{"id":"6662539e7e3aa3201154f917","title":"Member Privileges","path":"how-to/committee/member-admin/member-privileges","contentMarkdown":"# Member Privileges\n\nUse this guide to assign the right privileges to members and understand what each checkbox changes in NGX‑Ramblers.\n\n## Overview\n\nMember privileges control access to different areas of the system and determine what actions members can perform. Privileges are assigned through the **Member Admin** interface under the **Privileges** tab.\n## Accessing the Privileges Screen\n\n1. Navigate to **Admin → Member Admin**\n2. Select a member to edit\n3. Click on the **Privileges** tab\n4. Select or deselect privileges using the checkboxes\n5. Click **Save** to apply changes\n\n\n\n![](https://ngx-ramblers.org.uk/api/aws/s3/site-content/8fd42046-02eb-40c2-a64a-bb628e7ad24e.jpeg)\n\n## Privilege Descriptions\n### Core Membership\n\n\n\n#### Approved Social Member\n**Field:** `socialMember`\n\n**Purpose:** Allows members to view detailed social event information\n\n**Effect:**\n- Enables Social detail views for logged‑in members\n- Social events may have restricted visibility for non-social members\n- Used for email audience selection when targeting social members\n\n**When to assign:**\n- Assign to members who participate in social events\n- Typically assigned to most active members alongside \"Approved Group Member\"\n\n\n\n\n#### Approved Group Member\n**Field:** `groupMember`\n\n**Purpose:** Marks the person as an active group member and enables login access\n\n**Effect:**\n- **Required** for members to log in to the system\n- Without this privilege, login attempts will be blocked with the message: \"Logins for member [username] have been disabled\"\n- Included in member lists and email segments that target the full group\n- Required for Committee Member and Social Member lists\n- This is the foundational privilege that must be set for any active member\n\n**When to assign:**\n- Assign to all active, paid-up members who should have access to the system\n- Remove from members who should be denied access (e.g., lapsed membership, suspended accounts)\n\n\n\n\n\n#### Revoked Member\n**Field:** `revoked`\n\n**Purpose:** Historical/legacy field for marking revoked members\n\n**Effect:**\n- Currently **not actively enforced** in the current system\n- Excludes this person from automated updates and bulk changes (CSV updates skip revoked)\n\n**When to assign:**\n- Not recommended for active use\n- Use \"Approved Group Member\" (unchecked) instead to disable member access\n- Use when someone leaves the group or should no longer receive communications\n\n\n\n\n---\n\n\n#### Content Admin\n**Field:** `contentAdmin`\n\n**Purpose:** Controls ability to edit website content and pages\n\n**Effect:**\n- Can edit website content (Markdown pages, fragments, site edit modes)\n- Enables editing of page content, shared fragments, and site text\n- Allows management of carousels, images, and content metadata\n- Controls visibility of content editing tools throughout the site\n- Grants access to:\n  - Page editing interface\n  - Shared fragment management\n  - Carousel editor\n  - Image management tools\n\n**When to assign:**\n- Assign to committee members or volunteers responsible for maintaining website content\n- Typically assigned to Webmaster, Communications Officer, or similar roles\n- Does not grant access to member data or system settings\n\n\n\n\n#### Walk Admin\n**Field:** `walkAdmin`\n\n**Purpose:** Controls ability to create and edit group walks\n\n**Effect:**\n- Can create and manage Walks (group walks, updates)\n- Grants access to walk editing features\n- Enables creation, modification, and deletion of walks\n- Allows uploading of walks to Ramblers Walks Manager\n- Provides access to:\n  - Walk creation/editing interface\n  - Walk leader assignment\n  - Walk upload to Ramblers\n\n**When to assign:**\n- Assign to Walk Coordinators and Walk Leaders\n- Typically assigned to committee members responsible for walk programme management\n- Consider assigning to active walk leaders who need to edit their own walks\n\n\n\n### Administrative Privileges\n\n#### Member Admin\n**Field:** `memberAdmin`\n\n**Purpose:** Controls access to member administration features\n\n**Effect:**\n- Grants access to the **Admin** section of the site\n- Enables viewing and editing member