Skip to main content

Permission Reference

Use this page to look up any permission shown on Agency Settings → Agency Config → Access Roles. The permission names appear exactly as they do in RAM. If you are new to roles, begin with Roles & Permissions.

How to read this page​

  • Each table explains what a permission allows, what it does not include, what it requires, and which permissions are often given with it.
  • Requires lists access that RAM automatically adds with the permission. For example, someone cannot edit information they are not allowed to view. A dash means there is no additional requirement. Often given with is a suggestion, not a requirement.
  • "Included in Agency User" means every member already has it, because every member holds the Agency User role. You can change that on the Agency User role.
  • Permissions with "any member" in their name are about records that belong to someone else. Members can always manage their own.
  • Agency Admins already have complete access, so they do not need these permissions assigned separately.
  • Point to a permission on the screen to see a short description.
  • New roles begin with no permissions. Select only the access the role needs.
  • The Access Roles card on a member's profile spells some permission names differently from the Access Roles screen (for example "Activities — Generate QR" for Generate activity QR codes). They are the same permissions.
The exceptions to "Requires"

Almost every permission requires the View permission of its own group. The exceptions: the Qualification permissions require View qualifications; View storage locations, Edit storage locations, View asset compliance, and the other asset permissions require View assets; the Archives permissions and Map access require nothing. Switching a View permission off asks whether to remove everything that depends on it; Cancel leaves everything as it was.

Table of Contents​


Permissions that do more, or less, than their name suggests​

PermissionWhat to know
View the audit logAlso opens the Agency Activity Log (every member's service entries) and the list of files a member has uploaded. Training Manager and Operations Manager include it.
Approve activity attendanceDoes nothing on its own: the Agency Activity Log it works in needs View the audit log. Also lets the holder add an entry for another member.
Edit assetsOpens Asset Types and Asset IDs in Agency Settings, and every choice under Asset Actions (see the asset table).
Check out assets, Transfer assetsWork without Edit assets, but only for the Asset Actions choices in the asset table.
Manage alert groupsControls all Groups: the ones alerts, activity invitations, and group chat use. Only Agency Admins and holders can change groups, from any screen.
Manage certification templatesAlso opens the certification expiration and Team Certifications reports.
Edit activitiesIncludes creating activities and seeing every activity. Does not include deleting, or the Activity Sign-In Sheet.
Edit animalsIncludes adding animals.
Edit animal medical recordsIncludes viewing, creating, and deleting them.
Delete animalsThe web app has no button for it, so on screen it does nothing.
Edit certifications for any memberIncludes renewing anyone's certification, and changing validated ones.
Delete members, Delete certifications for any memberAlso open the matching Archives tab and let the holder restore.
Create alert devicesThe only way, besides Agency Admin, to see access keys in full, every key and not only a new one.
Create members, Edit membersEach lets the holder give roles to members who are not administrators.
Manage chat groupsThe only way, besides Agency Admin, to add people to a group chat, even one the holder started.

Create alone, Edit alone, Delete alone​

What a role gets if it holds only one of the three. Each also includes its View permission.

ModuleCreate aloneEdit aloneDelete alone
ActivitiesSchedule activities; edit, cancel, and delete the ones they createdEdit or cancel any activity; also create activitiesDelete any activity
AssetsAdd assets, with a starting location; keep editing the ones they addedEdit any asset and make any Asset Actions choice; no addingArchive assets (the permission is Archive assets)
AnimalsAdd animalsEdit any animal; also add animalsNothing on screen
Animal medical recordsAdd recordsEdit records; also view, add, deleteDelete records
CertificationsAdd a certification for another memberEdit or renew anyone's, validated ones included; no addingDelete anyone's, validated ones included; restore deleted ones
DocumentsUpload documents and links; cannot change them, even their ownChange details of existing documents; no uploadingDelete documents
MembersAdd members, and choose their starting rolesEdit others' profiles and roles; no addingArchive and restore members
AlertsSend alertsResolve alerts others sentDelete alerts

Activities​

The calendar, scheduled activities, and attendance. See Event Calendar and Activity Sign-In Sheet.

