The right access for the right officers.
Every officer position ships with a sensible default permission set out of the box. A platform Super Admin configures exactly which positions can view or edit each part of the platform during chapter setup: Treasurer to Finance, Risk Manager to Attendance and Social Monitors, Membership Educator to New Member Education and Academics, Alumni Chair to Alumni Relations, President and Vice President to full chapter-wide access.
A closer look at the permission matrix.
Illustrative example. A platform Super Admin configures each chapter's positions and matrix during setup.
| Module | President / VP | Treasurer | Risk Manager | Membership Educator | Alumni Chair | Recruitment Chair |
|---|---|---|---|---|---|---|
| Finance | Edit | Edit | N/A | N/A | N/A | N/A |
| Attendance | Edit | View | Edit | View | N/A | N/A |
| Social Monitors | Edit | N/A | Edit | N/A | N/A | N/A |
| New Member Education | Edit | N/A | N/A | Edit | N/A | N/A |
| Academics | Edit | N/A | N/A | Edit | N/A | N/A |
| Alumni Relations | Edit | N/A | N/A | N/A | Edit | N/A |
| Recruitment CRM | Edit | N/A | N/A | N/A | N/A | Edit |
| Judicial Board | Edit | N/A | View | N/A | N/A | N/A |
Enforced at the data layer.
Permissions aren't just hidden buttons in the interface. Access is enforced through Firestore Security Rules across three independent layers: a coarse role (Admin / Exec / Viewer), a per-chapter, per-officer-position permission matrix, and a platform-wide Super Admin flag.
Chapter-isolated by design.
ATO Executive System is built multi-tenant: every chapter's data is isolated from every other chapter's. The web app talks directly to Google Firebase (Firestore for data, Firebase Authentication for accounts) with no separate API layer to stand up or keep running.
Verified, not assumed.
CI runs on every code push: a syntax-check pass plus a real test suite that exercises the permission and security rules directly, so the access-control boundary is actually verified.
Responsible Disclosure
If you discover a security issue in ATO Executive System, please report it to atoexecutivesystem@gmail.com. We appreciate reports made in good faith and will work to address confirmed issues promptly.