records\n- Can manage members and privileges via Member Admin screens\n- Allows access to:\n  - Member Admin page (`/admin/member-admin`)\n  - Member Login Audit page (`/admin/member-login-audit`)\n  - Member Bulk Load page (`/admin/member-bulk-load`)\n  - Mailing Preferences page (`/admin/mailing-preferences`)\n  - System Settings page (`/admin/system-settings`)\n  - Mailchimp Settings, Mail Settings, Committee Settings, Migration Settings\n  - Page Content Navigator and Fragment Index\n\n**When to assign:**\n- Assign to committee members responsible for managing memberships\n- Typically assigned to Membership Secretary or similar roles\n- Exercise caution as this gives broad administrative access\n\n\n\n\n---\n\n\n#### Social Admin\n**Field:** `socialAdmin`\n\n**Purpose:** Controls ability to create and edit social events\n\n**Effect:**\n- Can create and manage Social events\n- Grants access to social event editing features\n- Enables creation, modification, and deletion of social events\n- Provides access to:\n  - Social event creation/editing interface\n  - Social event attendance management\n  - Social event notifications\n\n**When to assign:**\n- Assign to Social Secretary or Social Coordinators\n- Typically assigned to committee members responsible for organizing social events\n- Assign to volunteers who help organize social activities\n\n\n\n\n\n#### Walk Change Notifications\n**Field:** `walkChangeNotifications`\n\n**Purpose:** Determines who receives email notifications when walks are modified\n\n**Effect:**\n- Receives coordinator emails for walk create/update/cancel events\n- Members with this privilege receive automated email notifications when:\n  - Walks are created, updated, or cancelled\n  - Walk details are changed (date, time, meeting point, etc.)\n  - Walk leaders are changed\n- Notifications are sent to help coordinators track walk programme changes\n- **Note:** This is a notification privilege only—it does not grant editing rights\n\n**When to assign:**\n- Assign to Walk Coordinators who need to be informed of all walk changes\n- Typically assigned to 1-3 key walk coordinators\n- Can be assigned independently of Walk Admin privilege\n\n\n\n\n\n### Financial Privileges\n\n#### Finance Admin\n**Field:** `financeAdmin`\n\n**Purpose:** Controls ability to approve expense claims\n\n**Effect:**\n- Receives approval emails for expense claims\n- Grants access to expense claim approval features\n- Enables viewing and approving/rejecting expense claims submitted by members\n- Members with this privilege receive automated email notifications when:\n  - New expense claims are submitted\n  - Expense claims require approval\n- Works in conjunction with Treasury Admin for complete expense workflow\n- Provides access to expense claim management interface\n\n**When to assign:**\n- Assign to Treasurer or committee members authorized to approve expenses\n- Typically assigned to 1-2 committee members\n- Assign to those with budgetary oversight responsibility\n\n\n\n\n---\n\n\n#### Committee Member\n  **Field:** `committee`\n\n  **Purpose:** Grants access to committee-only areas, documents, and most admin tools\n\n  **Effect:**\n  - Shows the person in committee listings\n  - Used for committee visibility and access\n  - Enables access to committee pages and private committee files\n  - Allows viewing of documents marked as \"Committee Only\"\n  - Unlocks committee-specific sections of the website\n  - Grants access to most Admin tools:\n    - Admin dashboard (`/admin`)\n    - System Settings, Mail Settings, Mailchimp Settings, Committee Settings, Migration Settings\n    - Backup & Restore, Page Content Navigator, Fragment Index, Member Login Audit, Member Bulk Load, Mailing Preferences, AGM Statistics\n  - **Does not** grant access to:\n    - Member Admin page (`/admin/member-admin`)\n    - Editing member privileges\n\n  **When to assign:**\n  - Assign to all elected committee members\n  - Assign to co‑opted committee members\n  - May be assigned to other volunteers who need access to committee materials and admin tools, but not member administration\n\n\n\n#### Treasury Admin\n**Field:** `treasuryAdmin`\n\n**Purpose:** Controls ability to process approved expense payments\n\n**Effect:**\n- Receives payment emails for expense claims (post‑approval)\n- Grants access to payment processing for approved