RMS Security Objects
Security Management
Overview
The EIS RMS-2 product incorporates an expansive security management and previsioning service. The
Security Management component functions as the universal gatekeeper for all system resources and
was specifically designed to insulate the back-end system services and database from unauthorized
intrusion. As such whenever a user launches a common RMS-2 module, the application first contacts the
Security service to determine if the requesting user is recognized, and has been assigned sufficient
permissions to access the requested application. If the user is authenticated, the extended system
connection information along with the users defined permissions are returned to the client application
and enabled for the user to proceed. If the user fails authentication, a notification to the user is
provided. The user credential can be pulled from the Windows logon, to eliminate the application level
Username/password log-on approach.
While the basic operations of Security Management are comprised of a specific set of low level system
controls operating outside of the normal view of the user, the Security component also maintains the
comprehensive listing of all user permissions. As each user is authenticated, Security Management
retrieves the related system permissions prepares the session accordingly. These permissions cover all
aspects of system operations, including what applications the users can access, enforces control of
specific capabilities within the programs and determines what data the users can either view or modify.
In a multi-agency system deployment Security Management, will enforce cross agency data sharing
rules.
Access to the Security Management and permissions settings are provided through
the Security Management application which is separate from the other RMS
applications. It is accessible directly from the application directory or from a desktop
shortcut (if previously defined). It is recommended that the Security Management
application not be widely distributed along with the basic system modules, and only
be installed on those user’s workstations who have a specific reason to access.
1
Executive Information Services, Inc.
Security Permission Management
Security Management utilizes several
newer concepts to facilitate the rapid
assignment of system privileges to users,
and the management of those
permissions as required by the agency or
as new features are added. In reviewing
the security model from the bottom up,
all permissions are assigned as a
collection of functions associated with a
“Security Object”. Many of the system
modules contain multiple security objects
as appropriate. The Security Objects are
grouped and applied to either a specific
user account or to an agency Role
definition. Through this combination of
security objects and specified permission
the agency can develop very granular access privileges in accordance with agency policy. Once applied
the permissions become active and will be applied to the related user at their next log-on event.
Permissions can be added or modified at any time.
There are two specific concepts that must be understood to properly utilize the Security Management to
achieve the agency’s security directives, and to effectively manage the automated routing of system
reports as configured within the “EIS Workflow Engine”. These are the “Roles and Users” relationship
and the configuration of specific permissions for each user or user class (Role).
2
Executive Information Services, Inc.
System Security Objects and Permissions
The RMS-2 utilizes a multi-tiered security definition for each of the system modules and various
specialty components and functions. This multi-tiered approach is based upon the System Security
Objects and associated Permissions defined for each user or role. A Security Object is a specific set of
defined permissions associated with a system module. While the Security Object does not inherently
provide any specific permissions for a user, it must be present in the user’s profile before access
permissions can be granted. When a user attempts to access a portion of the system, the system will
first check to determine if the security object exists in the user’s profile. If the system cannot locate the
Security Object in the users profile the request will be denied immediately. If the Security Object is
present and no permissions have been assigned the request will also be denied. Only when the
combination of Security Object and associated permissions are present will the user be allowed to
proceed.
Security Objects
Each Security Object is listed with a set of descriptive data to identify the relationship of the object to
the overall system. These fields include;
Application: Identifies the RMS-2 workstation application that will use the object. The
application is what the user will launch to access the system. For example, if you wish to grant a
user access to the Asset Management Program for entering and modifying information, you
must first assign the appropriate security object – in this case the “RMSASSETMANAGEMENT”
object.
Module: The module specifies either the functional module (within an application that supports
multiple modules – such as RMS Entry), or a “PROGRAM” definition for some of the stand-alone
programs provided within the system. For example, since the Asset Management software is
provided as a stand-alone program, the application would be listed as:
“RMSASSETMANAGEMENT” and the module would be “PROGRAM”
Object: Specifies the specific portion of the module security affected by this Security Object.
These may be entire modules (and may be defined as “PROGRAM” or “ACCESS”) or they may
support a specific function within a module (e.g. access to the “EXPUNGE” function within the
RMS Manager application)
Description: Simply provides a textural description of the associated Security Object to assist
the user in identifying the appropriate item.
3
Executive Information Services, Inc.
Security Permissions
The actual permissions that allow access into the applications are contained within each of the security
objects. Applied permissions determine what privileges and capabilities will be available to each user as
they utilize the system. Once a Security Object has been associated with a user or role, the associated
permissions become visible. There is a common set of permissions provided within the system, however
not all modules will support all the available permissions. For example, an inquiry module (one that
only allows the retrieval of data) will not display an add, update or delete permission because data
modification is not supported in an inquiry only module, and the presence of these permissions would
only serve to confuse the user.
