RMS Security Management

RMS Security Management

RMS Security Management

RMS Security Management

RMS Security

Management

Correspondence regarding this publication should be directed to:

Executive Information Services

1396 NE 20th Avenue, Suite 100

Ocala, FL 34470

Phone: (208) 580-0400

FAX: (775) 201-7575

Internet Mail: support@goeis.net

Contents

EXECUTIVE INFORMATION SERVICES ...................................................................................... 0

CONTENTS ______________________________________________________________ 1

SECURITY MANAGEMENT .......................................................................................................... 2

OVERVIEW ______________________________________________________________ 2

SECURITY PERMISSION MANAGEMENT ................................................................................... 3

SECURITY OBJECTS AND PERMISSIONS .................................................................................. 3

SECURITY OBJECTS_________________________________________________________ 4

SECURITY PERMISSIONS _____________________________________________________ 4

ROLES AND USER PERMISSIONS ________________________________________________ 6

BUILDING THE USER’S ACCOUNT ________________________________________________ 7

ASSIGNING PERMISSIONS TO THE USER’S ACCOUNT ___________________________________ 7

Method 1: Assigning Permissions Manually to the User’s Account ....................................................8

METHOD 2: ASSIGNING PERMISSIONS TO THE USER’S ACCOUNT BY ROLE _____________________ 9

METHOD 3: ASSIGNING PERMISSIONS TO A USER’S ACCOUNT WITH AN EXISTING ROLE ___________ 10

WORKING WITH ROLES _____________________________________________________ 11

HOW TO BUILD AND PERMISSION A SYSTEM ROLE ___________________________________ 11

Building the Role ....................................................................................................................... 11

Assigning Permissions to the Role ............................................................................................... 13

Quick Features – Batch Updating ................................................................................................ 13

ADJUSTING ROLES OR USER’S PERMISSIONS _______________________________________ 13

COMPLETE LISTING OF SECURITY OBJECTS .......................................................................... 14

RMS SECURITY MANAGER ___________________________________________________ 14

CIVIL.NET ______________________________________________________________ 15

CITATION PAYMENT _______________________________________________________ 15

FACILITY VISITOR ________________________________________________________ 15

RMS M2 MANAGEMENT ____________________________________________________ 16

MIS MANAGER __________________________________________________________ 16

RMS ASSET MANAGER _____________________________________________________ 17

RMS ALARM CLIENT _______________________________________________________ 17

RMS ENTRY ____________________________________________________________ 17

RMS MANAGER __________________________________________________________ 20

RMS PERSONNEL MANAGER__________________________________________________ 21

RMS PROPERTY MANAGER __________________________________________________ 22

RMS QUERY ____________________________________________________________ 22

RMS REPORT VIEWER _____________________________________________________ 25

RMS STATE REPORTING ____________________________________________________ 25

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 Page |1

Phone: (208) 580-0400 | FAX: (775) 201-7575

Security Management

Overview

The EIS RMS-2 product incorporates an expansive security management and provisioning service. The

Security Management component functions as the universal gatekeeper for all system resources and was

specifically designed to insulate the back-end system services and database from unauthorized intrusion.

As such whenever a user launches a common RMS-2 module, the application first contacts the Security

service to determine if the requesting user is recognized and has been assigned sufficient permissions to

access the requested application. If the user is authenticated, the extended system connection

information along with the users defined permissions are returned to the client application and enabled

for the user to proceed. If the user fails authentication, a notification to the user is provided. The user

credential can be pulled from the Windows logon, to eliminate the application-level Username/password

log-on approach.

While the basic operations of Security Management are comprised of a specific set of low-level system

controls operating outside of the normal view of the user, the Security component also maintains the

comprehensive listing of all user permissions. As each user is authenticated, Security Management

retrieves the related system permissions prepares the session accordingly. These permissions cover all

aspects of system operations, including what applications the users can access, enforces control of

specific capabilities within the programs and determines what data the users can either view or modify.

In a multi-agency system deployment Security Management, will enforce cross agency data sharing rules.

Access to the Security Management and permissions settings are provided through

the Security Management application which is separate from the other RMS

applications. It is accessible directly from the application directory or from a desktop

shortcut (if previously defined). It is recommended that the Security Management

application not be widely distributed along with the basic system modules, and only

be installed on those user’s workstations who have a specific reason to access.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 Page |2

Phone: (208) 580-0400 | FAX: (775) 201-7575

Security Permission Management

Security Management utilizes several

newer concepts to facilitate the rapid

assignment of system privileges to users,

and the management of those permissions

as required by the agency or as new

features are added. In reviewing the

security model from the bottom up, all

permissions are assigned as a collection of

functions associated with a “Security

Object”. Many of the system modules

contain multiple security objects as

appropriate. The Security Objects are

grouped and applied to either a specific

user account or to an agency Role

definition. Through this combination of

security objects and specified permission

the agency can develop very granular

access privileges in accordance with

agency policy. Once applied the

permissions become active and will be

applied to the related user at their next log-on event. Permissions can be added or modified at any time.

There are two specific concepts that must be understood to properly utilize the Security Management to

achieve the agency’s security directives, and to effectively manage the automated routing of system

reports as configured within the “EIS Workflow Engine”. These are the “Roles and Users” relationship

and the configuration of specific permissions for each user or user class (Role).

