (formerly "products" or "applications"): Academics, Enrollment managements, Extracurricular, School website, Core.

Note: The persona and capability names are hard-coded into the system and can't be edited.

Pages, fields, and other functions (such as Conduct pages in Academics) correspond to security tasks. Schools configure which tasks are enabled for each security role. For example, a user likely needs the conduct manager and attendance manager roles to view and use conduct information.

Every user that logs into the system has the all school role by default. This is how Blackbaud Education Management identifies all users as a collective group at once.

Constituent Personas

Constituent personas are based on constituent or employee roles.

Super Users

Users with the platform manager role are sometimes considered "super users" because most tasks are enabled for them by default. Access to some sensitive data isn't included by default though, such as offering courses or viewing medical data in Blackbaud Student Information System.

By default, platform managers can also impersonate any other user. During impersonation, they can view data or take action as if they were that user. For example, they might impersonate an academic group manager to access the task for offering courses. However, some sensitive data, such as medical data, is still hidden during impersonation. If someone else needs to impersonate (view and do) or view as (view only) another user, then schools can enable those functions for other roles too.

Platform managers can enable security roles and tasks for all users, including themselves. For example, they could grant themselves the school nurse role, which is required to view medical data.

Thus, we recommend you grant this role sparingly. We discourage cloning it.

Tip: Consider reviewing help about roles and tasks for SKY API.