Activating the permissions within each Security Object is as simple as checking the permission box or
setting a variable value. Standard system permissions include:
ACCESS: A checkbox component that establishes the base level permission and controls
whether the user can launch the related application. This permission supersedes all other
permissions, in that if the user is not allowed to launch the application, no other function would
logically be available to the user. An “Access” permission must be provided if the user is to be
able to perform any function within the application. An “Access” permission will be in all
security objects.
ADD: A checkbox component that controls whether the user can create new records within the
related application. If enabled for an application or program the user will be allowed to create
new records within the module. An “Add” permission will only be presented in security objects
associated with data entry programs, and will not appear in any of the inquiry applications.
UPDATE: A checkbox component that controls whether the user can change an existing record
within the related application at its most basic level. If enabled for an application or program
the user will be allowed to update or modify records within the module. This permission can be
superseded by the module “Write Level” permission and/or the integral report restriction
capability. An “Update” permission will only be presented in security objects associated with
data entry programs, and will not appear in any of the inquiry applications.
4
Executive Information Services, Inc.
PRINT: A checkbox component that controls whether the user can access any of the standard
system output/distribution functions, including Printing documents and emailing reports. If
enabled for an application or program the user will be allowed to access these functions from
the application controls. PRINT permission will only be presented in security objects associated
with programs that natively support printing, and will not appear in any of the specialized
maintenance applications.
CASE MANGEMENT: A checkbox component that controls whether the user can access any of
the case management capabilities associated with a reporting module. There are specific
security objects related to the case management functions that are defined in the related
object. CASE MANAGEMENT permission will only be presented in security objects associated
with report entry programs, and should only be enabled for those report types built into the
report management Workflow.
ACCESS CONTROL: A checkbox component that controls whether the user can access any of the
access control capabilities within each report, and presented to the user on the “Report
Complete” page of the report within the entry application(s). These capabilities are used to
selectively segregate and restrict access to system users. An ACCESS CONTROL permission will
only be presented in security objects associated with report entry programs, and should only be
enabled for those users or roles that would be allowed to modify the security setting associated
with a specific report within the related module. This permission is typically reserved for
investigative and administrative personnel.
ACCESS LIST: A checkbox component that controls whether the ACCESS LIST would be available
for selection on the “Report Complete” page of the report within the entry application(s). This
capability is used to control whether the user will be able to restrict reports by Role or by Pin.
This permission is typically reserved for investigative and administrative personnel.
READ LEVEL: A variable numeric data field that controls the user default access level for a
specific report within the referenced module. Please review the “RMS ADMINISTRATORS
READ/WRITE manual for a details description of the usage and settings associated with this
control.
WRITE LEVEL: A variable numeric data field that controls the user default write/update access
level for a specific report within the referenced module. Please review the “RMS
ADMINISTRATORS READ/WRITE manual for a details description of the usage and settings
associated with this control.
By default, when the Security Object is added to the users (or roles) profile, all permissions are activated
and the read/write levels are automatically set to the highest level (100). To deactivate the permission
the administrator should simply click on the checkbox to disable the control. When a check appears
within the checkbox the permission has been enabled, if no check is present within the checkbox the
permission has not been assigned.
5
Executive Information Services, Inc.
Roles and User Permissions
Every system user will need to have a security profile developed and associated with their specific user
account before they will be able to utilize the system. A security profile includes a user account
definition, an assigned set of security objects and an enabled set of permissions within the security
objects. The system provides some quick methods of building default permission sets (ROLE’s) and then
associating the users with the roles to streamline permission assignment.
Each user must first have a user account that defines the basic information, passwords, and system
processing ID associated with external resources (if applicable). When creating a user, the user’s
personnel number (PIN), logon ID and agency must be provided along with the user’s system password.
All other fields are optional but may be necessary for certain program options to work properly.
How to Build and Permission a system USER
Each system user will require an account, you may create as many system users as needed by the
agency. If the RMS is to participate in a multi-agency configuration, generic external access roles will
need to be developed to permission users from external agencies to access selected system information.
Defining a user and the associated permissions is a relatively straight forward process within Security
Management.
6
Executive Information Services, Inc.
Building the User’s Account
1. Launch the Security Management Application from the run directory or from a provided desktop
shortcut (if available).
