Roles define access and authorized actions for each ACADEM user.
2 type of roles
“Business” roles
These correspond to the user’s function within the institution, giving different access to members of the administration (DA) and faculty members (FAC).
DA (Academic manager)
This is a static role assigned/removed from TrackingOne.
Accesses all ACADEM menus, and can view and manage all data. Can modify and validate data added by all faculty members, manage links between contacts, modify referential data and edit reports.
❌The DA role gives more rights than the other roles. It is therefore not advisable to add the DA_RO, DEPT_MGR, DEPT_MGR_RO, FAC_ASSIST roles to a DA user to avoid conflicts.
DATA_SUPERUSER
This is a static role assigned/removed from TrackingOne.
Can physically delete a teacher from the institution’s database along with all associated data. Its rights are limited to this delete screen.
✅This role gives additional authorisation to the DA role: you must therefore be a DA to become a DATA_SUPERUSER.
❌Since the DA role gives maximum rights to the user, it is not advisable to add the following permissions for a DA/DATA_SUPERUSER in order to avoid conflicts of rights: DA_RO, DEPT_MGR, DEPT_MGR_RO, FAC_ASSIST.
DA_RO (Ready-only Academic manager)
This is a static role assigned/removed from TrackingOne.
Can view all Faculty menus and data on ACADEM, but cannot modify them. Can consult all CVs and generate reports.
❌ It is not advisable to combine the roles of DA and DA_RO, as the DA role will have more rights.
❌ It is not advisable to add a dynamic DEPT_MGR_RO permission to DA_RO, as the DA_RO role will have more rights. This combination may therefore generate rights conflicts.
✅ The DA_RO role can be combined with the DEPT_MGR and FAC_ASSIST roles, which allow certain profiles to be edited.
DPT_MGR (Department manager)
This is a dynamic role set up in the contact’s profile on ACADEM > add a relationship > type of relationship ‘Department manager’. The role is assigned for a period limited by a start and end date.
Can view all the data for faculty members in their department. Does not have access to institutional data or accreditation reports.
❌It is not advisable to combine this role with an AD role (which has more rights) to avoid conflicts.
✅ This role can be combined with all other roles, as it is only attached to one or more academic departments.
DPT_MGR-RO (Read-only Department manager)
This is a dynamic role set up in the contact’s profile on ACADEM > add a relationship > type of relationship ‘(Read-Only) Department manager’. The role is assigned for a period limited by a start and end date.
Can view all the data for teachers in their department, but cannot modify it. Does not have access to institutional data or accreditation reports.
❌ It is not advisable to associate this role with a DA_RO role, which will have more visibility, to avoid conflicts.
FAC (Faculty member)
This is a static role assigned/removed from TrackingOne
Can view and edit all data in their own profile. Cannot validate contributions, nor modify information relating to the institution or accreditations in ‘personal information’. ⚠️ The faculty member must exist in the faculty roster on ACADEM to access his/her data.
✅ The FAC role can be associated with a DA, DA_RO or DEPT_MGR role. In this case, the user can view/edit their own profile as a FAC, and view other data as a DA.
FAC_ASSIST (Assistant)
This is a dynamic role set up in the contact’s profile on ACADEM > add a relationship > type of relationship ‘assistant to’. The role is assigned for a period limited by a start and end date.
Can see all the data in the profile of the faculty member to whom he/she is linked.
⚠️ The assistant must exist as a contact in ACADEM and the faculty member whom he/she is linked must exist in the faculty roster to access his/her data.
System roles
Define authorized actions on solution settings (modification of screen rules, addition of users, access to documentation, etc.).
T1_USER
Allows you to be involved in workflows such as those dedicated to data imports.
✅It is advisable to assign this role to all users, to enable them to be involved in workflows.
T1_MANAGER
Allows you to administer users in TrackingOne: create user accounts, modify their roles and extensions.
T1_ADMIN
Provides access to modify the interface (hide fields, modify labels, edit help texts, screen rules, etc.) and import data from ACADEM.
On TrackingOne, this role is used to administer workflows and reports in TrackingOne.
T1_SUPERADMIN
Allows complete administration of TrackingOne: add, edit, delete users, audit trail (find out who has connected to ACADEM), monitoring.
You can also reset a user password from TrackingOne.
✅ It is advisable to limit the number of T1_SUPERADMIN as much as possible. Only a T1_SUPERADMIN role can assign or remove the same role from someone else.
❌ _SCREEN_CONFIG roles should not be assigned as they cause conflicts in screen rules.
Role extensions
Each role must have a role extension:
- Category extensions: determine the scope of possible actions for system roles.
- Source System container extensions: define the scope of possible actions within the solution for business and system roles.