expense claims\n- Enables marking expenses as paid and recording payment details\n- Members with this privilege receive automated email notifications when:\n  - Expense claims have been approved and are ready for payment\n- Works alongside Finance Admin in the expense approval workflow\n- Provides access to payment processing interface\n\n**When to assign:**\n- Assign to Treasurer or authorized payment processors\n- Typically assigned to 1-2 committee members\n- Should only be assigned to those with access to group bank account\n- Often assigned to the same person as Finance Admin, but can be separate\n\n\n\n\n\n#### File Admin\n**Field:** `fileAdmin`\n\n**Purpose:** Controls ability to upload and manage committee files and member resources\n\n**Effect:**\n- Can upload and manage Committee files (documents, minutes, assets)\n- Grants ability to add, edit, and delete committee files (minutes, agendas, policies, etc.)\n- Enables management of member resources (guides, forms, how-to documents)\n- Allows sending of committee file notifications\n- Controls file type configuration\n- Provides access to:\n  - Committee file upload/management\n  - Member resource management\n  - File visibility settings\n\n**When to assign:**\n- Assign to Secretary or Webmaster\n- Assign to committee members responsible for maintaining documents\n- Typically assigned to 1-3 committee members\n- Often combined with Committee Member privilege\n\n\n\n\n---\n\n\n## How Permissions Are Applied\n\n### Logged‑in checks\n  The app reads a logged‑in member profile and gates features accordingly:\n  - Content Admin → content editing\n  - Walk Admin → walk editing\n  - Social Admin → social editing\n  - Member Admin → member admin edits (Member Admin page and member privileges)\n  - Finance Admin / Treasury Admin → expense notifications\n  - File Admin / Committee → committee files and visibility\n  - Committee Member → admin dashboard and most admin tools (excluding Member Admin page)\n  - Social Member → view social details\n\n### Email notifications\n- Walk changes → members with Walk Change Notifications\n- Expense approvals → Finance Admin\n- Expense payments → Treasury Admin\n\n### Lists and filters\n- Committee lists → Approved Group Member + Committee Member\n- Social lists → Approved Group Member + Approved Social Member\n\n---\n\n\n\n## Common Privilege Combinations\n\n### Standard Member\n- Approved Group Member\n- Approved Social Member\n\n**Purpose:** Regular member with full access to public features\n\n---\n\n### Walk Leader\n- Approved Group Member\n- Approved Social Member\n- Walk Admin\n\n**Purpose:** Member who can create and edit walks\n\n---\n\n### Walk Coordinator\n- Approved Group Member\n- Approved Social Member\n- Walk Admin\n- Walk Change Notifications\n\n**Purpose:** Coordinates walk programme and receives notifications of all walk changes\n\n---\n\n### Social Secretary\n- Approved Group Member\n- Approved Social Member\n- Social Admin\n- Committee Member\n\n**Purpose:** Manages social events and has access to committee materials\n\n---\n\n### Membership Secretary\n- Approved Group Member\n- Approved Social Member\n- Member Admin\n- Committee Member\n\n**Purpose:** Manages member records and has access to admin features\n\n---\n\n### Treasurer\n- Approved Group Member\n- Approved Social Member\n- Finance Admin\n- Treasury Admin\n- Committee Member\n\n**Purpose:** Manages expense claims (approval and payment)\n\n---\n\n### Secretary\n- Approved Group Member\n- Approved Social Member\n- File Admin\n- Committee Member\n\n**Purpose:** Manages committee documents and minutes\n\n---\n\n### Webmaster / Chairman (Full Access)\n- Approved Group Member\n- Approved Social Member\n- Content Admin\n- Walk Admin\n- Walk Change Notifications\n- Social Admin\n- Member Admin\n- Finance Admin\n- Treasury Admin\n- File Admin\n- Committee Member\n\n**Purpose:** Full administrative access to all system features\n\n---\n\n\n\n## Recommended Patterns\n\n### Core membership\nGrant Approved Group Member to active members; add Approved Social Member for social communications.\n\n### Committee\nAdd Committee Member; layer File Admin for document maintenance.\n\n### Walks\nUse Walk Admin for editors; add Walk Change Notifications for coordinators.\n\n### Offboarding\nSet Revoked Member when a person leaves; remove other privileges if access must be removed. Better still, uncheck \"Approved Group Member\" to disable login access.