Security Objects and Permissions

The RMS-2 utilizes a multi-tiered security definition for each of the system modules and various specialty

components and functions. This multi-tiered approach is based upon the System Security Objects and

associated Permissions defined for each user or role. A Security Object is a specific set of defined

permissions associated with a system module. While the Security Object does not inherently provide any

specific permissions for a user, it must be present in the user’s profile before access permissions can be

granted. When a user attempts to access a portion of the system, the system will first check to

determine if the security object exists in the user’s profile. If the system cannot locate the Security

Object in the users profile the request will be denied immediately. If the Security Object is present and

no permissions have been assigned the request will also be denied. Only when the combination of

Security Object and associated permissions are present will the user be allowed to proceed.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 Page |3

Phone: (208) 580-0400 | FAX: (775) 201-7575

Security Objects

Each Security Object is listed with a set of descriptive data to identify the relationship of the object to the

overall system. These fields include.

Application: Identifies the RMS-2 workstation application that will use the object. The application is

what the user will launch to access the system. For example, if you wish to grant a user access to the

Asset Management Program for entering and modifying information, you must first assign the appropriate

security object – in this case the “RMSASSETMANAGEMENT” object.

Module: The module specifies either the functional module (within an application that supports multiple

modules – such as RMS Entry), or a “PROGRAM” definition for some of the stand-alone programs

provided within the system. For example, since the Asset Management software is provided as a stand-

alone program, the application would be listed as:

“RMSASSETMANAGEMENT” and the module would be “PROGRAM”

Object: Specifies the specific portion of the module security affected by this Security Object. These may

be entire modules (and may be defined as “PROGRAM” or “ACCESS”) or they may support a specific

function within a module (e.g. access to the “EXPUNGE” function within the RMS Manager application)

Description: Simply provides a textural description of the associated Security Object to assist the user

in identifying the appropriate item.

Security Permissions

The actual permissions that allow access into the applications are contained within each of the security

objects. Applied permissions determine what privileges and capabilities will be available to each user as

they utilize the system. Once a Security Object has been associated with a user or role, the associated

permissions become visible. There is a common set of permissions provided within the system, however

not all modules will support all the available permissions. For example, an inquiry module (one that only

allows the retrieval of data) will not display an add, update or delete permission because data

modification is not supported in an inquiry only module, and the presence of these permissions would

only serve to confuse the user.

Activating the permissions within each Security Object is as simple as checking the permission box or

setting a variable value. Standard system permissions include:

ACCESS: A checkbox component that establishes the base level permission and controls whether the

user can launch the related application. This permission supersedes all other permissions, in that if the

user is not allowed to launch the application, no other function would logically be available to the user.

An “Access” permission must be provided if the user is to be able to perform any function within the

application. An “Access” permission will be in all security objects.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 Page |4

Phone: (208) 580-0400 | FAX: (775) 201-7575

ADD: A checkbox component that controls whether the user can create new records within the related

application. If enabled for an application or program the user will be allowed to create new records

within the module. An “Add” permission will only be presented in security objects associated with data

entry programs and will not appear in any of the inquiry applications.

UPDATE: A checkbox component that controls whether the user can change an existing record within

the related application at its most basic level. If enabled for an application or program the user will be

allowed to update or modify records within the module. This permission can be superseded by the

module “Write Level” permission and/or the integral report restriction capability. An “Update” permission

will only be presented in security objects associated with data entry programs and will not appear in any

of the inquiry applications.

PRINT: A checkbox component that controls whether the user can access any of the standard system

output/distribution functions, including Printing documents and emailing reports. If enabled for an

application or program the user will be allowed to access these functions from the application controls.

PRINT permission will only be presented in security objects associated with programs that natively

support printing and will not appear in any of the specialized maintenance applications.

CASE MANGEMENT: A checkbox component that controls whether the user can access any of the case

management capabilities associated with a reporting module. There are specific security objects related

to the case management functions that are defined in the related object. CASE MANAGEMENT permission

will only be presented in security objects associated with report entry programs and should only be

enabled for those report types built into the report management Workflow.

ACCESS CONTROL: A checkbox component that controls whether the user can access any of the access

control capabilities within each report and presented to the user on the “Report Complete” page of the

report within the entry application(s). These capabilities are used to selectively segregate and restrict

access to system users. An ACCESS CONTROL permission will only be presented in security objects

associated with report entry programs and should only be enabled for those users or roles that would be

allowed to modify the security setting associated with a specific report within the related module. This

permission is typically reserved for investigative and administrative personnel.

ACCESS LIST: A checkbox component that controls whether the ACCESS LIST would be available for

selection on the “Report Complete” page of the report within the entry application(s). This capability is

used to control whether the user will be able to restrict reports by Role or by Pin. This permission is

typically reserved for investigative and administrative personnel.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 Page |5

Phone: (208) 580-0400 | FAX: (775) 201-7575

READ LEVEL: A variable numeric data field that controls the user default access level for a specific

report within the referenced module. Please review the “RMS ADMINISTRATORS READ/WRITE manual

for a details description of the usage and settings associated with this control.

WRITE LEVEL: A variable numeric data field that controls the user default write/update access level for

a specific report within the referenced module. Please review the “RMS ADMINISTRATORS READ/WRITE

manual for a details description of the usage and settings associated with this control.

By default, when the Security Object is added to the users (or roles) profile, all permissions are activated,

and the read/write levels are automatically set to the highest level (100). To deactivate the permission

the administrator should simply click on the checkbox to disable the control. When a check appears

within the checkbox the permission has been enabled if no check is present within the checkbox the

permission has not been assigned.

Roles and User Permissions

Every system user will need to have a security profile developed and associated with their specific user

account before they will be able to utilize the system. A security profile includes a user account

definition, an assigned set of security objects and an enabled set of permissions within the security

objects. The system provides some quick methods of building default permission sets (ROLE’s) and then

associating the users with the roles to streamline permission assignment.