PermissionWhat it allowsDoes not includeRequiresOften given with
View activitiesSee every activity in the calendar and list. Included in Agency User. Without it the Activities page still opens, but the member sees only the activities they are invited to or assigned to, in the list, the upcoming count, the dashboard's in-progress list, and the calendar feed. Their invitations, sign-up, and own check-in still work. Holders of Create activities or Edit activities see everything either way.Creating or changing activities.-The rest of this group
Create activitiesSchedule new activities and open the create and edit form. Edit, cancel, and delete the activities they created. See every activity, including invite-only ones.Editing, canceling, or deleting other people's activities.View activitiesEdit activities, Delete activities
Edit activitiesEdit or cancel any activity. Also create activities and see every activity, including invite-only ones.Deleting any activity, even their own (needs Delete activities; Create activities covers their own). Checking members in or out and the Activity Sign-In Sheet (needs Manage activity check-in and check-out).View activitiesDelete activities
Delete activitiesDelete any activity.Creating or editing.View activitiesEdit activities
Approve activity attendanceApprove or reject the activity entries members log, and add an entry for another member, both in the Agency Activity Log (the All members view of the service log).Opening the Agency Activity Log, which needs View the audit log. Without that, this permission has no screen to work on. Check-in screens.View activitiesView the audit log
Generate activity QR codesShow an activity's check-in QR code, from the activity's details window, so members can check themselves in.Checking people in or out by hand, and the sign-in sheet (needs Manage activity check-in and check-out).View activitiesManage activity check-in and check-out
Manage activity check-in and check-outCheck other members in and out, correct check-outs, force check-out an entry left open (with View the audit log to open the agency log where that button lives), and open the Activity Sign-In Sheet. Without it, members can only check themselves in and out.Creating or editing the activity itself.View activitiesGenerate activity QR codes

Without Create activities or Edit activities, the create and edit form does not open.


Alerts & Devices​

Emergency call-outs, who receives them, and the devices that carry them. These need the Rapid Emergency Alerting module on your plan. See Rapid Emergency Alerting.

PermissionWhat it allowsDoes not includeRequiresOften given with
View alertsOpen the Rapid Alerts call-outs page and see every active and recent alert in the agency, including past alerts, and open the Alert Response Analytics and Responder Alert Performance reports. Included in Agency User. Without it a member still sees the call-outs they were sent and the ones they sent, so responding keeps working. Receiving an alert on a phone does not depend on it.Sending, resolving, or deleting alerts.-Every other alert permission
Create alertsSend emergency alerts to the people and groups you choose (a member without it cannot send one). An incident's commander can also send an alert for their own incident without it.Resolving others' alerts or deleting them.View alertsEdit alerts
Edit alertsUse Update Status to resolve an alert. The button is available only to holders of this permission and administrators, even to the person who sent the alert.Sending new alerts.View alertsCreate alerts
Delete alertsDelete alerts.Anything else.View alerts-
Manage alert groupsCreate, edit, and delete the shared member Groups that alerts, activity invitations, and group chat all use, and open the Groups page in Agency Settings. Also add members to a group from the Team Roster, and from the member edit page (which also needs Edit members). See Groups.Sending alerts.View alertsCreate alerts
View alert devicesOpen the Access Keys and Devices tabs of the Rapid Alerts page and see who has a key and which device, with each key hidden except its last four characters.Seeing a full key, issuing keys, or revoking them.-Create alert devices, Delete alert devices
Create alert devicesIssue new access keys (device licenses) so a person or device can receive alerts. Sees every key in full, in the list and among keys not yet used.Removing keys.View alert devices-
Delete alert devicesRevoke (remove) a device license, which stops that device receiving alerts. Keys stay hidden.Issuing keys. Seeing a full key.View alert devices-

Seeing a full key needs Agency Admin or Create alert devices.

Who receives alerts is separate

Receiving an alert on a phone depends on that person's device license, not on a role.


Animals & Animal Medical​

Working-animal profiles and their health records. These need the Animal Management module.