2. The application will launch and present the application environment. From the application
menu bar select the “User” option to load the user definition screen.
3. A search function and listing of current system users will be presented on the search grid,
vertically aligned along the left side of the screen. Make sure you do not attempt to create a
user with the same name as an existing user.
4. The main screen is divided into three sections; the top portion includes the user’s security
profile data fields.
a. Enter the users Personnel Number as created in the EIS personnel module.
b. Enter the user’s desired logon ID. If you are utilizing Windows to control access be sure
to use Windows login, must be an exact match.
c. Enter the user’s agency
d. Enter the user’s name information in the name fields as provided.
e. If the user is to have access to the integrated NCIC functions from within the RMS-2
application the data switch Gateway ID must be entered. This ID is a routing identifier
contained within the M2 data switch used to enable specific State Query controls and
routing. Please contact EIS support for assistance.
f. Enter the desired initial password for the user (it may be changed later at any time).
g. Make sure the “Disabled” checkbox is not enabled. If it is enabled, the users account
will be immediately suspended.
5. Click the [SAVE] button on the lower right hand button bar on the main form. This will create
the user’s profile and prepare the system to accept the security definition.
Assigning Permissions to the User’s Account
There are two ways to assign security objects to the user’s profile, either manually adding and
configuring the permission set within the user’s profile or by associating the user with a previously
defined “Role” and inheriting the security profile from the role definition.
Method 1: Assigning Permissions Manually to the User’s Account
To define system security, you must first select the general security object, and then select the
specific permissions within each security object. To associate the desired system security
objects from the “AVAILBALE SECURITY OBJECTS” grid to the user’s profile. You may;
a. ALL: Select all of the security objects and assign to the user’s profile by clicking on the
[ADD ALL] button. All available security objects will be copied into the “APPLIED
SECURITY OBJECTS” portion of the form.
7
Executive Information Services, Inc.
b. SINGLE: Select a specific single object by clicking directly on the row of the grid. The row
will highlight with a dark blue color indicating the selected object. Click the [ADD
SELECTED] button and the single security object will be copied into the “APPLIED
SECURITY OBJECTS” portion of the form.
c. MULTI SELECT: While depressing the [CTRL] key on the system keyboard, use the mouse
to select multiple rows by clicking directly on the row(s) of the grid. Each row will
highlight with a dark blue color indicating the selected object is activated. Click the
[ADD SELECTED] button and the collection of selected security’s object will be copied
into the “APPLIED SECURITY OBJECTS” portion of the form.
1. Once the desired security objects have been associated, it is now time to set the actual
permissions within each of the security objects.
Assigning Permissions to the user’s profile
1. Each object selected will appear in the grid view in the “APPLIED SECURITY OBJECTS” portion of
the application. Displayed within each row of the grid is the object definition fields along with
the set of permissions associated with each object. As noted earlier each object will support a
differing set of permissions so it is not uncommon to see voided permissions.
2. By default, when an object is applied all associated permissions are enabled. The administrator
should simply click on the checkbox, removing the checkbox, to disable the control. Repeat for
each object until the appropriate permissions have been allocated for the user’s profile.
8
Executive Information Services, Inc.
Quick Features – Batch Updating
3. To save time a set of Quick Features are available to
rapidly assign permissions to multiple objects. These
include selective batch permission assignment and
the “Select All” feature.
a. SELECT ALL: The “Select All” feature saves
the step of manually selecting each object
within the grid, and activates all security
objects assigned to the user.
b. MULTI SELECT: While depressing the [CTRL]
key on the system keyboard, use the mouse
to select multiple rows by clicking directly on
the row(s) of the grid. Each row will
highlight with a dark blue color indicating
the selected object is activated.
4. Batch Updating allows the administrator to set
multiple permissions, across multiple security
objects with a single command. With a selected set
of Objects, click on the [BATCH] button at the base of the Security manager form, and the
“Batch Update” function will appear in a new window. Select the permissions to be affected
and click on the save button.
5. The “Batch Update” window will close and the selected permissions will be applied to all the
selected security objects.
6. Once all the permissions have been assigned click the [SAVE] button to commit the permissions
to the systems.
9
Executive Information Services, Inc.
Method 2: Assigning Permissions the User’s Account from a Role
The system allows a very quick way of assigning user permissions from set of pre-defined permissions.
