SHARING PARISH FIGURES - REPORTS LOGINS ======================================= A parish treasurer, a section leader or a stewardship committee often needs to see the figures they are responsible for. Usually they have no email address, no account on parishrecordkeeper.com, and no computer of their own - only a phone. Giving them a full parish account would hand them everything: the whole database, the baptism register, the member list. The better solution is to grant them access only to what they need. This feature does what the transport booking page already does for catechists. The parish administrator creates ONE SHARED USERNAME AND PASSWORD, hands it out, and that is all the person needs. There are two ways in, with the same username and password: - THE PRK FINANCE APP, at parishrecordkeeper.com/finance/ - an icon on the phone's home screen, like any other app. This is the one to give people who look at the figures regularly: it can KEEP THEM SIGNED IN FOR 90 DAYS, so they are not typing a username and password every time, and the accounts open without a network once the copy has been downloaded. ONE APP, TWO JOBS. Transport booking is part of the same app rather than a second one: on the Data tab there is a switch, "This phone also takes transport bookings", and a phone that ticks it gets the booking page too. It is off unless it is ticked, so a treasurer who never books is not shown a link that means nothing to them. Ticking it grants nothing by itself - the booking username is still needed to sign in. THE PARISH REGISTER IS NOT IN THIS APP. There is no church-records tab and no baptism-book tab, and the copy the phone downloads carries only the few person details the money views need: the name to put on a figure, the area, the lay group and category the contributions sheet filters on. Birth, baptism, confirmation, marriage, parents, godparents, address and telephone never reach such a phone at all. The register stays with the parish team, in PRK Admin. - THE WEB PAGE parishrecordkeeper.com/report.php - the same figures in an ordinary browser, for somebody who does not want to install anything. A reports login is NOT a member account. It can open the reports listed below and nothing else - not the shared data file, not the member list, not the baptism register. WHAT THEY CAN SEE ----------------- - THE CONTRIBUTIONS SEARCH: who has given what, for a chosen year, with one column per contribution account, and a spreadsheet (CSV) download. This is the same list as the contributionsSearch window in the program. - THE ACCOUNT LEDGER: every transaction of one account with a running balance. The same view as the LedgerSingleAccount window. - THE AREA SHEET: the accounts totalled per area. The same view as the accountAreaCombined window. The ledger and the area sheet live inside the app on the phone. Once the copy has been downloaded over a connection, they keep working out where there is no network at all. The parish team do not need a reports login for any of this: their own PRK ADMIN app already holds the same views for the whole parish, and the transport booking page with them. The baptism register is deliberately left out of what a reports login receives, whether it is for the whole parish or for one area. A sacramental register is not a report. TWO DECISIONS WHEN YOU CREATE ONE --------------------------------- 1. HOW MUCH MAY IT SEE? THE WHOLE PARISH - for a parish treasurer or a finance committee. ONE AREA ONLY - for a section leader. You choose the level (whatever your parish calls them: Station, Prayer Centre, Section) and then the area itself. That login then sees only the people whose card sits in that area. Everybody else is not hidden from view - they are never sent to the phone at all, which matters because the copy is stored on the phone. Somebody who looks after two sections gets two logins. That is on purpose: it keeps the access log able to say WHICH hat was being worn. 2. MAY IT SEND CORRECTIONS? READ-ONLY - they can look, and nothing more. MAY SEND CORRECTIONS - when a figure looks wrong, or a contribution is missing, they can mark it on the phone. A CORRECTION NEVER CHANGES THE PARISH RECORDS BY ITSELF. It travels to you as a NOTE, exactly like a note from the PRK Admin app, and you go through the notes one at a time in the Server Actions window and decide which to accept. Nothing is written until you do. Even with this right, a shared login can never add a new person or a new baptism entry. Creating a parishioner is the parish office's own act. If they are area-scoped, they can only write about people inside their own area; a note about anybody else is refused before it ever reaches you. STAYING SIGNED IN FOR 90 DAYS ----------------------------- On the sign-in screen there is a box: "Keep me signed in on this phone (90 days)". When it is ticked, that