\n\n---\n\n## Security Best Practices\n\n### Principle of Least Privilege\n- Only assign privileges that are necessary for the member's role\n- Regularly review member privileges and remove unnecessary access\n- When members leave committee roles, update their privileges accordingly\n\n### Audit Trail\n- All member login activity is recorded in the Member Login Audit\n- Member Admin users can view this audit at `/admin/member-login-audit`\n- Changes to member records are tracked with timestamps and user identification\n\n### Multiple Administrators\n- Assign Member Admin to at least 2 people to avoid single points of failure\n- Ensure Walk Admin is assigned to multiple walk coordinators\n- Consider having backup administrators for critical roles\n\n### Regular Reviews\n- Review member privileges quarterly or when committee roles change\n- Remove \"Approved Group Member\" from lapsed or resigned members\n- Update privileges immediately when committee elections occur\n\n---\n\n\n\n## Troubleshooting\n\n### Member Cannot Log In\n**Check:** Is \"Approved Group Member\" selected?\n- If unchecked, the member will be denied login access\n- This is the most common cause of login issues\n\n### Member Cannot See Admin Menu\n**Check:** Does the member have at least one admin privilege?\n- Member Admin, Content Admin, Walk Admin, Social Admin, or File Admin\n\n### Member Not Receiving Walk Notifications\n**Check:** Is \"Walk Change Notifications\" selected?\n- This must be explicitly enabled to receive walk change emails\n- Walk Admin alone does not trigger notifications\n\n### Member Cannot Approve Expenses\n**Check:** Is \"Finance Admin\" selected?\n- This privilege is required to approve expense claims\n- Treasury Admin is for payment processing, not approval\n\n### Member Cannot Access Committee Files\n**Check:** Is \"Committee Member\" selected?\n- Files marked as \"Committee Only\" require this privilege\n- File Admin allows editing but requires Committee Member to view restricted files\n\n---\n\n\n\n## Quick Reference\n\n- View social details: Approved Social Member\n- Edit content: Content Admin\n- Edit walks: Walk Admin\n- Edit social events: Social Admin\n- Manage members: Member Admin\n- Receive walk change emails: Walk Change Notifications\n- Expense approvals: Finance Admin\n- Expense payments: Treasury Admin\n- Manage committee files: File Admin\n- Show in committee listings: Committee Member\n- Suppress updates: Revoked Member\n","contentHtml":"<h1>Member Privileges</h1>\n<p>Use this guide to assign the right privileges to members and understand what each checkbox changes in NGX‑Ramblers.</p>\n<h2>Overview</h2>\n<p>Member privileges control access to different areas of the system and determine what actions members can perform. Privileges are assigned through the <strong>Member Admin</strong> interface under the <strong>Privileges</strong> tab.</p>\n<h2>Accessing the Privileges Screen</h2>\n<ol>\n<li>Navigate to <strong>Admin → Member Admin</strong></li>\n<li>Select a member to edit</li>\n<li>Click on the <strong>Privileges</strong> tab</li>\n<li>Select or deselect privileges using the checkboxes</li>\n<li>Click <strong>Save</strong> to apply changes</li>\n</ol>\n<p><img src=\"https://ngx-ramblers.org.uk/api/aws/s3/site-content/8fd42046-02eb-40c2-a64a-bb628e7ad24e.jpeg\" alt=\"\"></p>\n<h2>Privilege Descriptions</h2>\n<h3>Core Membership</h3>\n<h4>Approved Social Member</h4>\n<p><strong>Field:</strong> <code>socialMember</code></p>\n<p><strong>Purpose:</strong> Allows members to view detailed social event information</p>\n<p><strong>Effect:</strong></p>\n<ul>\n<li>Enables Social detail views for logged‑in members</li>\n<li>Social events may have restricted visibility for non-social members</li>\n<li>Used for email audience selection when targeting social members</li>\n</ul>\n<p><strong>When to assign:</strong></p>\n<ul>\n<li>Assign to members who participate in social events</li>\n<li>Typically assigned to most active members alongside &quot;Approved Group Member&quot;</li>\n</ul>\n<h4>Approved Group Member</h4>\n<p><strong>Field:</strong> <code>groupMember</code></p>\n<p><strong>Purpose:</strong> Marks the person as an active group member and enables login access</p>\n<p><strong>Effect:</strong></p>\n<ul>\n<li><strong>Required</strong> for