For most system users, their access accounts can be set up in a few minutes utilizing this quick
configuration feature. To use the role assignment, there must be a predefined set of roles already
configured within the system. To configure a new “Role” please review the following section of this
manual “Working with Roles” for instructions on setting up system roles. Role
association is not required for system use, and users may be assigned to one,
multiple or no roles within the system. The Workflow engine utilizes Roles so care
must be taken when assigning multiple roles. It is not recommended to assign
more than one role that is a part of Workflow to the same person.
When a user’s profile is linked to a role the system will compare the permission set
defined for the role, and the permission set currently defined for the user. If the
permissions differ the system will notify the administrator and provide an option to
update the user’s permissions with those contained in the new role. By selecting
the permission import function, the system will attempt to import the security
permissions configured for the role, and apply them directly to the user’s security
profile. This function will only add those permissions not already present in the
user’s permission profile. If multiple roles are added to the user the system will
perform the permission parity check each time, and allow the administrator the
option of updating the user’s permissions each time the user role association is defined.
Note: The role permission assignment function is an additive function only, and it will not remove
assigned objects however it will apply the last applied permissions and read/write levels. Take care
when applying multiple roles so the desired access and permissions are applied. You will be presented
the option to accept or deny security permissions after the parity check is complete.
1. To associate a user with a role, select the desired role from the “AVAILABLE ROLES” listing along
the right-hand side of the Security manager form.
2. With the desired role highlighted, click on the [ADD] button.
3. The system will update to show the selected row is now
presented in the “APPLIED SECURITY” section.
4. The system will perform a permission parity check between
the permissions already assigned to the user (if any) and those
permissions defined for the role. If the system detects a
different set of permissions are provided within the role, a
dialog prompt will appear asking the administrator if they wish
to apply the disparate security settings to the user’s profile. Two options will be presented;
a. Update the user’s profile from the role’s permissions. If selected the disparate security
objects and permissions will be added to the user’s profile.
b. DON’T update the user’s profile from the role’s permissions. If selected no action occurs,
and the users profile is not modified.
10
Executive Information Services, Inc.
Working with Roles
While each user will require a specific set of permissions to be associated with their user account, the
EIS RMS-2 system has provided for the establishment of “User Roles” in addition to a single user
permission definition approach. The user “Role” can be used for 2 primary purposes, including:
1. Using an “Security Role” for the rapid assignment of permissions to a specific user. This
feature was designed to speed the management of user permissions and to help the agency to
ensure consistency in permission assignment. This function can be used when multiple system
users will be allocated the same general system permissions. The system security officer would
create a “Role” and define the set of permissions associated with the Role. When the user is
associated with the role the security officer has the choice of assigning the “Role” permissions to
the user with the single click of the mouse. This approach greatly simplifies individual user
permission management and will greatly speed the addition of new users to the system.
2. Assigning Users to Roles for Workflow processing. A users Role association is also used by the
EIS Workflow engine to determine the routing and assignment of agency reports. When a
system user is associated with a specified workflow process, that user will receive notifications
from the Workflow Engine whenever the “Role” is used as a routing destination. For example,
when a patrol officer completes an incident report the report is often routed to a patrol
supervisor for review and approval. Since we do not always know who will be acting as a
supervisor at that moment, the system will typically route the report to the “Patrol Supervisor”
role, and all system users associated with that role will receive the notification. This approach
simplifies the automated assignment of reports, and provides a general catch-all capability to
minimize the chance that the report will be missed.
How to Build and Permission a system Role.
You may create and name as many system Roles as appropriate to establish standard permission
assignments. However, since the Role definition can be used for both user permission assignment and
for system Workflow routing it is important that the role identity be consistent with established
Workflow configuration rules. If it is desired that new Workflow processes be defined for the role EIS
support should be consulted before proceeding.
Defining a role is a relatively straight forward process within the Security Management Application.
Building the Role
1. Launch the Security Management Application from the run directory or from a provided desktop
shortcut (if available).
2. The application will launch and present the application environment. From the application
menu bar select the “Role” option to load the role definition screen.
11
Executive Information Services, Inc.
3. A listing of current system roles will be presented on the search grid, vertically aligned along the
left side of the screen. Make sure you do not attempt to create a role with the same name as an
existing role.
4. The main screen is divided into three sections; the top portion includes the Role name data
fields.
a. Enter the name of the new role into the “ROLE NAME” data field, this is the value that
will be used system wide to identify the role.
b. Enter a “ROLE DESCRIPTION” which is used to provide expanded information about the
role if a cryptic name is used in the role name (e.g. ROLE NAME: S1 might mean ROLE
DESCRIPTION: Day shift patrol).
c. If the role is to be used within workflow processing, you may enter the associated
supervisory role into the “SUPERVISOR ROLE” data field (Patrol Patrol Supervisor). For
automated routing the specified roles must be defined within the system Workflow
Engine.
