What are the User Roles and Permissions in the Access Control Tool, ACT?

Overview

This article defines the standard user roles within ACT, including associated permissions, typical users, and expected responsibilities. These roles are used to ensure appropriate access to door systems while maintaining security and operational oversight.

All users must review and sign the required Terms and Conditions agreement prior to being granted access to ACT.

Ownership
Purdue ID Card Operations manages ACT role assignment and access in coordination with departments, door owners, and system administrators.

Standard Role Definitions

Merchant Report Viewer
Provides read-only visibility into merchant data and may allow temporary door state overrides depending on permissions set by the Merchant Administrator.

  • Typical Users: Clerical support staff, teaching assistants, and department heads.
  • Responsibilities: Validating that access is accurate for individual users or defined populations.

Merchant Staff
Allows users to view, grant, and revoke access within a merchant based on permissions assigned by the Merchant Administrator.

  • Typical Users: Class instructors and door owners.
  • Responsibilities: Maintaining appropriate access via auditing and adjusting permissions based on business needs.

Merchant Administrator
Provides full control within a merchant, including the ability to grant or revoke access and perform temporary door state overrides.

  • Typical Users: Door owners and Building Deputies.
  • Responsibilities: Managing Merchant-level user permissions, verifying required training/certifications, and ensuring Terms and Conditions are signed.

System Report Viewer
Provides visibility into system-level information and allows temporary door state overrides for doors assigned Access Level 4 or below.

  • Typical Users: Purdue Police and Physical Facilities staff.
  • Responsibilities: Reviewing system data to support operations and assisting Merchant Users with access issues.

System Staff
Allows users to view and manage access based on permissions assigned by the System Administrator.

  • Typical Users: Purdue ID Card Office staff.
  • Responsibilities: Ensuring all users have completed required certifications and signed Terms and Conditions.

System Administrator
Holds full system access across all merchants and system functionality.

  • Typical Users: Applications Administrators, BbTS Managers, and ID Card Office Data Analysts.
  • Responsibilities: System configuration, troubleshooting complex permission issues, and maintaining overall system compliance.

Facilities Viewer
Provides access to system infrastructure data (as-built drawings, floor plans, and door properties). Access to person-related data is restricted.

  • Typical Users: Purdue Electronics staff.
  • Responsibilities: Reviewing system information to support hardware troubleshooting and new installations.

Specialized Access Groups

The following access groups provide specialized permissions to specific roles based on departmental business needs. These are often layered on top of a standard Merchant or System role.

Accounting Access

  • Scope: Limited to authorized users within the Student Life Business Office and Purdue Dining & Culinary.
  • Purpose: Allows for specific financial or audit-related access oversight within the ACT environment.

Conferences Access

  • Scope: Restricted to users with specific, permission-based authorization.
  • Purpose: Provides the ability to manage temporary or group-based access required for university-hosted conference events.

Meal Plans Integration

  • Scope: Users managing dining-related access.
  • Purpose: Enables the management of door access specifically tied to Meal Plan eligibility and dining-related credentials.

StarRez Integration

  • Scope: Restricted to authorized users (typically Residence Life).
  • Purpose: Provides the ability to manage access that is synchronized with StarRez housing data to ensure seamless student move-in/move-out workflows.
Print Article

Related Articles (1)

A guide to the Merchant Administrator role. Learn who holds this position within a department, their authority to manage local user access, and their ongoing responsibilities regarding security auditing and compliance.