Rock U - Groups - Group Security

Transcribed Video Content

Handing Rock to volunteers or other staff only works when they can't wander into groups that they shouldn't have access to. So setting security on the group type and at the group level will allow us to know who has access to what. So let's cover some important security concepts. So this is the way that group security flows. So you'll want to reference this or think about this when you're actually securing groups. Now if you want, you could add security to every single group, but that's sort of unsustainable. And it's really difficult to go back if you wanna make a widespread change in the future. That's just a lot of work. So it's not the best way to secure things, though you can do that if there's specific groups that have special security needs. But after Rock checks the group itself for security, then the next place it goes to see if someone can do something view, edit, or administrate is looking at the group type. Now this is a great way to do security. That's because, generally, the kind of security that a group needs is based on the group type. Say you have something a help group or a recovery group that is it's something that you don't want everyone to be able to see. Then you could go to that group type for this kind of help group, and you could say people that can view this are only administrators or only staff workers, certain staff workers, then if you ever need to make a change, it's easy to make that change and each group type has proper security. Now you might get a little confused here because we jump from the group itself to the group type to the parent group. You would think that it goes from the group to the parent and the grandparent, and then group type is checked later. But we do it this way because it makes security easier. And ultimately, once you understand it, it's easy to follow what security will be checked for a group. Then after group type, we'll check the parent group security. That is, of course, if there is a parent group, then the grandparent group. Again, of course, if there is a grandparent group, then we'll check on the group entity type after that. So each entity in Rock can have its own security for things viewing rights. And we're probably gonna have defaults on there that say something it'll default to no. And that's because there's a better chance that most people are not gonna have viewing rights on a certain entity type unless there's something an administrator. Then after the group entity type is checked, the global default for security is checked. So this is the order. Remember to think about this as you're securing those sensitive groups. Now this is the flow when you actually go to set up security. So there's multiple different tabs because there's different kinds of security that someone can have in relation to a group, view, managing members, editing, scheduling, and administration. This makes it simpler to delegate certain things to volunteers or leaders such as scheduling, for example, that we'll talk about view, edit, and administrate. In this case, the way that Rock is gonna check the security is first, it'll go to the top and it will go down. So it'll look at Ted Decker and it sees that Ted Decker is given specific allow access, so it doesn't even need to check anything else if you're logged in as Ted Decker. Now, if you weren't Ted Decker, it would go see after that, are you in RSR Rock administration, which is our administration role in Rock. And if you weren't, it would go check staff workers, then staff workers, and then it would go down to all users and it would recognize that it says deny. So if you didn't fit any of those other permissions, then you would be denied access to viewing this group. Now each right has a different set of things that comes with it. For view rights, you can see the group and who is in the group. Pretty simple. For edit rights, you can change the group and you can manage membership. And membership, for example, is kind of the group role that someone is in. Then administration, this is everything above plus you can configure group sync, you can set up group requirements, you can configure group member attributes and set security on the group. That isn't exhaustive, but it's just an example of the things you can do. You can go in and really change a lot about how this specific group functions. Security allows you to hand groups to leaders with confidence because they can only see and act on things that you gave them access to.