5. Click the [SAVE] button on the lower right hand button bar on the main form. This will create
the role and prepare the system to accept the security definition.
6. To define system security, you must first select the general security object, and then apply the
specific permissions within each security object. To associate the desired system security
objects from the “AVAILABLE SECURITY OBJECTS” grid to the role. You may;
a. ALL: Select all the security objects and assign to the role by clicking on the [ADD ALL]
button. All available security objects will be copied into the “APPLIED SECURITY
OBJECTS” portion of the form.
b. SINGLE: Select a specific single object by clicking directly on the row of the grid. The row
will highlight with a dark blue color indicating the selected object. Click the [ADD
SELECTED] button and the single security object will be copied into the “APPLIED
SECURITY OBJECTS” portion of the form.
c. MULTI SELECT: While depressing the [CTRL] key on the system keyboard, use the mouse
to select multiple rows by clicking directly on the row(s) of the grid. Each row will
highlight with a dark blue color indicating the selected object is activated. Click the
12
Executive Information Services, Inc.
[ADD SELECTED] button and the collection of selected security’s object will be copied
into the “APPLIED SECURITY OBJECTS” portion of the form.
7. Once the desired security objects have been associated, it is now time to set the actual
permissions within each of the security objects.
Assigning Permissions to the Role
1. Each object selected will appear in the grid view in the “APPLIED SECURITY OBJECTS” portion of
the application. Displayed within each row of the grid is the object definition fields along with
the set of permissions associated with each object. As noted earlier each object will support a
differing set of permissions so it is not uncommon to see voided permissions.
2. By default, when an object is applied all associated permissions are enabled. The administrator
should simply click on the checkbox, removing the checkbox, to disable the control. Repeat for
each object until the appropriate permissions have been allocated for the
Role.
Quick Features – Batch Updating
To save time a set of Quick Features are available to rapidly
assign permissions to multiple objects. These include
selective batch permission assignment and the “Select All”
feature.
a. SELECT ALL: The “Select All” feature saves
the step of manually selecting each object
within the grid, and activates all security
objects assigned to the role or user.
b. MULTI SELECT: While depressing the [CTRL]
key on the system keyboard, use the mouse
to select multiple rows by clicking directly on
the row(s) of the grid. Each row will
highlight with a dark blue color indicating
the selected object is activated.
1. Batch Updating allows the administrator to set multiple permissions, across multiple security
objects with a single command. With a selected set of Objects, click on the [BATCH] button at
the base of the AAC manager form, and the “Batch Update” function will appear in a new
window. Select the permissions to be affected and click on the [SAVE] button.
13
Executive Information Services, Inc.
2. The “Batch Update” window will close and the selected permissions will be applied to all the
selected security objects.
3. Once all the permissions have been assigned click the [SAVE] button to commit the permissions
to the systems.
Adjusting User or Role Permissions
At any time, it becomes necessary to modify the user’s permissions within the system the administrator
can launch the Security Management Application and update the record as needed. All adjustments to a
specific user permissions must be made within the user’s permission settings to take effect, not the
users associated role permissions. Adjustments made to the role permissions after the role has been
assigned to a user will not update the user’s permission profile. Typical functions include:
1. Suspending a user’s rights within the system. Typically used when the user leaves the agency,
and is not expected to return. Depending on the preference of the system administrator the
user can either be deleted or the account can simply be
disabled.
a. DISABLE A USER’S PERMISSIONS: This is a one click
function that when activated, suspends all system
permissions effectively locking the user out of the
system. At any point in time the account can be re-
enabled if desired.
b. To delete a user’s account from Security
Management, the administrator would recall the user’s record to the screen by clicking
on the user’s name in the left-hand search/recall window and clicking the [DELETE]
button on the application toolbar. This function is permanent (not recoverable) and will
remove the user account and all assigned security objects from the system.
2. Modifying a user’s permissions can be simply accomplished by recalling the user’s permission
record, and updating the associated permission controls. The administrator may add or remove
security objects and/or permissions contained within each security object. Once the
permissions have been appropriately set, click the [SAVE] button to save the changes to the
system.
3. Updating or modifying a user’s ROLE association. At any point the administrator can assign the
user a new role, or to multiple roles. It is recommended to not assign multiple roles utilized by
the Workflow Engine to the same user. When the user is assigned to a new role the system will
compare the permission set defined for the role, and the permission set currently defined for
the user. If the permissions differ the system will notify the administrator and provide an option
to update the user’s permissions with those contained in the new role.
