Security & User Access
FiscFlow has two different ideas of "role," and understanding the difference is the key to managing access. This page explains how permissions are granted, how people sign in, and the admin tools for keeping access correct.
Two kinds of role
| Assignment role | Security role | |
|---|---|---|
| What it is | A workflow role you hold through an employee assignment. | The actual permission set - what screens, data, and actions you can use. |
| Controls | Who approves what, and site/account scoping via filters. | What you're allowed to see and do in the app at all. |
| Set by | Capability switches (can approve, can view work items…). | Permission settings on the role record. |
An assignment role links to one or more security roles. When you hold that assignment role, its security roles become part of your permissions. So assignment roles decide workflow behavior; the security roles behind them decide what you can actually access.
How you get your permissions
Your effective access is merged from everything that applies to you:
- the security roles behind each assignment role you hold, plus
- any supporting roles assigned to you directly.
FiscFlow combines these into a single merged role - the permission set you actually log in with. When roles or assignments change, the merged role is rebuilt so your access stays correct (see Applying access changes).
Under the hood there are three kinds of security role: regular roles you define and assign, user-specific roles that tailor a single person's access, and the automatically built merged role above. You manage the first two; FiscFlow maintains the merged one.
Special permissions
| Permission | Grants |
|---|---|
| Administrator | Full access - bypasses visibility and most gates. Grant sparingly. |
| Can Import Data | Shows the Import Data action. Typically admins only. |
| Can View Audit Trail | Opens a record's audit trail - the full history of changes. |
| Can Restore From Audit Trail | Ability to roll a record back to a prior state. |
| Can Edit Model | Access to the application-model / UI-customization tools. Advanced; admins only. |
Separately, which assignment roles a non-administrator may hand out is limited - you can only assign roles that are marked creatable from a role you already hold. This keeps delegation controlled.
Signing in & new users
Users sign in with Google, Microsoft, or a FiscFlow username and password - see Signing in & navigating. A person's access is tied to their employee record.
- New employees receive the district's Default Security Role (set in System Options) and are prompted to set a password on first login.
- Single sign-on (Google/Microsoft) can create a user automatically the first time they sign in - but only when a default role is configured and their email domain matches your district. Otherwise they see a message to register or ask for an invitation.
If someone gets this on sign-in, their account isn't set up yet (or their email domain doesn't match). An administrator should create their employee record - or add a direct login - before they try again.
Admin tools
| Tool | What it does |
|---|---|
| Add Direct Login | Give selected employees a username/password login. Passwords must be at least 10 characters with upper- and lower-case, a digit, and a symbol; users are prompted to change it on first sign-in. |
| Merge Roles | Rebuild a user's effective permissions after changing their roles or assignments (see below). |
| Import / Export Roles | Move a security role's full definition - including its permissions - between environments or districts, as a file. |
Applying access changes
Because access is a merged role, editing a security role or a user's assignments marks that user's permissions as needing a rebuild. Use Merge Roles on the affected employee to apply the change. (Districts using the automated security service have this handled for them; if it isn't configured, you'll see a message when a merge is requested.)
This is separate from data visibility: security roles decide what features and record types you can use; visibility and approval filters then decide which specific records within those you can see and act on.