members to log in to the system</li>\n<li>Without this privilege, login attempts will be blocked with the message: &quot;Logins for member [username] have been disabled&quot;</li>\n<li>Included in member lists and email segments that target the full group</li>\n<li>Required for Committee Member and Social Member lists</li>\n<li>This is the foundational privilege that must be set for any active member</li>\n</ul>\n<p><strong>When to assign:</strong></p>\n<ul>\n<li>Assign to all active, paid-up members who should have access to the system</li>\n<li>Remove from members who should be denied access (e.g., lapsed membership, suspended accounts)</li>\n</ul>\n<h4>Revoked Member</h4>\n<p><strong>Field:</strong> <code>revoked</code></p>\n<p><strong>Purpose:</strong> Historical/legacy field for marking revoked members</p>\n<p><strong>Effect:</strong></p>\n<ul>\n<li>Currently <strong>not actively enforced</strong> in the current system</li>\n<li>Excludes this person from automated updates and bulk changes (CSV updates skip revoked)</li>\n</ul>\n<p><strong>When to assign:</strong></p>\n<ul>\n<li>Not recommended for active use</li>\n<li>Use &quot;Approved Group Member&quot; (unchecked) instead to disable member access</li>\n<li>Use when someone leaves the group or should no longer receive communications</li>\n</ul>\n<hr>\n<h4>Content Admin</h4>\n<p><strong>Field:</strong> <code>contentAdmin</code></p>\n<p><strong>Purpose:</strong> Controls ability to edit website content and pages</p>\n<p><strong>Effect:</strong></p>\n<ul>\n<li>Can edit website content (Markdown pages, fragments, site edit modes)</li>\n<li>Enables editing of page content, shared fragments, and site text</li>\n<li>Allows management of carousels, images, and content metadata</li>\n<li>Controls visibility of content editing tools throughout the site</li>\n<li>Grants access to:<ul>\n<li>Page editing interface</li>\n<li>Shared fragment management</li>\n<li>Carousel editor</li>\n<li>Image management tools</li>\n</ul>\n</li>\n</ul>\n<p><strong>When to assign:</strong></p>\n<ul>\n<li>Assign to committee members or volunteers responsible for maintaining website content</li>\n<li>Typically assigned to Webmaster, Communications Officer, or similar roles</li>\n<li>Does not grant access to member data or system settings</li>\n</ul>\n<h4>Walk Admin</h4>\n<p><strong>Field:</strong> <code>walkAdmin</code></p>\n<p><strong>Purpose:</strong> Controls ability to create and edit group walks</p>\n<p><strong>Effect:</strong></p>\n<ul>\n<li>Can create and manage Walks (group walks, updates)</li>\n<li>Grants access to walk editing features</li>\n<li>Enables creation, modification, and deletion of walks</li>\n<li>Allows uploading of walks to Ramblers Walks Manager</li>\n<li>Provides access to:<ul>\n<li>Walk creation/editing interface</li>\n<li>Walk leader assignment</li>\n<li>Walk upload to Ramblers</li>\n</ul>\n</li>\n</ul>\n<p><strong>When to assign:</strong></p>\n<ul>\n<li>Assign to Walk Coordinators and Walk Leaders</li>\n<li>Typically assigned to committee members responsible for walk programme management</li>\n<li>Consider assigning to active walk leaders who need to edit their own walks</li>\n</ul>\n<h3>Administrative Privileges</h3>\n<h4>Member Admin</h4>\n<p><strong>Field:</strong> <code>memberAdmin</code></p>\n<p><strong>Purpose:</strong> Controls access to member administration features</p>\n<p><strong>Effect:</strong></p>\n<ul>\n<li>Grants access to the <strong>Admin</strong> section of the site</li>\n<li>Enables viewing and editing member records</li>\n<li>Can manage members and privileges via Member Admin screens</li>\n<li>Allows access to:<ul>\n<li>Member Admin page (<code>/admin/member-admin</code>)</li>\n<li>Member Login Audit page (<code>/admin/member-login-audit</code>)</li>\n<li>Member Bulk Load page (<code>/admin/member-bulk-load</code>)</li>\n<li>Mailing Preferences page (<code>/admin/mailing-preferences</code>)</li>\n<li>System Settings page (<code>/admin/system-settings</code>)</li>\n<li>Mailchimp Settings, Mail Settings, Committee Settings, Migration Settings</li>\n<li>Page Content Navigator and Fragment Index</li>\n</ul>\n</li>\n</ul>\n<p><strong>When to assign:</strong></p>\n<ul>\n<li>Assign to committee members responsible for managing memberships</li>\n<li>Typically assigned to Membership Secretary or similar