14
Executive Information Services, Inc.
Application Module Object Description
AAC COMPUTER ACCESS If configured, allows add/edit/update of authorized
Manager computers.
AAC LOGONLOG ACCESS Will allow user to access the LOGONLOG. This shows
Manager attempts success or failures of attempted logons.
Typically, the agency TAC will need access to this
object.
AAC PROGRAM PROGRAM Program access, must be applied if the user will need
Manager access to any object within the AAC (Security)
Manager.
AAC ROLE ACCESS User will be able to add, delete or update Security
Manager Roles
AAC SYSTEMROLE ACCESS Will allow access to add, delete, or update system
Manager roles. System roles are utilized in multi-agency
configurations.
AAC USER ACCESS Allows the user to add, delete, or update Users within
Manager the Security Manager.
EIS M2 ADDRESS ACCESS Address module of the M2 module allows the user to
Management add, remove, modify computer access to the various
services of the RMS, JMS, CAD EIS programs. Typically
granted to users that will be deploying new
workstations.
EIS M2 AUDITLOG ACCESS Allows access to the M2 audit log, as an example, AM
Management Messages, NCIC transactions. The Agency TAC
typically has access to this module.
EIS M2 PAGEADDRESS ACCESS User will be able to manage pager addresses with this
Management module.
EIS M2 PAGER ACCESS Users that will manage any portion of pagers will
Management need access to this module
EIS M2 PAGERGROUPS ACCESS Allows the user to manage pager groups
Management
EIS M2 PAGERLOG ACCESS Allows the user to view the pager log.
Management
EIS M2 PROGRAM PROGRAM Allows the User to access the M2 Management
Management Program, must be applied if the user will be accessing
any modules within M2 management
EIS Media PROGRAM PROGRAM Media Upload Program access. This is the program
Upload Client used to upload video and audio files into the RMS
program.
MISManager MLI ACCESS Not Currently Used
MISManager MNI ACCESS Allows user to manage the master name index.
Merge names, modify name records.
MISManager MPI ACCESS Not Currently Used
15
Executive Information Services, Inc.
MISManager MVI ACCESS Not Currently Used
MISManager PROGRAM PROGRAM Allows user to utilize the Master Index Manager.
Must be applied for user to open any module within
the MIS program.
RMS Asset PROGRAM PROGRAM Allows access to the Asset Manager program.
Manager Assigned to employee(s) responsible for entering,
removing, updating records within the asset
management program
RMSEntry ACCIDENT ACCESS Allows user to enter Accident records. Applied to any
employee that will be entering Accident reports.
RMSEntry CASE ACCESS Allows user to enter Incident Reports (Case and
Supplemental Reports)
RMSEntry CASE APPROVAL Allows the user to Approve a report outside of
workflow. Unlocks the APPROVED BY fields on the
face page of a report. Typically assigned to data entry
employees that are entering already approved
reports.
RMSEntry CASE UPOTHERI If this permission is applied the user will be able to
NCOMP update other user’s incomplete reports. This is
typically reserved for supervisor use only.
RMSEntry CASE ACCESS This is a note field on the Report Complete page.
COMMENT Agencies typically utilize this note field or the Report
Log feature for use by the various work groups, i.e.
records or detectives. Report Log has date time
stamp, case comment is free text.
RMSEntry CITATION ACCESS Allows entry of citation records through the RMS
Entry program.
RMSEntry CITATION APPROVAL Allows the user to Approve a citation outside of
workflow. Unlocks the APPROVED BY fields on the
face page of a citation. Typically, assigned to data
entry employees that are entering already approved
citations. Before applying consider if your agency
includes Citations in the supervisor review process.
RMSEntry CWP ACCESS Assign to users that will be entering or updating
records in the concealed weapon permit module of
the RMS entry program.
RMSEntry FI ACCESS Any employee that will be entering or modifying Field
Interview records will need this permission assigned
16
Executive Information Services, Inc.
RMSEntry FI APPROVAL Allows the user to approve a Field Interview record
outside of workflow. Unlocks the APPROVED BY
fields. Typically assigned to data entry employees
that are entering previously approved FI records.
Before applying consider if your agency includes Field
Interviews in the supervisor review process.