phone re-opens the app without the username and password until 90 days have passed without it being used; every use pushes the 90 days out again, so a phone in regular use never meets the sign-in screen at all. It is off unless the person ticks it, and it should be ticked only on their OWN phone. The password is shared, so a phone that stays signed in shows the parish figures to whoever picks it up. The screen lock of the phone is what protects it; the PIN inside the app (Data tab) is a second lock on top. Nothing is stored on the phone except a key that only names the login - no password, and no parish data beyond the copy that was downloaded. THE PARISH OFFICE CAN END IT AT ANY TIME, from either side: the SIGN OUT PHONES button in the REPORTS LOGINS window of the program, or the "Phones kept signed in" column on the workspace page of the website, which has the same button and shows how many phones each login is sitting on. Every phone then has to type the password again, while the login itself goes on working for everybody else. Use it when a phone is lost or handed on. Switching the login off, or deleting it, ends the remembered phones as well - and locks everybody out at once, which is the right tool when the password itself has gone astray. A phone that has the reports open at that very moment keeps them for a few more minutes, until its session ends. To lock everybody out this second, switch the login off. THE ACCESS LOG -------------- Because the password is shared, the program cannot know by itself WHO is using it. So everyone signing in is asked to type their own name once, and that name is written beside everything they do. Every sign-in, every search, every spreadsheet downloaded and every correction sent is recorded, with the date, the name they gave and the area they were signed in for. Refused attempts are recorded too. A phone that let itself in because it was told to stay signed in is logged as well, as "remembered phone" - a sign-in that cost nobody a password still belongs in the record. The log is the whole of the accountability here, so it is worth reading occasionally. It survives deleting the login: taking the credentials away must never erase the record of what was done with them. EXPORTING THE LOG. EXPORT THE LOG, in the reports logins window of the program, writes the whole log - oldest entry first, and with the IP address the window's own list leaves out - to a CSV file in the Exports folder beside the program, and offers to open it. Nothing on the server is changed by exporting. Do this before clearing the log if the parish wants to keep the record: a spreadsheet can be filed away, printed, or sent to the diocese. DELETING THE LOG. There is a button for it - DELETE THE LOG in the reports logins window of the program, and the same on the workspace page of the website - for a log that has grown into thousands of lines and buried what matters. You are asked to type DELETE first, because this is the one action that takes away the record of what everybody else did; the logins themselves and the corrections already sent are untouched. One line is written in place of what was removed, naming you and saying how many entries went, so the log can never quietly become empty. THE REPORTS LOGINS WINDOW - WHAT EACH BUTTON DOES ================================================= Open it with the REPORTS LOGINS button in the "Other workspace features" column, on the right of the Server Actions window, under TRANSPORT. You must be signed in, and you must be an administrator of the workspace - a plain member is refused by the server, which says so. THE LIST AT THE TOP ------------------- One line per login: the username, who it is for, what it may see, whether it may send corrections, whether it is switched on, and when it was last used. Click a line to select it before using the buttons beside REFRESH LIST. REFRESH LIST ------------ Asks the server for the list again. Use it after somebody else has made a change, or if you are not sure what you are looking at is current. Nothing is changed by pressing it. SWITCH ON / OFF --------------- Takes the login selected in the list and switches it off, or on again. SWITCHING OFF TAKES EFFECT IMMEDIATELY - including for phones that are signed in at that second. The website checks the login on every single request, so it does not wait for anybody to sign out. This is what you press when a phone is lost, or when somebody leaves the committee. The login is not deleted: switch it on again and the same username and password work as before. SIGN OUT PHONES --------------- Ends the 90 days on every phone that was told to stay signed in with the selected login. Each of them has to type the username and password again the next time; THE LOGIN ITSELF GOES ON WORKING, so everybody else can carry on reading the figures. This is