roles</li>\n<li>Exercise caution as this gives broad administrative access</li>\n</ul>\n<hr>\n<h4>Social Admin</h4>\n<p><strong>Field:</strong> <code>socialAdmin</code></p>\n<p><strong>Purpose:</strong> Controls ability to create and edit social events</p>\n<p><strong>Effect:</strong></p>\n<ul>\n<li>Can create and manage Social events</li>\n<li>Grants access to social event editing features</li>\n<li>Enables creation, modification, and deletion of social events</li>\n<li>Provides access to:<ul>\n<li>Social event creation/editing interface</li>\n<li>Social event attendance management</li>\n<li>Social event notifications</li>\n</ul>\n</li>\n</ul>\n<p><strong>When to assign:</strong></p>\n<ul>\n<li>Assign to Social Secretary or Social Coordinators</li>\n<li>Typically assigned to committee members responsible for organizing social events</li>\n<li>Assign to volunteers who help organize social activities</li>\n</ul>\n<h4>Walk Change Notifications</h4>\n<p><strong>Field:</strong> <code>walkChangeNotifications</code></p>\n<p><strong>Purpose:</strong> Determines who receives email notifications when walks are modified</p>\n<p><strong>Effect:</strong></p>\n<ul>\n<li>Receives coordinator emails for walk create/update/cancel events</li>\n<li>Members with this privilege receive automated email notifications when:<ul>\n<li>Walks are created, updated, or cancelled</li>\n<li>Walk details are changed (date, time, meeting point, etc.)</li>\n<li>Walk leaders are changed</li>\n</ul>\n</li>\n<li>Notifications are sent to help coordinators track walk programme changes</li>\n<li><strong>Note:</strong> This is a notification privilege only—it does not grant editing rights</li>\n</ul>\n<p><strong>When to assign:</strong></p>\n<ul>\n<li>Assign to Walk Coordinators who need to be informed of all walk changes</li>\n<li>Typically assigned to 1-3 key walk coordinators</li>\n<li>Can be assigned independently of Walk Admin privilege</li>\n</ul>\n<h3>Financial Privileges</h3>\n<h4>Finance Admin</h4>\n<p><strong>Field:</strong> <code>financeAdmin</code></p>\n<p><strong>Purpose:</strong> Controls ability to approve expense claims</p>\n<p><strong>Effect:</strong></p>\n<ul>\n<li>Receives approval emails for expense claims</li>\n<li>Grants access to expense claim approval features</li>\n<li>Enables viewing and approving/rejecting expense claims submitted by members</li>\n<li>Members with this privilege receive automated email notifications when:<ul>\n<li>New expense claims are submitted</li>\n<li>Expense claims require approval</li>\n</ul>\n</li>\n<li>Works in conjunction with Treasury Admin for complete expense workflow</li>\n<li>Provides access to expense claim management interface</li>\n</ul>\n<p><strong>When to assign:</strong></p>\n<ul>\n<li>Assign to Treasurer or committee members authorized to approve expenses</li>\n<li>Typically assigned to 1-2 committee members</li>\n<li>Assign to those with budgetary oversight responsibility</li>\n</ul>\n<hr>\n<h4>Committee Member</h4>\n<p>  <strong>Field:</strong> <code>committee</code></p>\n<p>  <strong>Purpose:</strong> Grants access to committee-only areas, documents, and most admin tools</p>\n<p>  <strong>Effect:</strong></p>\n<ul>\n<li>Shows the person in committee listings</li>\n<li>Used for committee visibility and access</li>\n<li>Enables access to committee pages and private committee files</li>\n<li>Allows viewing of documents marked as &quot;Committee Only&quot;</li>\n<li>Unlocks committee-specific sections of the website</li>\n<li>Grants access to most Admin tools:<ul>\n<li>Admin dashboard (<code>/admin</code>)</li>\n<li>System Settings, Mail Settings, Mailchimp Settings, Committee Settings, Migration Settings</li>\n<li>Backup &amp; Restore, Page Content Navigator, Fragment Index, Member Login Audit, Member Bulk Load, Mailing Preferences, AGM Statistics</li>\n</ul>\n</li>\n<li><strong>Does not</strong> grant access to:<ul>\n<li>Member Admin page (<code>/admin/member-admin</code>)</li>\n<li>Editing member privileges</li>\n</ul>\n</li>\n</ul>\n<p>  <strong>When to assign:</strong></p>\n<ul>\n<li>Assign to all elected committee members</li>\n<li>Assign to co‑opted committee members</li>\n<li>May be assigned to other volunteers who need access to committee materials and admin tools, but not member administration</li>\n</ul>\n<h4>Treasury Admin</h4>\n<p><strong>Field:</strong> <code>treasuryAdmin</code></p>\n<p><strong>Purpose:</strong> Controls