RMSEntry MCR ACCESS Apply this object to users that will be entering or
modifying Major Crime Registrant (Sex Offender,
Armed Career Criminal) records within the RMS Entry
Program
RMSEntry MEDIA ACCESS Access to this module must be applied to grant the
ability to add media (PDF's and Images) to records
within RMS Entry Program
RMSEntry MLI ACCESS Records will be included in the Master Location Index
RMSEntry MNI ACCESS Allows access to Master Name Index button on the
name page in the various modules of the RMS Entry
Program
RMSEntry MPI ACCESS Records will be included in the Master Property Index
RMSEntry MVI ACCESS Allows access to Master Vehicle Index button on the
vehicle page in the various modules of the RMS Entry
Program
RMSEntry PARKING ACCESS Assign to users that will be entering or updating
Parking Citation records within the RMS Entry
Program.
RMSEntry PARKING APPROVAL Allows the user to Approve a parking citation outside
of workflow. Unlocks the APPROVED BY fields on the
face page of parking citation. Typically, assigned to
data entry employees that are entering already
approved parking citations. Before applying consider
if your agency includes Parking Citations in the
supervisor review process.
RMSEntry PAWN ACCESS Assign to users that will be entering or updating
records in the Pawn module in the RMS Entry
Application.
RMSEntry PERMIT ACCESS Allows users to access the Permit module within RMS
Entry which allows entry of Permit records.
RMSEntry PROGRAM PROGRAM Program access, must be applied if the user will need
access to any object within the RMS Entry
Application.
RMSEntry PROTECT ACCESS any employee that will enter or modify records in the
Protect (Restraining Orders) Module of the RMS Entry
Application
17
Executive Information Services, Inc.
RMSEntry REGISTRANT ACCESS Registrant Entry, (realtor, massage therapists, door to
door sales, etc.)
RMSEntry REPORT ACCESS Report comment is a free text field on the report
COMMENT complete page. Typically used by certain work groups
within an agency, i.e. records or detectives. Usually
an agency chooses this feature or Report Log. Report
Log is date time and user stamped and entry is
consistent through a set of report log type codes.
RMSEntry REPORTLOG ACCESS Report log is a feature that allows users to add report
notes. This screen is feature rich with date/time
stamps, user stamps, ability to include entry across all
supplements, and consistent entry through use of
report log type codes.
RMSEntry RMS ACCESS Allow user to access the state reporting validation
STATEREPORTI feature within the Entry Application. Access granted
NG to those responsible for State Reporting preparation.
RMSEntry STATEENTRY ACCESS Allows access to State Entry feature if applicable.
RMSEntry STATEQUERY ACCESS Allows access to the State Query feature if applicable.
RMSEntry TRESPASS ACCESS Assign permission to any user that will be entering
trespass warnings into the RMS Entry Application
RMSEntry WARRANT ACCESS Users responsible for warrant entry into the RMS
Entry Application will need access to this object.
RMSManager ACCESS AGENCY Allows the user to modify Agency related information
examples, GEO labels, Agency Logo, Address,
UCR/IBR preparer information, etc. Typically, system
administrators have access to this module.
RMSManager ACCESS AGENCY Each module has a unique number string and can be
NUMBERM self-assign or system generated. This module is the
GMT management of all numbers within the RMS Program.
RMSManager ACCESS BASESUPC Allows a user change a base report to a supplemental
HANGE report and vice versa.
RMSManager ACCESS CASE Users with permission can change report numbers for
NUMBER various modules within the RMS Program
CHANGE
RMSManager ACCESS CRIME Allows the user to manage the Crime Code Table
CODES utilized by the RMS Program. User can add, delete,
and modify Crime Codes.
RMSManager ACCESS EXPUNGE Allows the user to Expunge records from various RMS
Modules including Reports, Warrants, and Citations.
This is a permanent action and cannot be reversed.
RMSManager ACCESS RESTRICT Restrict module allow the user to restrict or un-
restrict reports without having to open the report.
18
Executive Information Services, Inc.
RMSManager ACCESS SEAL Users that need to seal various reports will need
access to this module.
RMSManager ACCESS TABLE Table Data (F1 drop down lists throughout the
DATA program) maintenance including update, add, delete.
RMSManager ACCESS TEMPLATE Narrative templates throughout the system are
MGMT managed within this module.
RMSManager ACCESS UNSEAL Sealed records may be un-sealed using this module.
Access is typically limited to the Records Manager
and Records Supervisor.
RMSManager ACCESS WORK Permission to this module allows the user to manage
STATION workstations which includes camera and State
Entry/Query management.
RMSManager PROGRAM PROGRAM Program access, must be applied if the user will need
access to any object within the RMS Manager.
