Skip to content

Administration & security

A multi-campus CRM with the controls IT expects.

Define roles down to the action on each page, mask contact details for roles that don't need them, organize users into teams and campuses, and protect sign-in with SSO and MFA. Audit logs and encryption give you a secure CRM you can explain to your data protection officer.

  1. Edit the Counselor role: 18 users assigned
  2. Leads: turn off Export for this role
  3. Mask contact details: calls and emails still work
  4. Update Role saves the new permissions
  5. CRM Users: who holds the Counselor role
  6. The User Journey Log records the role change
Recreated product screens with fictional sample data.

Custom roles

Roles for admissions, the registrar and finance, down to each action.

Build roles for admissions directors, counselors, program directors, registrar and finance staff. On each page, tick the actions a role may take, grouped by area, and the roles list shows how many users hold each one.

  • View, create, edit, delete and export rights on each page
  • Start from a template, import roles or duplicate one
  • Bulk role assignment when seasonal readers join for the cycle
  • Deactivate a role once no users hold it
  • Masked phone numbers and emails for the roles you pick

Schools, campuses and admissions offices, mapped once.

Set up reporting lines, teams and campuses so targets and dashboards follow the way your institution is organized, from one admissions office to colleges and universities with several campuses, schools and an online division. Every account has the same controls.

User hierarchy & teams

Reporting lines for each admissions office.

Place each user in the hierarchy and in teams such as undergraduate, graduate or international admissions. A team lead opens the team dashboard to see each counselor's leads, applications, overdue follow-ups and progress against targets.
  • Managers and direct reports in a user hierarchy
  • Teams for undergraduate, graduate and international admissions
  • Team targets split equally across members, or set per person

One account, with campuses, schools or departments beneath it.

Your institution sits at the top as the organization, and each campus (an institute in the app) can be a physical site, a school or department such as nursing, or an online division. Staff move between the campuses they have access to from the header, and each campus can show its own logo.
  • Your institution at the top, campuses beneath it
  • Campus switcher in the header
  • A logo for the organization and for each campus

Secure admissions CRM

Controls your IT office can inspect and turn on.

Administrators connect OpenID Connect SSO and set the MFA policy. Each staff member reviews and ends their own sessions, and an API key, such as the one your SIS integration uses, can be limited to an IP allow-list. The trust center describes each control for your IT and data protection review.

  • OpenID Connect SSOStaff sign in with their existing accounts through your identity provider.
  • Multi-factor authenticationAuthenticator app plus backup codes, set by administrators as optional or mandatory.
  • Active session reviewEach staff member sees their devices, browsers and IP addresses, and can end any other session or log out everywhere.
  • Audit logsStaff activity with old and new values, plus an audit history on each applicant's record.
  • AES-256 encryptionFor custom fields you mark as encrypted, such as passport numbers, and for stored integration credentials.
  • IP allow-lists for API keysAn API key, such as the one your SIS integration uses, accepts calls only from the address ranges you list.
  • Rate limitingLimits on request volume that help guard against abuse.
  • Verified inbound webhooksWebhooks from your portal or other systems are checked by HMAC signature or secret before they are accepted.
  • Contact masking by roleRoles such as student callers see partial phone numbers and emails, yet can still call, text and email.

Audit logs

Show who changed an applicant record, and when.

Staff activity is recorded with old and new values, along with navigation, security events, exports, role changes and workflow edits. Each lead also keeps its own audit history of stage changes, assignments, documents and messages.

FERPA and GDPR support

Opt-out checks before each send, masking by role, audit logs and field encryption support your FERPA and GDPR obligations. Your registrar and data protection officer set the policies.

How the trust center covers each control

44-language interface

International admissions staff can work in their own language.

Each user picks an interface language in the top bar. Newer areas such as campaigns, workflows and chatbots are English-only today, so ask us to walk through coverage for the languages your offices use.

44 interface languages, right-to-left included.

Preparing for an IT security review?

We'll take your IT and data protection staff through roles, SSO, MFA, sessions and the audit log, set up the way your campuses and offices are organized.

FAQ

Questions from IT, the registrar and the provost's office

Can we build separate roles for admissions, registrar and finance staff?

Yes. Create custom roles and tick, page by page, the actions each one may take, such as view, create, edit, delete or export, grouped by area. You can start from a role template, import roles or duplicate an existing one, then assign it in bulk when seasonal application readers join for the cycle.

How do we set up several campuses, schools or an online division?

Your college or university is the organization, with campuses (called institutes in the app) underneath. A campus can be a physical site, a school or department within the university, or an online division. Staff switch between the campuses they have access to, and the organization and each campus can carry their own logo.

Can staff sign in with our own identity provider?

Yes, if your identity provider supports OpenID Connect; SAML is not supported. Multi-factor authentication with an authenticator app and backup codes works with or without SSO, and administrators can make it mandatory.

The provost's office wants to know who can see and change applicant data. What can we show them?

The roles screen lists each role's page and action permissions and how many users hold it. The audit log records staff activity with old and new values, navigation, security events and exports, including role changes and workflow edits, and each lead keeps its own history of stage changes, assignments, documents and messages. Access to the audit log is itself controlled by role permissions.

What happens to access when a staff member leaves the admissions office?

Deactivating the user signs them out on every device. Day to day, each user manages their own sessions: they see the device, browser, IP address and last access for each one, and can end any other session or log out of all devices. Administrators can't end another user's individual sessions.

Does higheredcrm.ai support FERPA and GDPR compliance?

It provides controls that support those obligations: role permissions and contact masking, audit logs, encryption of custom fields you mark as sensitive, MFA and SSO, and do-not-contact and per-channel opt-outs checked before each send. Your registrar and data protection office still decide the policies, such as which staff may see student records.

Can international admissions staff use the CRM in their own language?

Each user picks an interface language from the top bar, from 44 options including right-to-left languages. Newer areas such as campaigns, workflows, chatbots, WhatsApp settings and API access are in English only today, so check coverage for the languages your offices use during your evaluation.

Glossary: FERPA, GDPR, CRM vs SIS · Trust center · Developers & API · Integrations · higheredcrm.ai for IT teams

Bring your IT and data protection questions to a demo.

Send us your security questionnaire or list of concerns first. We'll set up your campuses and roles, then check SSO, MFA, masking and the audit log against it, the way your reviewers would.