Each user must first have a user account that defines the basic information, passwords, and system

processing ID associated with external resources (if applicable). When creating a user, the user’s

personnel number (PIN), logon ID and agency must be provided along with the user’s system password.

All other fields are optional but may be necessary for certain program options to work properly.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 Page |6

Phone: (208) 580-0400 | FAX: (775) 201-7575

How to Build and Permission a system USER

Each system user will require an account, you may create as many system users as needed by the

agency. If the RMS is to participate in a multi-agency configuration, generic external access roles will

need to be developed to permission users from external agencies to access selected system information.

Defining a user and the associated permissions is a relatively straight forward process within Security

Management.

Building the User’s Account

1. Launch the Security Management Application from the run directory or from a provided desktop

shortcut (if available).

2. The application will launch and present the application environment. From the application menu bar

select the “User” option to load the user definition screen.

3. A search function and listing of current system users will be presented on the search grid, vertically

aligned along the left side of the screen. Make sure you do not attempt to create a user with the

same name as an existing user.

4. The main screen is divided into three sections; the top portion includes the user’s security profile data

fields.

a. Enter the users Personnel Number as created in the EIS personnel module.

b. Enter the user’s desired logon ID. If you are utilizing Windows to control access be sure to

use Windows login, must be an exact match.

c. Enter the user’s agency

d. Enter the user’s name information in the name fields as provided.

e. If the user is to have access to the integrated NCIC functions from within the RMS-2

application the data switch Gateway ID must be entered. This ID is a routing identifier

contained within the M2 data switch used to enable specific State Query controls and routing.

Please contact EIS support for assistance.

f. Enter the desired initial password for the user (it may be changed later at any time).

g. Make sure the “Disabled” checkbox is not enabled. If it is enabled, the users account will be

immediately suspended.

5. Click the [SAVE] button on the lower right-hand button bar on the main form. This will create the

user’s profile and prepare the system to accept the security definition.

Assigning Permissions to the User’s Account

There are three ways to assign security objects to the user’s profile, either manually adding and

configuring the permission set within the user’s profile or by associating the user with a previously

defined “Role” and inheriting the security profile from the role definition.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 Page |7

Phone: (208) 580-0400 | FAX: (775) 201-7575

Method 1: Assigning Permissions Manually to the User’s Account

To define system security, you must first select the general security object, and then select the specific

permissions within each security object. To associate the desired system security objects from the

“AVAILBALE SECURITY OBJECTS” grid to the user’s profile. You may.

1. ALL: Select all of the security objects and assign to the user’s profile by clicking on the [ADD ALL]

button. All available security objects will be copied into the “APPLIED SECURITY OBJECTS” portion of

the form.

2. SINGLE: Select a specific single object by clicking directly on the row of the grid. The row will

highlight with a dark blue color indicating the selected object. Click the [ADD SELECTED] button

and the single security object will be copied into the “APPLIED SECURITY OBJECTS” portion of the

form.

3. MULTI SELECT: While depressing the [CTRL] key on the system keyboard, use the mouse to select

multiple rows by clicking directly on the row(s) of the grid. Each row will highlight with a dark blue

color indicating the selected object is activated. Click the [ADD SELECTED] button and the

collection of selected security’s object will be copied into the “APPLIED SECURITY OBJECTS” portion

of the form.

4. Once the desired security objects have been associated, it is now time to set the actual permissions

within each of the security objects.

Assigning Permissions to the user’s profile

1. Each object selected will appear in the grid view in the “APPLIED SECURITY OBJECTS” portion of the

application. Displayed within each row of the grid is the object definition fields along with the set of

permissions associated with each object. As noted earlier each object will support a differing set of

permissions so it is not uncommon to see voided permissions.

2. By default, when an object is applied all associated permissions are enabled. The administrator

should simply click on the checkbox, removing the checkbox, to disable the control. Repeat for each

object until the appropriate permissions have been allocated for the user’s profile.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 Page |8

Phone: (208) 580-0400 | FAX: (775) 201-7575

Quick Features – Batch Updating

1. To save time a set of Quick Features are available to

rapidly assign permissions to multiple objects. These

include selective batch permission assignment and the

“Select All” feature.

a. SELECT ALL: The “Select All” feature saves

the step of manually selecting each object

within the grid, and activates all security

objects assigned to the user.

b. MULTI SELECT: While depressing the

[CTRL] key on the system keyboard, use the

mouse to select multiple rows by clicking

directly on the row(s) of the grid. Each row

will highlight with a dark blue color indicating

the selected object is activated.

2. Batch Updating allows the administrator to set multiple

permissions, across multiple security objects with a single

command. With a selected set of Objects, click on the

[BATCH] button at the base of the Security manager

form, and the “Batch Update” function will appear in a

new window. Select the permissions to be affected and

click on the save button.

3. The “Batch Update” window will close and the selected

permissions will be applied to all the selected security

objects.

4. Once all the permissions have been assigned click the [SAVE] button to commit the permissions to

the systems.

Method 2: Assigning Permissions to the User’s Account by Role

The system allows a very quick way of assigning user permissions from set of pre-defined permissions.

For most system users, their access accounts can be set up in a few minutes utilizing this quick

configuration feature. To use the role assignment, there must be a predefined set of roles already

configured within the system. To configure a new “Role” please review the following section of this

manual “Working with Roles” for instructions on setting up system roles. Role association is not required

for system use, and users may be assigned to one, multiple or no roles within the

system. The Workflow engine utilizes Roles so care must be taken when assigning

multiple roles. It is not recommended to assign more than one role that is a part of

Workflow to the same person.