PermissionWhat it allowsDoes not includeRequiresOften given with
View animalsOpen the Agency K9s list and any animal's page. Not in Agency User. Without it a member sees only the animals they handle (as primary handler or on an active handler assignment), and can always open those. Other animals are not found. Create, Edit, and Delete animals open the list too.Changing anything.-The rest of the animal permissions
Create animalsAdd working-animal records: the Add Animal button and form.Editing existing animals (needs Edit animals, or being the animal's primary handler).View animalsEdit animals
Edit animalsEdit any animal's profile and handler assignment, and add animals.The animal's medical records.View animalsView animal medical records
Delete animalsNothing on screen: the web app has no Delete button. To retire an animal, edit it and set its Status to Retired.Editing.View animals-
View animal medical recordsSee an animal's medications and health records. Without it a member cannot see them, even for their own animal.Changing them.-View animals
Create animal medical recordsAdd health records and medications.Editing or deleting.View animal medical records-
Edit animal medical recordsEdit health records and medications. Also covers viewing, creating, and deleting them.Animal profiles.View animal medical recordsView animals
Delete animal medical recordsDelete health records and medications.Editing.View animal medical records-

An animal's primary handler can always edit that animal's profile, without Edit animals. They cannot delete it (nobody can, in the web app).


Archives​

Deleted and archived records. See Archives for what each tab shows. The Archives menu item appears for a member who holds any permission in this section, or Delete members, Delete certifications for any member, or Delete qualifications, each of which opens its matching tab. Permanently deleting a member or certification is always Agency Admin only, and the button shows only to Agency Admins.

PermissionWhat it allowsDoes not includeRequiresOften given with
Manage deleted membersOpen the Members tab (titled Archived Members), see the list, and restore a member. Delete members does the same.Permanently deleting.-Delete members
Manage deleted certificationsOpen the Deleted view on the Certifications tab and restore a deleted certification. Delete certifications for any member does the same.Permanently purging it.-View archived certifications
View archived certificationsRead-only access to the Previous versions view: earlier versions of renewed certifications, kept as an audit trail.Restoring or changing anything.-Manage deleted certifications
View archived assetsRead-only access to the Archived Assets tab and archived asset details.Restoring an asset.-Manage archived assets
Manage archived assetsOpen Archived Assets and restore an archived asset to active inventory. Includes View archived assets.Permanently deleting.-Edit assets
Manage archived incidentsView archived incidents and restore one.---

A deleted Qualification waits in Archives → Qualifications. Anyone who holds Delete qualifications can see it there and restore it. See Qualifications.


Certifications & Training​

Member certifications, certification templates, and Qualifications. Every member can open the Certifications page and its My Certifications tab, and always sees their own Your Qualifications card, without any of these. See Certification Templates.

A member's own certifications. Until a certification is validated, its member can edit it, renew it, and delete it. Once it is validated (locked), the member can still renew it, but editing or deleting it takes Edit certifications for any member or Delete certifications for any member (or Agency Admin).

PermissionWhat it allowsDoes not includeRequiresOften given with
View certificationsSee certification records for everyone in the agency (the Team Certifications tab, team stats, expiring and expired lists), and read certification templates. Included in Agency User. Without it the member still opens Certifications and their own records, but the Team Certifications tab is hidden (Edit certifications for any member also shows it).Changing anyone else's record. Exports (need Export certifications for any member).-Every other certification permission
Create certifications for any memberAdd a certification record for another member, and show the "who is this for?" choice. Members can always add their own, except from a Restricted template, which only this permission (or Agency Admin) can add.Editing existing records (needs Edit certifications for any member).View certificationsEdit certifications for any member
Edit certifications for any memberEdit anyone's certification, including validated or locked ones, renew anyone's, and change a record's status.Adding records for others. Validating (needs Validate certifications).View certificationsValidate certifications
Delete certifications for any memberDelete anyone's certification, including locked ones, and restore deleted ones from the Archives Certifications tab.Permanently purging deleted records (Agency Admin only).View certificationsManage deleted certifications
Manage certification templatesCreate, edit, delete, import, and export the certification templates the agency uses. Also needed to run the certification expiration and Team Certifications reports under Agency → Reports.Records created from them.View certifications-
Validate certificationsSign off on a member's certification. After it is validated, its member can no longer edit or delete it. Also unlock a verified record for editing, from the record panel or the Team Certifications row menu; the record goes back to pending review and must be verified again.Editing the record.View certificationsEdit certifications for any member
Import certifications for any memberBulk-import certification records from a spreadsheet. See Bulk Records Import/Export.Exporting.View certificationsCreate or Edit certifications for any member
Export certifications for any memberDownload agency-wide certification records as a spreadsheet. Members can always see their own without it.Viewing records in the app.View certifications-
View qualificationsOpen the Qualifications tab: list Qualifications, see their requirements and who holds them. Without it the tab is hidden.Changing anything.-The other Qualification permissions
Create qualificationsCreate a new Qualification and its requirements, and duplicate one.Assigning it to members.View qualifications-
Edit qualificationsEdit a Qualification: rename it, change its requirements, switch it on or off.Assigning it to members.View qualifications-
Delete qualificationsDelete a Qualification. It leaves the Qualifications tab and every member's list at once, and waits 30 days in Archives → Qualifications, where a holder can restore it.Destroying it sooner (Agency Admin only).View qualifications-
Manage qualification membersAssign or remove a Qualification for members. Members cannot enroll themselves.Defining the Qualification.View qualifications-

