Skip to main content

Public summary

Access control summary

Admin and partner permissions, with multi-factor authentication and separate roles for higher-risk actions.

Updated
August 30, 2026
Scope
Public summary
Escalation
Formal follow-up available

Current control position

Partner authority comes from active server-side membership, role, and location scope rather than editable profile hints. Reporting-only access excludes participant records, and sponsorship alone grants no participant or portal access.

Access control summary · Current public evidence boundary

Current safeguards

What Blacklight currently does

These statements describe implemented controls and their limits in plain language. They are not a certification, legal opinion, or substitute for an institution-specific contract requirement.

01

Partner and admin capabilities are split by role so routine visibility, billing actions, user management, and higher-risk controls do not all sit behind the same permission level.

02

Sensitive actions require stronger authentication, especially for account changes, partner-access decisions, or administrative overrides.

03

Location-aware and role-aware access boundaries are part of the model so larger organizations can limit what staff see when broader access is not appropriate.

04

Reporting-only users and aggregate-only event organizers do not receive participant records. Operational participant access must be explicitly assigned for a legitimate support need, and sponsorship alone never grants that access.