When a user’s profile is linked to a role the system will compare the permission set

defined for the role, and the permission set currently defined for the user. If the

permissions differ the system will notify the administrator and provide an option to

update the user’s permissions with those contained in the new role. By selecting the

permission import function, the system will attempt to import the security

permissions configured for the role and apply them directly to the user’s security

profile. This function will only add those permissions not already present in the

user’s permission profile. If multiple roles are added to the user the system will

perform the permission parity check each time and allow the administrator the

option of updating the user’s permissions each time the user role association is

defined.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 Page |9

Phone: (208) 580-0400 | FAX: (775) 201-7575

Note: The role permission assignment function is an additive function only, and it will not remove

assigned objects however it will apply the last applied permissions and read/write levels. Take care when

applying multiple roles so the desired access and permissions are applied. You will be presented the

option to accept or deny security permissions after the parity check is complete.

1. To associate a user with a role, select the desired role from the “AVAILABLE ROLES” listing along the

right-hand side of the Security manager form.

2. With the desired role highlighted, click on the [ADD] button.

3. The system will update to show the selected row is now presented

in the “APPLIED SECURITY” section.

4. The system will perform a permission parity check between the

permissions already assigned to the user (if any) and those

permissions defined for the role. If the system detects a different

set of permissions are provided within the role, a dialog prompt will

appear asking the administrator if they wish to apply the disparate

security settings to the user’s profile. Two options will be

presented.

a. Update the user’s profile from the role’s permissions. If selected the disparate security

objects and permissions will be added to the user’s profile.

b. DON’T update the user’s profile from the role’s permissions. If selected no action occurs,

and the user’s profile is not modified.

Method 3: Assigning Permissions to a User’s Account with an

existing Role

Once a role is established or modified using the Role Feature (see below for further information) the

administrator may apply changes to all those within the role with one click of a button. The administrator

may replace or elevate all users within a role and associated permissions. This feature will be restricted

by a security object under the AACMANAGER application name.

The buttons to perform this are only available based on user rights Module Name = REPLACE-ELEVATE.

Replace Users in Role – This will delete and reinsert all security objects for all users in the selected

role.

Elevate Users in Role – This will update and insert missing security objects for all users in the selected

role.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 10

Phone: (208) 580-0400 | FAX: (775) 201-7575

Working with Roles

While each user will require a specific set of permissions to be associated with their user account, the EIS

RMS-2 system has provided for the establishment of “User Roles” in addition to a single user permission

definition approach. The user “Role” can be used for 2 primary purposes, including:

1. Using an “Security Role” for the rapid assignment of permissions to a specific user. This

feature was designed to speed the management of user permissions and to help the agency to

ensure consistency in permission assignment. This function can be used when multiple system users

will be allocated the same general system permissions. The system security officer would create a

“Role” and define the set of permissions associated with the Role. When the user is associated with

the role the security officer has the choice of assigning the “Role” permissions to the user with the

single click of the mouse. This approach greatly simplifies individual user permission management

and will greatly speed the addition of new users to the system.

2. Assigning Users to Roles for Workflow processing. A users Role association is also used by

the EIS Workflow engine to determine the routing and assignment of agency reports. When a

system user is associated with a specified workflow process, that user will receive notifications from

the Workflow Engine whenever the “Role” is used as a routing destination. For example, when a

patrol officer completes an incident report the report is often routed to a patrol supervisor for review

and approval. Since we do not always know who will be acting as a supervisor at that moment, the

system will typically route the report to the “Patrol Supervisor” role, and all system users associated

with that role will receive the notification. This approach simplifies the automated assignment of

reports and provides a general catch-all capability to minimize the chance that the report will be

missed.

How to Build and Permission a System Role

You may create and name as many system Roles as appropriate to establish standard permission

assignments. However, since the Role definition can be used for both user permission assignment and

for system Workflow routing it is important that the role identity be consistent with established Workflow

configuration rules. If it is desired that new Workflow processes be defined for the role EIS support

should be consulted before proceeding.

Defining a role is a relatively straight forward process within the Security Management Application.

Building the Role

1. Launch the Security Management Application from the run directory or from a provided desktop

shortcut (if available).

2. The application will launch and present the application environment. From the application menu bar

select the “Role” option to load the role definition screen.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 11

Phone: (208) 580-0400 | FAX: (775) 201-7575

3. A listing of current system roles will be presented on the search grid, vertically aligned along the left

side of the screen. Make sure you do not attempt to create a role with the same name as an existing

role.

4. The main screen is divided into three sections; the top portion includes the Role name data fields.

a. Enter the name of the new role into the “ROLE NAME” data field, this is the value that

will be used system wide to identify the role.

b. Enter a “ROLE DESCRIPTION” which is used to provide expanded information about the

role if a cryptic name is used in the role name (e.g. ROLE NAME: S1 might mean ROLE

DESCRIPTION: Day shift patrol).

c. If the role is to be used within workflow processing, you may enter the associated

supervisory role into the “SUPERVISOR ROLE” data field (Patrol → Patrol Supervisor). For

automated routing the specified roles must be defined within the system Workflow

Engine.

5. Click the [SAVE] button on the lower right hand button bar on the main form. This will create the

role and prepare the system to accept the security definition.