Communications & Chat​

The in-app chat. Chats that belong to a Group (Agency Settings → Agency Config → Groups) are managed there instead.

PermissionWhat it allowsDoes not includeRequiresOften given with
View chatOpen chat and see the conversations the member is in. Included in Agency User. Without it chat does not open, direct messages included.Starting group chats.-Every other chat permission
Create chatStart a new group chat. Included in Agency User.Direct messages between two people are not controlled by this.View chat-
Delete chatA moderator permission: delete a group chat they belong to, and remove other members' messages in group chats they belong to, including chats that belong to a Group. It adds nothing in a one-to-one direct message, where each person can delete only their own messages. The chat's creator, a message's sender, and Agency Admins can still do these without it. Included in Membership Manager.Deleting a chat that belongs to a Group (done by editing the Group). Chats the member is not in.View chat-
Manage chat groupsFor group chats the member belongs to, even ones someone else started: rename the chat, remove members, and change its picture. Also the only way to add members, even to a chat the member started.Chats tied to a Group, which are managed on the Groups screen. Chats the member is not in.View chat-

Documentation​

The agency document library. These permissions control opening, adding, and copying documents. Every plan includes the library.

PermissionWhat it allowsDoes not includeRequiresOften given with
View documentsOpen the library and read documents in the in-app viewer. Included in Agency User. Without it the library shows a lock and the message "Your role does not include the document library".Saving or printing a copy.-Every other document permission
Create documentsUpload new documents and add links.Changing existing ones, even ones they uploaded (needs Edit documents), and deleting.View documentsEdit documents
Edit documentsChange a document's or link's title, category, description, or web address.Uploading new ones (needs Create documents).View documentsCreate documents
Delete documentsDelete documents.Uploading.View documents-
Download documentsSave a copy of a document to their device. Without it the Download and Open-in-New-Tab buttons are hidden and the download is refused. For a PDF with the personalized watermark on, the saved copy is the member's own marked copy.Viewing in the app.View documents-
Print documentsUse the Print button in the viewer. Without it the button is hidden.It hides the button only; a member who can see a document can still print it from the browser menu.View documents-
Docs — Access originalOpen a watermarked PDF as it was uploaded, without the stamp, to view, print, or (with Download documents) save one clean copy. It does not change the document's setting, and every use is recorded in the audit log.Turning the watermark off.View documentsDownload documents
Docs — Manage watermarkingTurn the personalized watermark on or off for a document, when uploading or afterwards. The change is recorded in the audit log.Viewing the unmarked original.View documentsCreate documents or Edit documents

Out of the box, only View documents is held by a starter role (Agency User). Only Agency Admins can upload, edit, delete, download, or print until you add those permissions to a role. If members should be able to save copies, add Download documents to Agency User. The two "Docs —" permissions are named that way on the Access Roles screen too.

Personalized watermark​

Each PDF in the library has a Personalized watermark setting. When it is on, every copy that leaves the library, whether viewed, downloaded, or printed, is stamped diagonally across every page with the viewer's email, your agency, and the time. The viewer tells the member their copy is marked.