ability to process approved expense payments</p>\n<p><strong>Effect:</strong></p>\n<ul>\n<li>Receives payment emails for expense claims (post‑approval)</li>\n<li>Grants access to payment processing for approved expense claims</li>\n<li>Enables marking expenses as paid and recording payment details</li>\n<li>Members with this privilege receive automated email notifications when:<ul>\n<li>Expense claims have been approved and are ready for payment</li>\n</ul>\n</li>\n<li>Works alongside Finance Admin in the expense approval workflow</li>\n<li>Provides access to payment processing interface</li>\n</ul>\n<p><strong>When to assign:</strong></p>\n<ul>\n<li>Assign to Treasurer or authorized payment processors</li>\n<li>Typically assigned to 1-2 committee members</li>\n<li>Should only be assigned to those with access to group bank account</li>\n<li>Often assigned to the same person as Finance Admin, but can be separate</li>\n</ul>\n<h4>File Admin</h4>\n<p><strong>Field:</strong> <code>fileAdmin</code></p>\n<p><strong>Purpose:</strong> Controls ability to upload and manage committee files and member resources</p>\n<p><strong>Effect:</strong></p>\n<ul>\n<li>Can upload and manage Committee files (documents, minutes, assets)</li>\n<li>Grants ability to add, edit, and delete committee files (minutes, agendas, policies, etc.)</li>\n<li>Enables management of member resources (guides, forms, how-to documents)</li>\n<li>Allows sending of committee file notifications</li>\n<li>Controls file type configuration</li>\n<li>Provides access to:<ul>\n<li>Committee file upload/management</li>\n<li>Member resource management</li>\n<li>File visibility settings</li>\n</ul>\n</li>\n</ul>\n<p><strong>When to assign:</strong></p>\n<ul>\n<li>Assign to Secretary or Webmaster</li>\n<li>Assign to committee members responsible for maintaining documents</li>\n<li>Typically assigned to 1-3 committee members</li>\n<li>Often combined with Committee Member privilege</li>\n</ul>\n<hr>\n<h2>How Permissions Are Applied</h2>\n<h3>Logged‑in checks</h3>\n<p>  The app reads a logged‑in member profile and gates features accordingly:</p>\n<ul>\n<li>Content Admin → content editing</li>\n<li>Walk Admin → walk editing</li>\n<li>Social Admin → social editing</li>\n<li>Member Admin → member admin edits (Member Admin page and member privileges)</li>\n<li>Finance Admin / Treasury Admin → expense notifications</li>\n<li>File Admin / Committee → committee files and visibility</li>\n<li>Committee Member → admin dashboard and most admin tools (excluding Member Admin page)</li>\n<li>Social Member → view social details</li>\n</ul>\n<h3>Email notifications</h3>\n<ul>\n<li>Walk changes → members with Walk Change Notifications</li>\n<li>Expense approvals → Finance Admin</li>\n<li>Expense payments → Treasury Admin</li>\n</ul>\n<h3>Lists and filters</h3>\n<ul>\n<li>Committee lists → Approved Group Member + Committee Member</li>\n<li>Social lists → Approved Group Member + Approved Social Member</li>\n</ul>\n<hr>\n<h2>Common Privilege Combinations</h2>\n<h3>Standard Member</h3>\n<ul>\n<li>Approved Group Member</li>\n<li>Approved Social Member</li>\n</ul>\n<p><strong>Purpose:</strong> Regular member with full access to public features</p>\n<hr>\n<h3>Walk Leader</h3>\n<ul>\n<li>Approved Group Member</li>\n<li>Approved Social Member</li>\n<li>Walk Admin</li>\n</ul>\n<p><strong>Purpose:</strong> Member who can create and edit walks</p>\n<hr>\n<h3>Walk Coordinator</h3>\n<ul>\n<li>Approved Group Member</li>\n<li>Approved Social Member</li>\n<li>Walk Admin</li>\n<li>Walk Change Notifications</li>\n</ul>\n<p><strong>Purpose:</strong> Coordinates walk programme and receives notifications of all walk changes</p>\n<hr>\n<h3>Social Secretary</h3>\n<ul>\n<li>Approved Group Member</li>\n<li>Approved Social Member</li>\n<li>Social Admin</li>\n<li>Committee Member</li>\n</ul>\n<p><strong>Purpose:</strong> Manages social events and has access to committee materials</p>\n<hr>\n<h3>Membership Secretary</h3>\n<ul>\n<li>Approved Group Member</li>\n<li>Approved Social Member</li>\n<li>Member Admin</li>\n<li>Committee Member</li>\n</ul>\n<p><strong>Purpose:</strong> Manages member records and has access to admin features</p>\n<hr>\n<h3>Treasurer</h3>\n<ul>\n<li>Approved Group Member</li>\n<li>Approved Social Member</li>\n<li>Finance Admin</li>\n<li>Treasury