6. To define system security, you must first select the general security object, and then apply the

specific permissions within each security object. To associate the desired system security objects

from the “AVAILABLE SECURITY OBJECTS” grid to the role. You may;

a. ALL: Select all the security objects and assign to the role by clicking on the [ADD ALL]

button. All available security objects will be copied into the “APPLIED SECURITY

OBJECTS” portion of the form.

b. SINGLE: Select a specific single object by clicking directly on the row of the grid. The

row will highlight with a dark blue color indicating the selected object. Click the [ADD

SELECTED] button and the single security object will be copied into the “APPLIED

SECURITY OBJECTS” portion of the form.

c. MULTI SELECT: While depressing the [CTRL] key on the system keyboard, use the

mouse to select multiple rows by clicking directly on the row(s) of the grid. Each row will

highlight with a dark blue color indicating the selected object is activated. Click the

[ADD SELECTED] button and the collection of selected security’s object will be copied

into the “APPLIED SECURITY OBJECTS” portion of the form.

7. Once the desired security objects have been associated, it is now time to set the actual permissions

within each of the security objects.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 12

Phone: (208) 580-0400 | FAX: (775) 201-7575

Assigning Permissions to the Role

1. Each object selected will appear in the grid view in the “APPLIED SECURITY OBJECTS” portion of

the application. Displayed within each row of the grid is the object definition fields along with

the set of permissions associated with each object. As noted earlier each object will support a

differing set of permissions so it is not uncommon to see voided permissions.

2. By default, when an object is applied all associated permissions are enabled. The administrator

should simply click on the checkbox, removing the checkbox, to disable the control. Repeat for

each object until the appropriate permissions have been allocated for the

Role.

Quick Features – Batch Updating

To save time a set of Quick Features are available to rapidly assign permissions to multiple objects.

These include selective batch permission assignment and the “Select All” feature.

1. SELECT ALL: The “Select All” feature saves the step

of manually selecting each object within the grid and

activates all security objects assigned to the role or

user.

2. MULTI SELECT: While depressing the [CTRL] key on

the system keyboard, use the mouse to select multiple

rows by clicking directly on the row(s) of the grid.

Each row will highlight with a dark blue color indicating

the selected object is activated.

a. Batch Updating allows the administrator to set

multiple permissions, across multiple security

objects with a single command. With a

selected set of Objects, click on the [BATCH]

button at the base of the AAC manager form,

and the “Batch Update” function will appear in

a new window. Select the permissions to be

affected and click on the [SAVE] button.

b. The “Batch Update” window will close, and the

selected permissions will be applied to all the

selected security objects.

c. Once all the permissions have been assigned click the [SAVE] button to commit the

permissions to the systems.

Adjusting Roles or User’s Permissions

At any time, it becomes necessary to modify the user’s permissions within the system the administrator

can launch the Security Management Application and update the record as needed. All adjustments to a

specific user permission must be made within the user’s permission settings to take effect, not the

users associated role permissions. Adjustments made to the role permissions after the role has been

assigned to a user will not update the user’s permission profile. Typical functions include:

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 13

Phone: (208) 580-0400 | FAX: (775) 201-7575

1. Suspending a user’s rights within the system. Typically used when the user leaves the agency

and is not expected to return. Depending on the preference of the system administrator the user

can either be deleted or the account can simply be disabled.

a. DISABLE A USER’S PERMISSIONS: This is a one

click function that when activated, suspends all

system permissions effectively locking the user out

of the system. At any point in time the account can

be re-enabled if desired.

b. To delete a user’s account from Security

Management, the administrator would recall the

user’s record to the screen by clicking on the user’s

name in the left-hand search/recall window and

clicking the [DELETE] button on the application toolbar. This function is permanent (not

recoverable) and will remove the user account and all assigned security objects from the

system.

2. Modifying a user’s permissions can be simply accomplished by recalling the user’s permission

record and updating the associated permission controls. The administrator may add or remove

security objects and/or permissions contained within each security object. Once the permissions

have been appropriately set, click the [SAVE] button to save the changes to the system.

3. Updating or modifying a user’s ROLE association. At any point the administrator can assign the

user a new role, or to multiple roles. It is recommended to not assign multiple roles utilized by

the Workflow Engine to the same user. When the user is assigned to a new role the system will

compare the permission set defined for the role, and the permission set currently defined for the

user. If the permissions differ the system will notify the administrator and provide an option to

update the user’s permissions with those contained in the new role.

Complete Listing of Security Objects

RMS Security Manager

Application Module Object Description

AAC Manager COMPUTER ACCESS If configured, allows add/edit/update of authorized

computers.

AAC Manager LOGONLOG ACCESS Will allow user to access the LOGONLOG. This shows

attempts success or failures of attempted logons.

Typically, the agency TAC will need access to this

object.

AAC Manager PROGRAM PROGRAM Program access, must be applied if the user will need

access to any object within the AAC (Security)

Manager.

AAC Manager REPLACE/ ACCESS Determines if the user can replace and elevate users

ELEVATE in role.

AAC Manager ROLE ACCESS User will be able to add, delete or update Security

Roles.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 14

Phone: (208) 580-0400 | FAX: (775) 201-7575

Application Module Object Description

AAC Manager SYSTEMROLE ACCESS Will allow access to add, delete, or update system

roles. System roles are utilized in multi-agency

configurations.

AAC Manager USER ACCESS Allows the user to add, delete, or update Users within

the Security Manager.

Civil.net

Application Module Object Description

CIVIL CIVIL ACCOUNT Allows user access to the account module.

CIVIL CIVIL SERVICE Allows user access to service module.

CIVIL CIVIL PROGRAM Allows user access to the civil application.

CIVIL CIVIL ACCOUNTI Allows user access to accounting functions.

NG

Citation Payment

Application Module Object Description

EISCITATION PAYMENT ACCESS Allows the user to run citation payment.

PAYMENT

EISCITEMAN MANAGE ACCESS Allows user to access all transactions in the citation

AGEMENT management module.

