Purpose Statement
The role-based permissions feature in the Business Portal allows administrators to control what users can access and manage based on their responsibilities.
The updated permissions structure provides six specialized roles across three categories, allowing businesses to assign users the appropriate level of access for administration, ITM reporting, permit management, and view-only activities.
Multiple roles can be assigned to the same user, allowing access to be tailored to the user's responsibilities.
Background Information
Previously, Business Portal users had two basic roles. The updated role-based permissions system expands this structure to six specialized roles:
- Admin – Add/Manage AHJs
- Admin – User Access Control
- ITM Manager
- ITM User
- Permit Manager
- Viewer
These roles are organized into three categories: Admin, ITM, and Permit.
Multiple roles can be assigned to a single user. This allows administrators to provide different levels of access based on the work the user performs.
Existing users do not need to be manually reconfigured as part of the change. Existing permissions are automatically migrated to the new role-based permissions system so users retain their previous access.
Required Permissions
To add users and manage their roles and permissions, the user must have the:
- Admin – User Access Control role
This role allows the user to manage team members and their permissions within the Business Portal.
Video
User Roles and Permissions
The Business Portal provides six roles that can be assigned based on the user's responsibilities.
Admin – Add/Manage AHJs
Allows the user to connect and manage Authority Having Jurisdiction (AHJ) relationships.
Admin – User Access Control
Allows the user to manage team members and their permissions.
ITM Manager
Provides full ITM access, including:
- Viewing reports
- Submitting reports
- Purchasing ITM Credits
ITM User
Provides ITM access for submitting reports but does not allow the user to purchase ITM Credits.
Permit Manager
Provides full access for fire department permit management.
Viewer
Provides read-only access to the work types used by the business.
Step-by-Step Guide
1. Navigate to Users
Sign in to the Business Portal.
Select the First Due logo to open the navigation menu.
- Select Admin.
Select Users.
- The Users page displays the existing users associated with the business.
2. Add a New User
- From the Users page, select Add User.
The new user window opens.
3. Enter the User's Information
Enter the applicable information for the new user, including:
- Password
- First Name
- Middle Name, if applicable
- Last Name
- Name Suffix, if applicable
- Primary Phone Number
You can also upload an image for the user.
4. Select the User's Roles
Locate the roles section and select the appropriate role or roles based on the access the user requires.
Available roles include:
- Admin – Add/Manage AHJs
- Admin – User Access Control
- ITM Manager
- ITM User
- Permit Manager
- Viewer
A user can be assigned multiple roles.
5. Combine Roles When Needed
Assign multiple roles when a user needs different levels of access for different responsibilities.
For example, a user could be assigned an ITM User role for ITM-related responsibilities along with a Viewer role for permit-related access.
This allows the user to perform their assigned ITM functions while maintaining read-only access for permits.
6. Set the User's Account to Active
After selecting the appropriate roles, set the user's account to Active if they should have access immediately.
7. Create the User
- Review the user's information.
- Confirm that the appropriate roles have been selected.
- Verify the account's active status and credential settings.
- Select Create.
The new user is added to the Business Portal with the selected roles and permissions.
Best Practices
- Follow the principle of least privilege. Assign only the roles necessary for the user's job responsibilities.
- Use ITM Manager selectively. This role includes the ability to purchase ITM Credits in addition to other ITM functionality. Use ITM User when a user needs to submit reports but should not purchase credits.
- Limit User Access Control to appropriate administrators. Users with the Admin – User Access Control role can manage team members and permissions.
- Assign multiple roles when responsibilities overlap. A user does not need to be limited to a single role.
- Use Viewer for read-only needs. Assign the Viewer role when a user needs visibility into applicable work types without management access.
- Review roles before creating the account. Confirm that each user's permissions match their responsibilities before granting access.
- Periodically review user access. Update assigned roles when a user's responsibilities change.
Troubleshooting & FAQs
How many roles are available in the Business Portal?
There are six specialized roles: Admin – Add/Manage AHJs, Admin – User Access Control, ITM Manager, ITM User, Permit Manager, and Viewer.
Can I assign more than one role to a user?
Yes. Multiple roles can be assigned to the same user to provide the appropriate combination of access.
What is the difference between ITM Manager and ITM User?
The ITM Manager has full ITM access, including the ability to purchase ITM Credits. The ITM User can perform ITM reporting functions but cannot purchase credits.
Which role allows a user to manage other users and their permissions?
The Admin – User Access Control role allows management of team members and their permissions.
Which role allows a user to manage AHJ relationships?
The Admin – Add/Manage AHJs role allows the user to connect and manage Authority Having Jurisdiction relationships.
What does the Viewer role allow?
The Viewer role provides read-only access to the work types used by the business.
Will existing users lose access because of the new role-based permissions?
No. Existing permissions are automatically migrated to the new permissions system so users retain the access they previously had.
Can I make a new user active immediately?
Yes. When creating the user, you can set the account to active and choose to send the user's credentials.