What each role can do
Everything you can see and do in the ITS portal comes from two things:
- your role, a named set of permissions that an administrator puts on your account; and
- your organisation: the AfCFTA Secretariat, a State Party, or a Regional Economic Community (REC).
The role decides which screens and buttons you get. The organisation decides whose data those screens show. Two people with the same role, one at a State Party and one at a REC, get the same screens with different data in them. This page covers the first. For the second, see the "What you see depends on who you are" boxes in each chapter.
If a menu item or a button in this manual is missing from your screen, your role does not include it. Nothing is broken.
The roles people hold
| Role (as the portal names it) | Who holds it | What it is for |
|---|---|---|
| System admin | The operator who runs the ITS deployment. The built-in its.admin account holds it. | Everything, including the roles screen. Nobody can grant it from the portal. |
| Secretariat admin | The AfCFTA Secretariat's administrator. The built-in afcfta.admin account holds it. | Governance, every report, the customs office register for all of Africa, and the Secretariat's own users. It reads declarations but cannot lodge or stamp them. |
| Organisation admin | The administrator of a State Party or a REC. | The organisation's own users, its customs offices, every report, and read-only access to declarations, all limited to the countries it administers. |
| Partner | The technical contact of a State Party or REC. | The organisation's integration workspace. It usually comes together with Organisation admin. |
| Customs officer | An officer at a customs station, usually working in a national customs system rather than in the portal. | Lodging declarations and stamping them along the corridor, plus two report areas. |
| Departure authority | The customs administration of the departure country. | Amending and cancelling its own declarations. |
For now, ITS is used system to system. A national customs system lodges, stamps, amends and cancels declarations through the ITS API, not through the portal. The declaration permissions below belong to those systems and to officers whose systems act for them. In the portal a person reads declarations; there is no button to lodge one.
The roles systems hold
The roles list also shows roles that are not meant for people. They let a connected customs system, or a part of ITS itself, do its job. Never give one to a colleague.
| Role | What it is |
|---|---|
| Partner system | A State Party's or REC's customs system calling ITS: it reads declarations, acknowledges what ITS sends it and reads a few reports. |
| Notification publisher, Reporting publisher | Used by ITS's own services to send messages and publish report definitions. They grant nothing in the portal. |
| Sandbox onboarding reconciler, Trust bundle reader | Used by ITS internally for onboarding and certificates. |
| State party admin | An older name for Organisation admin. It grants no permissions. See the caution below. |
State party admin is the old name of Organisation admin. It still appears on the roles screen with 0 permissions, and on the development system one account still holds it. Somebody who holds only this role can sign in and do nothing. Give Organisation admin instead.
How to read the tables
| Mark | Meaning |
|---|---|
| Yes | The screen or button is there and works. |
| Read only | The screen opens and you can search and filter, but the buttons that change something are not there. |
| No | Not shown. The portal hides what you may not use instead of greying it out. |
| System | Done by a connected customs system through the API, not in the portal. |
Screens
| Screen | System admin | Secretariat admin | Organisation admin | Partner | Customs officer | Departure authority |
|---|---|---|---|---|---|---|
| Overview | Yes | Yes | Yes | No | Yes | Yes |
| Declarations list and declaration pages | Yes | Yes | Yes | No | Yes | Yes |
| Failed transmissions | Yes | Yes | Yes | No | Yes | Yes |
| Notifications and the bell | Yes | Yes | Yes | Yes | Yes | Yes |
| Reports: Transit volumes, Time & delays | Yes | Yes | Yes | No | Yes | No |
| Reports: Register | Yes | Yes | Yes | No | Yes | No |
| Reports: Integration | Yes | Yes | Yes | No | No | No |
| Reports: Workforce | Yes | Yes | Yes | No | No | No |
| Governance | Yes | Yes | No | No | No | No |
| Customs offices | Yes | Yes | Yes | Read only | Read only | Read only |
| Users | Yes | Yes | Yes | No | No | No |
| Roles | Yes | No | No | No | No | No |
| Track a consignment, Verify a document | Yes | Yes | Yes | Yes | Yes | Yes |
Track and Verify are public: anyone can use them, signed in or not.