Facility Visitor

Application Module Object Description

EISFACILITY PROGRAM PROGRAM Allows user access.

VISITOR

EISFACILITY COMMENT ACCESS Allows user access.

VISITOR

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 15

Phone: (208) 580-0400 | FAX: (775) 201-7575

RMS M2 Management

Application Module Object Description

EIS M2 ADDRESS ACCESS Address module of the M2 module allows the user to

Management add, remove, modify computer access to the various

services of the RMS, JMS, CAD EIS programs.

Typically granted to users that will be deploying new

workstations.

EIS M2 AUDITLOG ACCESS Allows access to the M2 audit log, as an example, AM

Management Messages, NCIC transactions. The Agency TAC

typically has access to this module.

EIS M2 PAGEADDRESS ACCESS User will be able to manage pager addresses with this

Management module.

EIS M2 PAGER ACCESS Users that will manage any portion of pagers will need

Management access to this module.

EIS M2 PAGERGROUPS ACCESS Allows the user to manage pager groups.

Management

EIS M2 PAGERLOG ACCESS Allows the user to view the pager log.

Management

EIS M2 PROGRAM PROGRAM Allows the User to access the M2 Management

Management Program, must be applied if the user will be accessing

any modules within M2 management.

EIS Media PROGRAM PROGRAM Media Upload Program access. This is the program

Upload Client used to upload video and audio files into the RMS

program.

MIS Manager

Application Module Object Description

MISManager MLI ACCESS Not Currently Used

MISManager MNI ACCESS Allows user to manage the master name index. Merge

names, modify name records.

MISManager MPI ACCESS Not Currently Used

MISManager MVI ACCESS Not Currently Used

MISManager PROGRAM PROGRAM Allows user to utilize the Master Index Manager. Must

be applied for user to open any module within the

MIS program.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 16

Phone: (208) 580-0400 | FAX: (775) 201-7575

RMS Asset Manager

Application Module Object Description

RMS Asset PROGRAM PROGRAM Allows access to the Asset Manager program.

Manager Assigned to employee(s) responsible for entering,

removing, updating records within the asset

management program.

RMS Asset PROGRAM PROGRAM Allows user access to the program.

Manager

RMS Alarm Client

Application Module Object Description

RMS Alarm PROGRAM PROGRAM Allows user access to the program.

Client

RMS Entry

Application Module Object Description

RMSEntry ACCIDENT ACCESS Allows user to enter Accident records. Applied to any

employee that will be entering Accident reports.

RMSEntry CASE ACCESS Allows user to enter Incident Reports (Case and

Supplemental Reports).

RMSEntry CASE APPROVAL Allows the user to Approve a report outside of

workflow. Unlocks the APPROVED BY fields on the

face page of a report. Typically assigned to data entry

employees that are entering already approved

reports. *Note: If approval information is entered in

these fields, the record will bypass workflow process.

RMSEntry CASE CASE Allows user to access notify button in RMS Entry

NOTIFY Application.

RMSEntry CASE COMPLETE Allows user to override validation errors on case

complete page.

RMSEntry CASE DISTRIBUT Allows user to access the distribution of the RMS

ION Entry Application.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 17

Phone: (208) 580-0400 | FAX: (775) 201-7575

Application Module Object Description

RMSEntry CASE REPORT Allows user to view the case access log in report

management.

ACCESS

LOG

RMSEntry CASE SUPONRES Allows user to create a supplement report on a

TRICTED restricted base case.

RMSEntry CASE UPOTHERI If this permission is applied the user will be able to

NCOMP update other user’s incomplete reports. This is

typically reserved for supervisor use only. *Contact

Support if you wish to use this as the database must

be configured as well.

RMSEntry CASE ACCESS This is a note field on the Report Complete page.

COMMENT Agencies typically utilize this note field or the Report

Log feature for use by the various work groups, i.e.

records or detectives. Report Log has date time

stamp, case comment is free text.

RMSEntry CITATION ACCESS Allows entry of citation records through the RMS Entry

program.

RMSEntry CITATION APPROVAL Allows the user to Approve a citation outside of

workflow. Unlocks the APPROVED BY fields on the

face page of a citation. Typically, assigned to data

entry employees that are entering already approved

citations. Before applying consider if your agency

includes Citations in the supervisor review process.

RMSEntry CWP ACCESS Assign to users that will be entering or updating

records in the concealed weapon permit module of

the RMS entry program.

RMSEntry FI ACCESS Any employee that will be entering or modifying Field

Interview records will need this permission assigned.

RMSEntry FI APPROVAL Allows the user to approve a Field Interview record

outside of workflow. Unlocks the APPROVED BY

fields. Typically assigned to data entry employees that

are entering previously approved FI records. Before

applying consider if your agency includes Field

Interviews in the supervisor review process.

RMSEntry MCR ACCESS Apply this object to users that will be entering or

modifying Major Crime Registrant (Sex Offender,

Armed Career Criminal) records within the RMS Entry

Program

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 18

Phone: (208) 580-0400 | FAX: (775) 201-7575

Application Module Object Description

RMSEntry MEDIA ACCESS Access to this module must be applied to grant the

ability to add media (PDF's and Images) to records

within RMS Entry Program.

RMSEntry MEDIA ACCESS Allows user to get media objects from related reports.

RELATED

UPLOAD

RMSEntry MLI ACCESS Records will be included in the Master Location Index.

RMSEntry MNI ACCESS Allows access to Master Name Index button on the

name page in the various modules of the RMS Entry

Program.

RMSEntry MPI ACCESS Records will be included in the Master Property Index.