the button for a phone that was lost or handed on to somebody else - the one case where switching the login off would punish the whole committee for one phone. The message tells you how many phones were signed out, or that none was. A phone with the reports open at that very moment keeps them for a few more minutes, until its session ends. When it is the PASSWORD that has gone astray rather than a phone, use SWITCH ON / OFF instead: that stops everybody, this second. DELETE LOGIN ------------ Removes the selected login for good. You are asked to type the username back before anything happens, so a stray click cannot do it. Everybody using it is locked out at once. Corrections they already sent stay in your queue, and the access log keeps what was done with the login. To lock out one lost phone but keep the others working, DO NOT delete it - give the login a new password instead (see below) and tell the others the new one. USERNAME / PASSWORD / FOR WHOM ------------------------------ The three boxes for creating a login, or changing one that already exists. USERNAME must be unique across the whole website, not just your parish, so put the parish name in it - for example "lumimbatreasurer". Letters, digits, dot, hyphen and underscore only; no spaces and no accents. PASSWORD may be left EMPTY, in which case the server invents one for you. If you type one it must be at least 8 characters. THE PASSWORD IS SHOWN ONCE, in the message that appears after you press SAVE LOGIN, and never again. Write it down before you close that message. FOR WHOM is just a note to yourself - "parish treasurer", "St Peter's section leader" - so the list still makes sense to you in a year's time. MAY SEE THE WHOLE PARISH (tick box) ----------------------------------- Ticked, the login sees the figures of the entire parish. Unticked, the two boxes below it come alive and you choose ONE area: first the level, then the area itself. The list of areas comes from your own parish data, so it is empty until the parish database has been uploaded to the server at least once. MAY ALSO SEND CORRECTIONS (tick box) ------------------------------------ Ticked, the login may send corrections for you to review. Unticked, it can only read. SAVE LOGIN ---------- Creates the login, or - if the username already exists - updates it. Typing an EXISTING username here is how you change a login: its scope and its rights are saved as you have set them, and if you also typed a password, that password is changed. Everybody using the old password has to be told the new one, which is how you lock out a phone that was lost. Saving an existing login also switches it back on if it was switched off. ACCESS LOG (the list at the bottom) and REFRESH LOG -------------------------------------------------- The most recent entries, newest first: when, which login, the name the person gave, and what they did. REFRESH LOG fetches the latest entries from the server. ? (bottom of the window) ------------------------ Opens this file. The same ? sits beside the REPORTS LOGINS button on the Server Actions window. CLOSE ----- Closes the window. Nothing is left half-done: every button above finishes its work with the server before it returns. WHAT THE OTHER PERSON DOES ========================== 1. They go to parishrecordkeeper.com/report.php on their phone. 2. They type the username and password you gave them. 3. They are asked for their own name, once. It is remembered on that phone afterwards. 4. They get a short page listing what they may open. If they ever see somebody else's figures, or cannot see their own, the scope on their login is wrong - change it with SAVE LOGIN and it takes effect the next time they load a page. THINGS WORTH KNOWING ==================== - Signing in with a reports login on a computer where somebody is signed in with a parish account ENDS that parish session. This is deliberate: the two must never be held at the same time, or the shared login would quietly inherit the member's full view. The member simply signs in again. - If the parish's online subscription has lapsed, the figures can still be READ but corrections cannot be sent. An area leader halfway through checking last Sunday's collection should not lose the figures because the parish is a week late paying. - Ten wrong passwords from the same place lock that place out for fifteen minutes. A shared password is weaker than a personal one, so this matters more here than elsewhere. - The figures are always AS OF THE LAST UPLOAD of the parish database. If a treasurer says the numbers look old, the answer is usually that the parish database has not been uploaded recently. - Give these out with care. Anybody who knows the two words can read those figures, and unlike a member account there is no way to tell two users of the same login apart except by the name they typed.