Administration
Security
Teams, roles, and permissions for CMIForge access control.
Current User
Ima User imauser@twodumbdogs.comTeams
8
Active assignment groupsRoles
10
Permission bundlesAudit
76
Recorded security eventsCMIForge Support Access
Tenant admins control whether CMIForge support users may access this tenant for support. Platform-admin tenants keep internal company access available.
Disabled
Tenant: Demo
Roles
| Role | Permissions | Type |
|---|---|---|
| Administrator Full CMIForge administration. | 40 | CMIForge standard |
| CMIForge Support CMIForge vendor support access. Requires tenant support access to be enabled before support impersonation can start. | 1 | CMIForge standard |
| Entity Approver Can view entity records and approve assigned entity changes without creating, editing, archiving, or maintaining restricted entity data. | 4 | CMIForge standard |
| Entity Manager Can view, create, and edit operational entities. | 19 | CMIForge standard |
| Form and Workflow Admin Can design, publish, copy, and retire forms and workflows. | 8 | CMIForge standard |
| Intake Reviewer Can review and approve assigned intake workflow tasks. | 9 | CMIForge standard |
| Partner Can be selected as lead partner and review partner-level intake work. | 10 | CMIForge standard |
| Submitter Can submit forms and view their own submissions. | 6 | CMIForge standard |
| Walls Admin Can create and maintain ethical-wall teams and wall membership. | 1 | CMIForge standard |
| Workflow Designer Can design forms and workflows. | 6 | CMIForge standard |
Permissions
| Permission | Category |
|---|---|
| Review conflict searches Record clearance, potential conflict, conflict, or needs-info decisions. | Conflicts |
| Run conflict searches Create party-based conflict search requests. | Conflicts |
| View conflict searches View conflict search requests and results. | Conflicts |
| Approve entity changes Approve or reject proposed changes to clients and matters. | Entities |
| Create entities Create clients, matters, and users. | Entities |
| Edit restricted entity sections Maintain sensitive entity panels such as aliases, relationships, links, notes, and archive actions. | Entities |
| Submit entity changes Submit proposed changes to clients, matters, and users. | Entities |
| View business entities View clients, matters, parties, and contacts. | Entities |
| View confidential documents View, preview, open, and download entity documents marked confidential. | Entities |
| View restricted entity sections View sensitive entity panels such as aliases, relationships, linked parties, notes, audit history, pending changes, and invite history. | Entities |
| View user entities View user profiles and their business relationships separately from client and matter data. | Entities |
| Access development environment Choose and work in the tenant development environment. | Environments |
| Access test environment Choose and work in the tenant test environment. | Environments |
| Design forms Create and publish form versions. | Forms |
| Form and workflow admin Retire obsolete form and workflow definitions while preserving historical submissions and workflow audit trails. | Forms |
| Submit forms Submit available intake forms. | Forms |
| View forms View available form definitions. | Forms |
| Manage scheduled exports Configure and run scheduled customer-owned data exports. | Imports/Exports |
| Run imports Upload CSV files to import clients, matters, and parties. | Imports/Exports |
| View imports/exports View import/export center, export downloads, and import batch history. | Imports/Exports |
| View reports View hardcoded operational reports. | Reporting |
| Manage security Manage teams, roles, and permission assignments. | Security |
| Manage wall teams Create and maintain ethical-wall teams without granting access to ordinary security teams and roles. | Security |
| Approve submissions Approve or return workflow tasks. | Submissions |
| Convert submissions Create client and matter records from submissions. | Submissions |
| Edit existing client fields on submissions Override the read-only client-data guard when an intake submission reuses an existing client. | Submissions |
| View all submissions View all submitted intake records. | Submissions |
| View own submissions View submissions submitted by the user. | Submissions |
| Impersonate users Temporarily view the app as another active user for support, routing, and approval testing. | System |
| Manage API applications Create, rotate, scope, and revoke tenant API credentials. | System |
| Manage maintenance rules Configure and run entity maintenance and health-check rules. | System |
| System administrator Full CMIForge platform access. | System |
| Approve time Approve submitted time entries. | Time |
| Create time Record time entries. | Time |
| Edit time Edit existing time entries. | Time |
| View all time View time entries across users, clients, and matters. | Time |
| View own time View time entries recorded by the user. | Time |
| Design workflows Create and edit workflow definitions and steps. | Workflows |
| View all workflow queues View all open workflow tasks. | Workflows |
| View workflow queue View assigned workflow tasks. | Workflows |