RMSEntry MVI ACCESS Allows access to Master Vehicle Index button on the

vehicle page in the various modules of the RMS Entry

Program.

RMSEntry PARKING ACCESS Assign to users that will be entering or updating

Parking Citation records within the RMS Entry

Program.

RMSEntry PARKING APPROVAL Allows the user to Approve a parking citation outside

of workflow. Unlocks the APPROVED BY fields on the

face page of parking citation. Typically, assigned to

data entry employees that are entering already

approved parking citations. Before applying consider if

your agency includes Parking Citations in the

supervisor review process.

RMSEntry PAWN ACCESS Assign to users that will be entering or updating

records in the Pawn module in the RMS Entry

Application.

RMSEntry PERMIT ACCESS Allows users to access the Permit module within RMS

Entry which allows entry of Permit records.

RMSEntry PROGRAM PROGRAM Program access, must be applied if the user will need

access to any object within the RMS Entry Application.

RMSEntry PROTECT ACCESS any employee that will enter or modify records in the

Protect (Restraining Orders) Module of the RMS Entry

Application

RMSEntry REGISTRANT ACCESS Registrant Entry, (realtor, massage therapists, door to

door sales, etc.)

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 19

Phone: (208) 580-0400 | FAX: (775) 201-7575

Application Module Object Description

RMSEntry REPORT ACCESS Report comment is a free text field on the report

COMMENT complete page. Typically used by certain work groups

within an agency, i.e. records or detectives. Usually

an agency chooses this feature or Report Log. Report

Log is date time and user stamped and entry is

consistent through a set of report log type codes.

RMSEntry REPORTLOG ACCESS Report log is a feature that allows users to add report

notes. This screen is feature rich with date/time

stamps, user stamps, ability to include entry across all

supplements, and consistent entry through use of

report log type codes.

RMSEntry RMS ACCESS Allow user to access the state reporting validation

STATEREPORTI feature within the Entry Application. Access granted to

NG those responsible for State Reporting preparation.

RMSEntry STATEENTRY ACCESS Allows access to State Entry feature if applicable.

RMSEntry STATEQUERY ACCESS Allows access to the State Query feature if applicable.

RMSEntry TRESPASS ACCESS Assign permission to any user that will be entering

trespass warnings into the RMS Entry Application.

RMSEntry WARRANT ACCESS Users responsible for warrant entry into the RMS

Entry Application will need access to this object.

RMS Manager

Application Module Object Description

RMSManager ACCESS AGENCY Allows the user to modify Agency related information

examples, GEO labels, Agency Logo, Address,

UCR/IBR preparer information, etc. Typically, system

administrators have access to this module.

RMSManager ACCESS AGENCY Each module has a unique number string and can be

NUMBERM self-assign or system generated. This module is the

GMT management of all numbers within the RMS Program.

RMSManager ACCESS BASESUPC Allows a user to change a base report to a

HANGE supplemental report and vice versa.

RMSManager ACCESS CASE Users with permission can change report numbers for

NUMBER various modules within the RMS Program.

CHANGE

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 20

Phone: (208) 580-0400 | FAX: (775) 201-7575

Application Module Object Description

RMSManager ACCESS CRIME Allows the user to manage the Crime Code Table

CODES utilized by the RMS Program. User can add, delete,

and modify Crime Codes.

RMSManager ACCESS EXPUNGE Allows the user to Expunge records from various RMS

Modules including Reports, Warrants, and Citations.

This is a permanent action and cannot be reversed.

RMSManager ACCESS RESTRICT Restrict module allow the user to restrict or un-restrict

reports without having to open the report.

RMSManager ACCESS SEAL Users that need to seal various reports will need

access to this module.

RMSManager ACCESS TABLE Table Data (F1 drop down lists throughout the

DATA program) maintenance including update, add, delete.

RMSManager ACCESS TEMPLATE Narrative templates throughout the system are

MGMT managed within this module.

RMSManager ACCESS UNSEAL Sealed records may be un-sealed using this module.

Access is typically limited to the Records Manager and

Records Supervisor.

RMSManager ACCESS WORK Permission to this module allows the user to manage

STATION workstations which includes camera and State

Entry/Query management.

RMSManager PROGRAM PROGRAM Program access, must be applied if the user will need

access to any object within the RMS Manager.

RMS Personnel Manager

Application Module Object Description

RMS PROGRAM PROGRAM Allows access to the Personnel Management

Personnel Application. All system users must be entered in the

Manager personnel management application. Assign access to

the person responsible for managing the Personnel

Application or to those that will be creating user

profiles or inactivating users.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 21

Phone: (208) 580-0400 | FAX: (775) 201-7575

RMS Property Manager

Application Module Object Description

RMS Property PROGRAM PROGRAM Access to this Application is typically limited to those

Manager directly responsible for managing the

property/evidence room. All others may view property

room information through the RMS Query Application.

RMS Query

Application Module Object Description

RMSQuery ACCIDENT ACCESS View access of Accidents through the RMS Query

Application.

RMSQuery ACCIDENT DELETE Not Currently Used

RMSQuery CASE ACCESS View access of Reports (base case and supplemental)

through the RMS Query Application.

RMSQuery CASE CASE Allows user to access the notify button in RMS Entry

NOTIFY Application.

RMSQuery CASE REPORT Allows the user to view the case access log in Report

ACCESS Management.

LOG

RMSQuery CASE ACCESS Allows user to view case comments within the Query

COMMENT Application.

RMSQuery CFS ACCESS Allows the user to view Calls for Service (CAD Calls) in

the Query Application.

