Manage Profiles
Use Profiles to find a person and maintain their staff record. The page is plan-gated by community_profiles; opening the list or a profile needs profiles:read.
Profile controls and access
| Control or area | C2 visibility | Required API permission | Result |
|---|---|---|---|
| Profile list, filters, and a profile card | profiles:read | profiles:read | Finds and opens people records. Filters and card/table view do not alter data. |
| Header wrench | Your own profile, or profiles:update | Own alias: no role permission; another profile: profiles:update | Saves an alias between 2 and 255 characters. |
| Background image | Your own profile, profiles:update, or profiles:modify-background | The API’s standard profile update route; confirm dedicated media enforcement before creating a least-privilege role | Uploads and saves the background image. |
| Avatar image | Your own profile, profiles:update, or profiles:modify-avatar | The API’s standard profile update route; confirm dedicated media enforcement before creating a least-privilege role | Uploads and saves the avatar image. |
| Status badge with wrench | profiles:modify-statuses | profiles:modify-statuses | Sets or clears the profile status. |
| Recruiter badge | profiles:update | profiles:update | Turns the recruiter flag on or off. It does not grant a role. |
| Rank, primary unit, or primary position wrench | C2 currently checks profiles:update | API requires respectively profiles:modify-ranks, profiles:modify-units, or profiles:modify-positions | Sets or clears the single primary assignment. |
| Qualifications, awards, units, or positions wrench | C2 currently checks profiles:update (units use units:update) | API requires the matching profiles:modify-* permission | Adds/removes the selected profile attributes. |
| Metadata edit | profiles:modify-metadata | profiles:modify-metadata | Adds, edits, or removes custom key/value profile metadata. |
| Roles card | roles:read or legacy roles:view to show; profiles:modify-roles to change | profiles:modify-roles | Assigns or removes C2 roles. |
| Notes | Individual note permissions | profile-notes:read, :create, :delete | Opens internal notes; creates or deletes a note. |
| Delete | profiles:delete, but disabled for your own profile and a profile with the admin role | profiles:delete | Opens the destructive deletion confirmation, then returns to Profiles. |
C2/API mismatch: C2 exposes rank, assignment, and attribute-edit controls under
profiles:update, but the Spring API uses the narrowerprofiles:modify-*keys listed above. Grant both the C2-visible key and the relevant API key, then test with a non-owner account until this is reconciled.
Change an alias, image, status, or recruiter flag
- Open Profiles, find the person, and open their profile.
- Select the header wrench to edit an alias; enter 2–255 characters and select Save.
- Select either image button to upload a background or avatar. The new image is saved immediately after upload succeeds.
- Select the status badge with the wrench, choose a status (or the clear option), then select Save.
- Select the recruiter badge, change Recruiter in the dialog, then select Save.
If a save fails, leave the current value in place and use the shown error rather than repeating the request. A status can be cleared; image changes and alias changes do not have a dedicated undo control.
Change assignments and attributes
Use the cards below the profile header.
- Select the wrench on Rank, Duty Assignment, or the relevant attribute card.
- Choose the assignment(s) required and select Save.
- Re-open the card and confirm the saved item is displayed.
Rank, primary unit, and primary position are single assignments. Qualifications and awards support add/remove selection. Unit assignments can expose slots: a primary unit, a unit membership, and a roster slot are separate records. Check the expected one after every move.
For bulk changes, open the relevant attribute’s detail page and use its profile-assignment tool; see Manage Attributes And Folders.
Notes, metadata, roles, and history
- Select Notes to open the internal-note drawer. Reading, writing, and deleting are independently controlled. Notes are staff context, not public messages.
- In Metadata, use the edit control to add or remove custom fields, then select Save. Only
profiles:modify-metadataexposes it. - In Roles, select the wrench, choose an unassigned role, and select Assign. Use the remove control beside an existing role to remove it. Changing roles affects C2 access immediately; see Roles And Permissions.
- Review profile history before reversing an important change. The C2 screen has a delete-log control, but its customer-facing permission is not established; do not include it in a role recipe.
Delete a profile carefully
- Confirm that you are not deleting your own profile or a profile carrying the
adminrole; C2 disables the control for both. - Select the red Delete button.
- Read the confirmation and only confirm when the entire profile should be removed.
This is not a roster-cleanup action. Use assignment or slot controls when the person should remain in the community.
Verification notes
- Profile media controls are visible under the conditions stated above, but C2 saves them through the standard profile update route. The dedicated
profiles:modify-avatarandprofiles:modify-backgroundkeys are in the canonical catalogue; endpoint-level enforcement needs a role-matrix test. - The
roles:viewcheck is legacy C2 compatibility code and is not inabilities.json; useroles:readin roles. - Operational-check information appears when C2 sees
attendance-statuses:reador legacyattendance_status:read. It is view-only and is not a profile-edit permission.