  • The original is never changed. The stamp is added to the copy sent out. Turning the setting off means copies go out unmarked from then on; copies already saved or printed keep their mark.
  • New PDFs start without a watermark unless your agency turns it on under Agency Settings → Security → Access & Sessions → Agency documents. PDFs that were in the library before this setting existed keep their watermark until someone turns it off.
  • One clean copy without changing the setting: a member with Docs — Access original chooses View original in the viewer, confirms, and sees the unmarked file under a banner. The audit log records who viewed or downloaded an original and when.
  • A PDF that cannot be watermarked is not shown unmarked. Password-protected or damaged PDFs are refused on upload with the watermark on, with the choice of uploading an unprotected copy or turning the watermark off for that document.
  • PDFs only. Word, Excel, and image files are not watermarked.
A watermark is a deterrent, not protection

It discourages passing a document on and shows whose copy it was. It does not stop copying: a determined member can still screenshot a page or retype it.


Inventory & Assets​

Equipment and supplies. See Asset Management.

Asset Actions: what each choice takes. Check out assets and Transfer assets work without Edit assets, but only for these choices:

Asset Actions choiceWhenWhat it takes
PersonThe asset is in storage or has no locationCheck out assets
PersonThe asset is signed out to another memberTransfer assets
StorageReturning an asset a member holdsCheck out assets, Transfer assets, or being the member who holds it
StorageMoving an asset between storage locationsTransfer assets
MobileLoading it on a mobile assetTransfer assets
Maintenance, RetireAny assetEdit assets
Any choiceThe asset is under maintenance or retiredEdit assets
Return, on an assignment to a member, or under Agency Gear Held on My AssetsAn asset signed out to a memberCheck out assets, or the member it is signed out to

Edit assets and Agency Admins can make every choice.

PermissionWhat it allowsDoes not includeRequiresOften given with
View assetsSee the asset list, each asset's details and value, and run the asset valuation report. Included in Agency User. Without it the Assets page does not open, including My Assets, which sits on that page.Changing anything. The compliance dashboard and reports (need View asset compliance and Export asset compliance).-Every other asset permission
Create assetsAdd new assets (New Asset, quick add, and the wizard), choosing where each starts, and keep editing the assets they added: details, photo, documents, and contents, with no time limit.Editing an asset someone else added (needs Edit assets). Archiving, even their own (needs Archive assets). Moving, assigning, or transferring an asset after it is added, and its registration, insurance, and usage records. Importing assets needs both Create assets and Edit assets. Creating storage locations.View assets-
Edit assetsEdit any asset, make any Asset Actions choice, add records, and open Asset Types and Asset IDs in Agency Settings.Adding assets (needs Create assets) and archiving (needs Archive assets).View assets-
Archive assetsArchive an asset. Assets are archived (kept, read-only), not erased.Restoring (needs Manage archived assets).View assetsManage archived assets
Check out assetsSign an asset out to a member from storage, and return an asset signed out to a member.Moving an asset from one member to another, between storage locations, or onto a mobile asset (needs Transfer assets). Maintenance and Retire (need Edit assets).View assetsTransfer assets
Transfer assetsMove an asset from one member to another, between storage locations, or onto a mobile asset. Also covers returning an asset a member holds.Signing an asset out from storage to a member (needs Check out assets). Maintenance and Retire (need Edit assets).View assetsCheck out assets
View storage locationsSee the storage-location tree (facilities, areas, sections, bins) and choose a location when placing an asset. Included in Agency User. Without it the Storage Locations page is hidden.Changing it.View assetsEdit storage locations
Edit storage locationsCreate, rename, move, and delete facilities, areas, sections, and bins. Includes View storage locations.Creating assets: Create assets does not grant this.View assetsView storage locations
Create log entries for any assetRecord a maintenance, inspection, repair, calibration, or cleaning entry on any asset.Editing or deleting existing entries, which stays with Edit assets so the history cannot be rewritten.View assets-
View asset complianceOpen the Asset Compliance dashboard: what is overdue, due soon, on track, or has no schedule.Exporting.View assetsExport asset compliance
Export asset complianceDownload the Asset Compliance Status PDF (Agency → Reports).Viewing the dashboard. View assets alone is not enough for this report.View assetsView asset compliance
Export assets for any memberDownload the full asset list (with subcomponents) as a spreadsheet, and the Excel asset template.Viewing the list in the app.View assets-

Map access​

Maps work as a ladder rather than separate switches. A role holds one access level, each including the ones before it, plus one separate switch. The map features have their own documentation coming.