RMSQuery CFS COMMENT If this permission is applied the user will be able to

add comments to Calls for Service (CAD Calls) this is

the only place that entry may occur within the Query

Application.

RMSQuery CITATION ACCESS View only access to the Citation Module within the

RMS Query Application.

RMSQuery CWP ACCESS View only access to the Concealed Weapon Permit

module within Query Application.

RMSQuery FI ACCESS When applied to user they will have view access to

Field Interview records within Query Application.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 22

Phone: (208) 580-0400 | FAX: (775) 201-7575

Application Module Object Description

RMSQuery JMSQUERY ACCESS Allows view only access to Jail Management

information through the RMS Query Application.

RMSQuery MCR ACCESS Major Crime registrant view only access through the

Query Application.

RMSQuery MEDIA ACCESS User may access the Media module within RMS Query

application.

RMSQuery MII ACCESS Allows user to access the Master Incident Index

module within the RMS Query Application. Master

Incident allows searches across modules of the RMS

with simple filters.

RMSQuery MLI ACCESS Master Location Index search within the RMS Query

Application allows the user to conduct searches based

on locations across various RMS modules.

RMSQuery MNI ACCESS Master Name Index search allows the user to search

across multiple RMS modules in one transaction.

RMSQuery MPI ACCESS Allows access to the Master Property Index search.

This module is for serialized property searches only.

RMSQuery MVI ACCESS Allows users to access the Master Vehicle Index

search module in the RMS Query Application. This

module allows user to search vehicles across multiple

modules at one time.

RMSQuery PARKING ACCESS View only access to parking citation records within the

RMS Query Application.

RMSQuery PAWN ACCESS View only access to pawn records within the RMS

Query Application.

RMSQuery PERMIT ACCESS Allows user to view permit records within the RMS

Query Application.

RMSQuery PERSONNEL ACCESS Limited view only access to records within the

personnel management program through RMS Query

Application (Name, Contact Information, Emergency

information).

RMSQuery PERSONNEL ACCESS Limited view only access to records within the

QUERY personnel management program through RMS Query

Application (Name, Contact Information, Emergency

information).

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 23

Phone: (208) 580-0400 | FAX: (775) 201-7575

Application Module Object Description

RMSQuery PROGRAM PROGRAM Program access to RMS Query Application. User must

have this permission if they will be accessing any

module within RMS Query.

RMSQuery PROPERTY ACCESS Allows the user view only access of Property

QUERY Management Program information through the RMS

Query Application.

RMSQuery PROTECT ACCESS View only access to records within the Protection

Order (Restraining Order) module within RMS Query

Application.

RMSQUERY REGISTRANT ACCESS In the RMS Query Application allows the user view

only access to Registrant module (Realtors, Massage

therapists, etc.).

RMSQuery REPORT ACCESS Allow user to view any comments entered in the

COMMENT report comment area, in a view mode only within the

RMS Query Application.

RMSQuery REPORTLOG ACCESS Allows user view access only to the Report Log screen

in RMS Query Application.

RMSQuery STATEENTRY ACCESS Allows access to State Entry feature if applicable.

RMSQuery STATEQUERY ACCESS Allows access to State Query feature if applicable.

RMSQuery TRESPASS ACCESS View access only to Trespass records through the

RMS Query Application.

RMSQuery WARRANT ACCESS Grants view only access to Warrant records through

the RMS Query Application.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 24

Phone: (208) 580-0400 | FAX: (775) 201-7575

RMS Report Viewer

Application Module Object Description

RMS Report PROGRAM PROGRAM Allows user to access RMS Reports Application to run

Viewer pre-written statistical reports for various RMS

Applications.

RMS Report RMS REPORTS Allows the user to view and modify the active status

Viewer ACTIVE (Y/N) for each report.

STATUS

RMS State Reporting

Application Module Object Description

RMS State PROGRAM PROGRAM Allows access to the UCR/IBR State Submission

Reporting program. Typically granted to the user(s) responsible

for State Submission only.

1396 NE 20th Avenue, Suite 100 | Ocala, FL 34470 P a g e | 25

Phone: (208) 580-0400 | FAX: (775) 201-7575


Source: RMS Security Management.docx

    • Related Articles

    • RMS Security Management (Old)

      RMS Security Management (Old) Security Managment Security Managment Table of Contents TOC \o "1-3" \h \z \u Table of Contents PAGEREF _Toc75519592 \h 1 SECURITY MANAGEMENT Overview The EIS RMS-2 product incorporates an expansive security management ...
    • RMS Security Objects

      RMS Security Objects RMS Security Objects Security Management Overview The EIS RMS-2 product incorporates an expansive security management and previsioning service. The Security Management component functions as the universal gatekeeper for all ...
    • Case Management Workflow

      Case Management Workflow Case management and workflow Case management and workflow Table of Contents Table of Contents PAGEREF _Toc69217903 \h 1 purpose PAGEREF _Toc69217904 \h 2 workflow information PAGEREF _Toc69217905 \h 3 PD General Workflow ...
    • Release Notes RMS January2018

      Release Notes RMS January2018 Release Notes RMS January2018 E I S , I . XECUTIVE NFORMATION ERVICES NC PRODUCT RELEASE NOTES RECORDS MANAGEMENT SYSTEM JANUARY, 2018 Executive Information Services, Inc. 1396 NE 20th Ave. Suite 100 Ocala, FL 34470 ...
    • RMS Manager Templates

      RMS Manager Templates RMS Manager Template Creation Correspondence regarding this publication should be directed to: Executive Information Services 1396 NE 20th Avenue, Suite 100Ocala, FL 34470 Phone: (208) 580-0400FAX: (775) 201-7575 E Mail: ...