If your role reads some report areas but not others, Reports shows only the tabs you may open. Each tab opens completely or is not shown, so an empty tile always means "nothing happened", never "you may not see this".
Declarations
| Action | System admin | Secretariat admin | Organisation admin | Customs officer | Departure authority | Partner system |
|---|---|---|---|---|---|---|
| Read a declaration, its history and its transit document | Yes | Yes | Yes | Yes | Yes | System |
| Lodge a declaration | System | No | No | System | No | No |
| Stamp it along the corridor | System | No | No | System | No | No |
| Amend it | System | No | No | System | System | No |
| Attach documents | System | No | No | System | No | No |
| Cancel it | System | No | No | No | System | No |
| Acknowledge an announcement from ITS | System | No | No | No | No | System |
The Secretariat reads declarations but never lodges goods into the system. That is intended.
Customs offices
| Action | System admin | Secretariat admin | Organisation admin | Everybody else who can open it |
|---|---|---|---|---|
| Read the register for all of Africa | Yes | Yes | Yes | Yes |
| New office, Edit, Withdraw, reopen | Every country | Every country | Only the countries it administers | No |
| Bulk Upload | Every country | Every country | Only the countries it administers | No |
| Export | Yes | Yes | Yes | No |
A REC administers only the members that have delegated their submissions to it, not every member of the community. See Governance.
Governance
Only the Secretariat (System admin and Secretariat admin) can open Governance. It records which countries take part, which RECs exist, who their members are and who submits for whom. Organisation admin cannot see it at all.
Users
| Action | System admin | Secretariat admin | Organisation admin |
|---|---|---|---|
| See the organisation's users | Yes | Yes | Yes |
| Add user, Edit | Yes | Yes | Yes (see the caution) |
| Bulk Upload | Yes | Yes | Yes |
| Deactivate and reactivate | Yes | Yes | Yes |
| Record a duty station posting | Yes | Yes | Yes |
Who may give which role. An administrator can only give the roles their organisation is allowed to give:
| The administrator works for | They can give |
|---|---|
| The Secretariat | Secretariat admin, Organisation admin, Customs officer, Departure authority, Partner |
| A State Party | Customs officer, Departure authority |
| A REC | Customs officer |
System admin can never be given from the portal. A REC can staff its own gateway but not a member's customs service.
On the current version of the portal, Add user and Edit open nothing when an Organisation admin selects them: no window, no message. The permission is there; the screen does not act on it. Until this is fixed, ask the Secretariat to create or change accounts in your organisation. See Users.
ITS refuses to deactivate the last active Secretariat admin or Organisation admin of an organisation, because nobody inside it could then give the role back.
Roles
Only System admin can open the roles screen, look at what a role grants, and create, copy, change or delete a custom role. Secretariat admin and Organisation admin have no Roles tab. Typing its address shows a page that keeps loading. See Roles and permissions.
The roles in plain words
System admin. The operator. Everything in the portal and the API. Keep it to the people who run the deployment.
Secretariat admin. The Secretariat's administrator. Governs who takes part and who submits for whom, maintains the customs office register on everyone's behalf, reads every report and every declaration, and manages the Secretariat's own people. It never lodges, stamps or amends a declaration.
Organisation admin. The administrator of one State Party or one REC. Reads the declarations and reports of the countries it administers, keeps its customs offices up to date, and manages its own people. It is the same role for a State Party and a REC. The data differs because the organisation differs.
Partner. The technical contact who connects the organisation's customs system. On its own it opens the integration workspace, the customs office register (read only) and notifications, and nothing else.
Customs officer and Departure authority. Roles for the people and systems that act on declarations: lodging and stamping (officer), amending and cancelling (departure country). Their work happens in the national customs system, which calls ITS.
Related pages
- Roles and permissions: how to read what a role grants.
- Users: giving roles to people.
- Governance: why a REC may act for some members and not others.