Admin</li>\n<li>Committee Member</li>\n</ul>\n<p><strong>Purpose:</strong> Manages expense claims (approval and payment)</p>\n<hr>\n<h3>Secretary</h3>\n<ul>\n<li>Approved Group Member</li>\n<li>Approved Social Member</li>\n<li>File Admin</li>\n<li>Committee Member</li>\n</ul>\n<p><strong>Purpose:</strong> Manages committee documents and minutes</p>\n<hr>\n<h3>Webmaster / Chairman (Full Access)</h3>\n<ul>\n<li>Approved Group Member</li>\n<li>Approved Social Member</li>\n<li>Content Admin</li>\n<li>Walk Admin</li>\n<li>Walk Change Notifications</li>\n<li>Social Admin</li>\n<li>Member Admin</li>\n<li>Finance Admin</li>\n<li>Treasury Admin</li>\n<li>File Admin</li>\n<li>Committee Member</li>\n</ul>\n<p><strong>Purpose:</strong> Full administrative access to all system features</p>\n<hr>\n<h2>Recommended Patterns</h2>\n<h3>Core membership</h3>\n<p>Grant Approved Group Member to active members; add Approved Social Member for social communications.</p>\n<h3>Committee</h3>\n<p>Add Committee Member; layer File Admin for document maintenance.</p>\n<h3>Walks</h3>\n<p>Use Walk Admin for editors; add Walk Change Notifications for coordinators.</p>\n<h3>Offboarding</h3>\n<p>Set Revoked Member when a person leaves; remove other privileges if access must be removed. Better still, uncheck &quot;Approved Group Member&quot; to disable login access.</p>\n<hr>\n<h2>Security Best Practices</h2>\n<h3>Principle of Least Privilege</h3>\n<ul>\n<li>Only assign privileges that are necessary for the member&#39;s role</li>\n<li>Regularly review member privileges and remove unnecessary access</li>\n<li>When members leave committee roles, update their privileges accordingly</li>\n</ul>\n<h3>Audit Trail</h3>\n<ul>\n<li>All member login activity is recorded in the Member Login Audit</li>\n<li>Member Admin users can view this audit at <code>/admin/member-login-audit</code></li>\n<li>Changes to member records are tracked with timestamps and user identification</li>\n</ul>\n<h3>Multiple Administrators</h3>\n<ul>\n<li>Assign Member Admin to at least 2 people to avoid single points of failure</li>\n<li>Ensure Walk Admin is assigned to multiple walk coordinators</li>\n<li>Consider having backup administrators for critical roles</li>\n</ul>\n<h3>Regular Reviews</h3>\n<ul>\n<li>Review member privileges quarterly or when committee roles change</li>\n<li>Remove &quot;Approved Group Member&quot; from lapsed or resigned members</li>\n<li>Update privileges immediately when committee elections occur</li>\n</ul>\n<hr>\n<h2>Troubleshooting</h2>\n<h3>Member Cannot Log In</h3>\n<p><strong>Check:</strong> Is &quot;Approved Group Member&quot; selected?</p>\n<ul>\n<li>If unchecked, the member will be denied login access</li>\n<li>This is the most common cause of login issues</li>\n</ul>\n<h3>Member Cannot See Admin Menu</h3>\n<p><strong>Check:</strong> Does the member have at least one admin privilege?</p>\n<ul>\n<li>Member Admin, Content Admin, Walk Admin, Social Admin, or File Admin</li>\n</ul>\n<h3>Member Not Receiving Walk Notifications</h3>\n<p><strong>Check:</strong> Is &quot;Walk Change Notifications&quot; selected?</p>\n<ul>\n<li>This must be explicitly enabled to receive walk change emails</li>\n<li>Walk Admin alone does not trigger notifications</li>\n</ul>\n<h3>Member Cannot Approve Expenses</h3>\n<p><strong>Check:</strong> Is &quot;Finance Admin&quot; selected?</p>\n<ul>\n<li>This privilege is required to approve expense claims</li>\n<li>Treasury Admin is for payment processing, not approval</li>\n</ul>\n<h3>Member Cannot Access Committee Files</h3>\n<p><strong>Check:</strong> Is &quot;Committee Member&quot; selected?</p>\n<ul>\n<li>Files marked as &quot;Committee Only&quot; require this privilege</li>\n<li>File Admin allows editing but requires Committee Member to view restricted files</li>\n</ul>\n<hr>\n<h2>Quick Reference</h2>\n<ul>\n<li>View social details: Approved Social Member</li>\n<li>Edit content: Content Admin</li>\n<li>Edit walks: Walk Admin</li>\n<li>Edit social events: Social Admin</li>\n<li>Manage members: Member Admin</li>\n<li>Receive walk change emails: Walk Change Notifications</li>\n<li>Expense approvals: Finance Admin</li>\n<li>Expense payments: Treasury Admin</li>\n<li>Manage committee files: File Admin</li>\n<li>Show in committee listings: Committee Member</li>\n<li>Suppress updates: Revoked Member</li>\n</ul>\n"}