OptionOne-line summary
View (included in Agency User)Open maps and see the map content you may view.
ContributeView, plus add map objects and edit the ones you created.
Edit map contentContribute, plus edit others' objects, organize folders, import tracks, and create maps.
Manage mapsEdit map content, plus archive or delete any map and start or end map operations.
Restrict map objects and manage who may see themA separate switch: limit who may see a map object. It does not reveal restricted objects the person was not given.

Membership​

Member profiles, the team roster, and invitations. See Team Management.

PermissionWhat it allowsDoes not includeRequiresOften given with
View membersOpen the team roster and see other members' profiles. Included in Agency User. Without it the roster and profiles are hidden, but member pickers (groups, certification "who for", activity invitations and check-in, access keys) still work and show names and photos only, never email. The chat member list does not show email addresses either.Changing anything.-Every other membership permission
Create membersTurns on the roster's Add member button, and lets the holder choose starting roles (never Agency Admin).Editing existing members. Importing members or exporting the roster (Agency Admins only).View membersEdit members, Resend member invitations
Edit membersTurns on the roster's Edit button (a member can always edit their own row). Edit other members' profiles and photos, and change the roles of any member who is not an administrator (never Agency Admin).Changing an administrator's roles. Changing their own roles.View members-
Delete membersTurns on the roster's Archive button. Remove (archive) members, and open the Archives Members tab and restore them.Permanently deleting a member (Agency Admin only).View membersManage deleted members
Resend member invitationsResend the invitation email to a member who has not yet signed in, with the Resend Verification button on their profile card (Agency Admins see it too). That is all it covers.Adding members.View membersCreate members
Create members and Edit members can hand out roles

Create members lets someone choose roles when adding a member, and Edit members lets them change the roles of an existing one. Either way they can give any non-administrator any role you have created, strong ones included, so treat each as nearly as sensitive as managing roles. Keep them to people you trust with that.

There is no permission for promoting someone to administrator. Only an Agency Admin can assign the Agency Admin role.


Operations & Incidents​

Incident features have their own documentation. Listed here so you know what each switch is.

PermissionOne-line summary
View incidentsSee incidents. Included in Agency User.
Create incidentsStart incidents.
Edit incidentsEdit incident details.
Delete incidentsDelete incidents.
Close incidentsClose out an incident.
Manage incident check-insCheck people in and out of an incident and correct their times.
View lost-person questionnairesSee subject cards and print the questionnaire, medical section withheld. Included in Agency User.
View lost-person questionnaires, including medical detailsEverything above, plus the medical section.
Collect and edit lost-person questionnairesAdd a subject and fill in or change the questionnaire, medical section withheld.
Collect and edit lost-person questionnaires, including medical detailsThe whole questionnaire, including medical.

System & Audit​

PermissionWhat it allowsDoes not includeRequiresOften given with
View the audit logOpen the audit log (read-only), the Agency Activity Log (every member's service entries), the Training Hours and Activity Overview reports, and the list of files a member has uploaded. Also see the Audit & Logs retention settings, read-only.Changing records. Deleting service-log entries (Agency Admins can; a member can delete their own while it is still editable). Changing retention settings (Agency Admins only). Exporting (needs Export audit logs).-Approve activity attendance
Export audit logsExport the audit log as CSV or JSON. Without it the export items are disabled with a tooltip. Training Manager and Operations Manager include it.Viewing the log.View the audit log-

Where the audit log is: the Audit Logs item in the left menu. It is unavailable for a member without View the audit log. Agency Settings → Security → Audit & Logs is a different page, which sets how long records are kept.

Audit log access is sensitive

The audit log records detailed activity across the agency. Give View the audit log deliberately, and Export audit logs even more so, since an export leaves RAM.