RMS PROGRAM PROGRAM Allows access to the Personnel Management
Personnel Application. All system users must be entered in the
Manager personnel management application. Assign access to
the person responsible for managing the Personnel
Application or to those that will be creating user
profiles or inactivating users.
RMS PROGRAM PROGRAM Access to this Application is typically limited to those
Property directly responsible for managing the
Manager property/evidence room. All others may view
property room information through the RMS Query
Application.
RMSQuery ACCIDENT ACCESS View access of Accidents through the RMS Query
Application
RMSQuery ACCIDENT DELETE Not Currently Used
RMSQuery CASE ACCESS View access of Reports (base case and supplemental)
through the RMS Query Application
RMSQuery CASE ACCESS Allows user to view case comments within the Query
COMMENT Application
RMSQuery CFS ACCESS Allows the user to view Calls for Service (CAD Calls) in
the Query Application
RMSQuery CFS COMMENT If this permission is applied the user will be able to
add comments to Calls for Service (CAD Calls) this is
the only place that entry may occur within the Query
Application
RMSQuery CITATION ACCESS View only access to the Citation Module within the
RMS Query Application
RMSQuery CWP ACCESS View only access to the Concealed Weapon Permit
module within Query Application
19
Executive Information Services, Inc.
RMSQuery FI ACCESS When applied to user they will have view access to
Field Interview records within Query Application
RMSQuery JMSQUERY ACCESS Allows view only access to Jail Management
information through the RMS Query Application
RMSQuery MCR ACCESS Major Crime registrant view only access through the
Query Application
RMSQuery MEDIA ACCESS User may access the Media module within RMS
Query application
RMSQuery MII ACCESS Allows user to access the Master Incident Index
module within the RMS Query Application. Master
Incident allows searches across modules of the RMS
with simple filters
RMSQuery MLI ACCESS Master Location Index search within the RMS Query
Application allows the user to conduct searches
based on locations across various RMS modules.
RMSQuery MNI ACCESS Master Name Index search allows the user to search
across multiple RMS modules in one transaction.
RMSQuery MPI ACCESS Allows access to the Master Property Index search.
This module is for serialized property searches only.
RMSQuery MVI ACCESS Allows users to access the Master Vehicle Index
search module in the RMS Query Application. This
module allows user to search vehicles across multiple
modules at one time.
RMSQuery PARKING ACCESS View only access to parking citation records within
the RMS Query Application
RMSQuery PAWN ACCESS View only access to pawn records within the RMS
Query Application
RMSQuery PERMIT ACCESS Allows user to view permit records within the RMS
Query Application
RMSQuery PERSONNEL ACCESS Limited view only access to records within the
personnel management program through RMS Query
Application (Name, Contact Information, Emergency
information)
RMSQuery PERSONNEL ACCESS Limited view only access to records within the
QUERY personnel management program through RMS Query
Application (Name, Contact Information, Emergency
information)
RMSQuery PROGRAM PROGRAM Program access to RMS Query Application. User must
have this permission if they will be accessing any
module within RMS Query
20
Executive Information Services, Inc.
RMSQuery PROPERTY ACCESS Allows the user view only access of Property
QUERY Management Program information through the RMS
Query Application
RMSQuery PROTECT ACCESS View only access to records within the Protection
Order (Restraining Order) module within RMS Query
Application
RMSQUERY REGISTRANT ACCESS In the RMS Query Application allows the user view
only access to Registrant module (Realtors, Massage
therapists, etc.)
RMSQuery REPORT ACCESS Allow user to view any comments entered in the
COMMENT report comment area, in a view mode only within the
RMS Query Application
RMSQuery REPORTLOG ACCESS Allows user view access only to the Report Log screen
in RMS Query Application
RMSQuery STATEENTRY ACCESS Allows access to State Entry feature if applicable.
RMSQuery STATEQUERY ACCESS Allows access to State Query feature if applicable.
RMSQuery TRESPASS ACCESS View access only to Trespass records through the
RMS Query Application
RMSQuery WARRANT ACCESS Grants view only access to Warrant records through
the RMS Query Application
RMS Report PROGRAM PROGRAM Allows user to access RMS Reports Application to run
Viewer pre-written statistical reports for various RMS
Applications
RMS State PROGRAM PROGRAM Allows access to the UCR/IBR State Submission
Reporting program. Typically granted to the user(s) responsible
for State Submission only.
TRAINING PROGRAM PROGRAM Allows user to enter, modify, delete records within
the Training Program.
21
Executive Information Services, Inc.
Source: RMS Security Objects.docx