Platform Manager role, how is it determined if it's necessary?
Good afternoon,
It certainly seems like best practice to drastically limit the number of “platform managers” within an organization, though the “impersonate user” function is proving to be coveted by members of our Communications department as a means to see different user experiences on our site, and quickly get a glance at what parents of a 3rd grader, or 11th grader, might be seeing on a week to week basis.
How are other schools determining if a person or position should be granted platform manager rights? In this specific scenario, impersonating users is the only access that's actually desired.
Have you figured out a different way to allow members of your professional community to have better insight into the parent, student, or employee experiences in Blackbaud's products?
Thanks for any suggestions,
Dave
Comments
-
In our organization, only Senior Admin (4) and IT have impersonate rights. If someone that does have rights, needs to see what a parent/student/faculty view, they contact me and I screenshot or sit with them to show. Platform Manager (impersonate role) gives the rights to change and alter throughout the system. In my opinion this role should be given out sparsely or you lose data integrity. BB doesn't have change logs that we can accessed easily.
3 -
We have 5 people with the Platform Manager role.
We find it helpful for the a couple of other people involved in user support to be able to impersonate users, so we we cloned the role to create Platform Assistant Manager. That role has Impersonate User permission (plus a handful of others). Two people have that role.
3 -
@Dave Levin we're pretty strict with our permissions and only have two platform managers. We have 2 others with platform manager lite (a cloned role) that is very watered down.
3 -
We also have a cloned role for that access. All division assistants (Lower, Middle Upper, etc.) have access, as well as the nurses and a handful of other administrators/staff. No faculty. Impersonating preserves SSO connections as well so people really find it valuable to check a parent's forms status, for example, which is in 3rd party software but connected by SSO. Although impersonate allows you to edit data, if you restrict it to people who already have access to editing biographical data, then the risk isn't increased much. The other roles we have cloned from Platform Manager are: Calendar Manager, Emergency Notification Manager, Logo & Watermark Manager, Resource Board Editor, and Student & Profile Manager.
2 -
Seconding what folks have said about creating a new cloned role with limited rights. Keep in mind that impersonation can allow users to see information that would not otherwise be published to them. I try to be very cautious about who gets these kinds of permissions, but I think it's leagues better to clone and dilute than to have more than 3 Platform Managers in the system. Too many cooks in the kitchen.
2 -
How about creating test students and then having them be the parents of the test students?
1 -
We stopped using “test” students - everyone running student reports, mailing list and admission numbers had to remember to remove the test student account(s) or subtract that test student from that class of numbers. We went from 12 (1 for each grade) test students in EE to none - Test Z-fictional's were receiving a lot of mail at the school - lol
0 -
Wouldn't someone with “just” the impersonate ability given to them selectively be able to then impersonate a full-fledged administrator and have access to absoluately everything?
0 -
Geoffrey Goodfellow:
Wouldn't someone with “just” the impersonate ability given to them selectively be able to then impersonate a full-fledged administrator and have access to absoluately everything?
There are some safeguards in place to prevent that

https://kb.blackbaud.com/knowledgebase/articles/Article/101206
0 -
Good to know! Thanks, @Jamie Cross
0 -
We do the same thing. I feel impersonation should be used sparingly because it can be easily abused. BB does have some safeguards in place but they are not that great.
1 -
@Jamie Cross
There are not useful safeguards in place. Users 100% can impersonate an admin with more permissions and grant themselves additional permissions. It's a HUGE problem.0 -
Hi @Erin Aiston
Users with a cloned Platform Manager role cannot impersonate users with the Platform Manager role or users who have a cloned Platform Manager role. Only users with the full Platform Manager role can impersonate other users with the Platform Manager role or a cloned version of it.
2 -
More information about clones
Help:
Blog:
0 -
@Dave Levin - We have so quite a few cloned PM roles and it's not great, but there's no way around it. We have distributed much of our data administration the business units and you can't. use Core unless you are a PM or a cloned PM. Word out there is that BB is overhauling permissions next year, so let's hope this gets addressed.
Also - as a fail-safe, we gave all our senior leadership a cloned PM role with no tasks so that no one can impersonate them. We did this with Finance too, since we don't totally trust that users won't be able to impersonate a Billing Clerk.
The other issue we have with impersonate access, right now, is that you can impersonate parents and see their financial statements in Billing Management. This is a BIG deal for us and something BB thought they had resolved.
Thanks to everyone for sharing on this topic. Understanding roles in BB is a mind warp
0 -
@Dave Levin I should also have said - in order to get access as a cloned PM, you have to place a help desk ticket with the Information and Innovation team. The IT leadership evaluates the request and does a deep investigation into the implications. We then decide based on impact to other business units. Right now our primary concern is keeping financial data secure.
0 -
@Bryan Lorenzo What tasks do you assign to PM Lite?
0
Categories
- All Categories
- 6 Blackbaud Community Help
- 206 bbcon®
- 1.4K Blackbaud Altru®
- 393 Blackbaud Award Management™ and Blackbaud Stewardship Management™
- 1.1K Blackbaud CRM™ and Blackbaud Internet Solutions™
- 15 donorCentrics®
- 356 Blackbaud eTapestry®
- 2.5K Blackbaud Financial Edge NXT®
- 638 Blackbaud Grantmaking™
- 557 Blackbaud Education Management Solutions for Higher Education
- 3.1K Blackbaud Education Management Solutions for K-12 Schools
- 929 Blackbaud Luminate Online® and Blackbaud TeamRaiser®
- 82 JustGiving® from Blackbaud®
- 6.4K Blackbaud Raiser's Edge NXT®
- 3.6K SKY Developer
- 239 ResearchPoint™
- 117 Blackbaud Tuition Management™
- 163 Organizational Best Practices
- 237 The Tap (Just for Fun)
- 32 Blackbaud Community Challenges
- 25 PowerUp Challenges
- 3 (Open) Raiser's Edge NXT PowerUp Challenge: Standard Reports+
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Email Marketing
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Gift Management
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Event Management
- 3 (Closed) Raiser's Edge NXT PowerUp Challenge: Home Page
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Standard Reports
- 4 (Closed) Raiser's Edge NXT PowerUp Challenge: Query
- 772 Community News
- 2.9K Jobs Board
- 53 Blackbaud SKY® Reporting Announcements
- 47 Blackbaud CRM Higher Ed Product Advisory Group (HE PAG)
- 19 Blackbaud CRM Product Advisory Group (BBCRM PAG)








