Aug 04, 2026
SIRAS User Access Roles and Permissions
User Access Roles control the type and breadth of access assigned to a SIRAS user account. Roles are assigned on the User Account tab under Tools → Manage Users / My Account.
Most users do not need an Access Role. An account with no Access Role is a General User and normally sees only the student records assigned to that user.
Assign the narrowest access that supports the person's job.
Normally, assign only one district- or school-level role. Add another role only when a separate module or specialized function requires it.
Normally, assign only one district- or school-level role. Add another role only when a separate module or specialized function requires it.
In This Guide
| How Access Works | General User & Add-On Roles |
| District-Level Roles | School & Site Roles |
| SELPA & Specialized Roles | Assigning and Reviewing Roles |
| Role Assignment Examples | Related Help |
How Access Works
- A user may be assigned more than one Access Role, but this is not usually necessary.
- Each role contains permissions defined by SIRAS. Those permissions may be revised as program requirements change.
- Roles are associated with one or more SIRAS designations or modules: Special Education, 504, or SST.
- A login uses one designation at a time. The effective permissions are the combination of the roles assigned for that designation.
- District- and school-level roles normally should not overlap. For example, a District SPED Clerk generally should not also be assigned District Admin 1.
- District, school, and SELPA assignments determine where a broad role applies. Student assignments determine which records a General User can access.
Example: A user may need 504/SST Coordinator access for 504 work and School Read Only access for Special Education. The permissions shown depend on the designation currently selected.
For the detailed permission matrix, see the Chart of User Access Roles (PDF).
General User and Add-On Roles
| Role | Access and intended use |
|---|---|
| No User Access Role (General User) | Access is limited to individually assigned student records. This is the normal configuration for most providers and teachers. |
| Gen. User - Read Only | Read-only access to individually assigned student records. |
| Gen. User - Edit Providers | Access to individually assigned records, plus the ability to add other users to records the account already can access. Useful for staff who help maintain peer caseload assignments. |
| Goals and Progress Service Log Only | A specialized add-on for a General User whose work is limited to goals, progress, and service logging. |
| 504/SST Clerk | Highest administrative access within the 504 and SST modules. May create records and users, subject to the account's assigned scope. |
| 504/SST Coordinator | Administrative access within the 504 and SST modules. May create records but not users. |
| CALPADS Access | An add-on used with an appropriate district-level role to allow SEDS data submission and CALPADS-related functions. |
See How to Set Up SST and 504 Roles for the legacy module-specific setup reference.
District-Level Roles
| Role | Key capabilities and limitations |
|---|---|
| District SPED Clerk | Highest district-level Special Education access. May manage users, transfers, passwords, student and school assignments, MIS Summary unlocking, meeting reactivation, onboarding, and offboarding. Use only for staff who need this level of control. Charter LEAs generally use this role instead of a school-level clerk role. |
| District Admin 1 | May create student records, edit provider assignments, approve transfers, and support onboarding. Cannot create new users. Appropriate for trusted directors, program specialists, or office staff who need broad district access without full SPED Clerk authority. |
| District Admin 2 | May add or remove providers and update records created through SIS integration. Cannot create students or users and cannot approve transfers. |
| District Read Only | Read-only access across the assigned district. May support SIS audits, Forms Status review, or document uploads. An individual student assignment can grant edit access to that specific record. |
| District Wide | General-user editing access across the assigned district without the administrative functions of a District Admin or SPED Clerk. Useful for staff such as nurses who need to review or work with records across the district. |
School and Site Roles
| Role | Key capabilities and limitations |
|---|---|
| School SPED Clerk | Highest school-level Special Education access. May manage users, transfers, passwords, assignments, MIS Summary unlocking, meeting reactivation, onboarding, and offboarding for the assigned site. May also be used for charter-school administrators. |
| School Admin 1 | May request and submit school transfers, edit school and provider assignments, and unlock the MIS Summary page. |
| School Admin 2 | May edit provider assignments for records within the assigned school scope. |
| School Read Only | Read-only access to records at assigned sites, with the ability to upload scanned documents for reference. An individual student assignment can grant edit access to that specific record. |
| Site Wide | General-user editing access across the assigned school or schools without school-administrator functions. |
| Incoming School Read Only | Read-only school-level access used to review incoming students. |
SELPA and Specialized Roles
| Role | Access and intended use |
|---|---|
| SELPA User | Access to records in all assigned LEAs within the SELPA, including transfer-related functions. |
| SELPA User (no transfer) | Similar to SELPA User, but does not allow initiating or approving transfers between districts. |
| SELPA Read Only | Read-only access to records in all assigned LEAs within the SELPA. |
| Service Log Only | Service Log data entry for individually assigned records only. |
| Service Log Only (District wide) | Service Log data entry across the assigned district. |
| Service Log Only (School wide) | Service Log data entry across assigned schools. |
| Translator (Individual) | Access to specifically assigned records that have an incomplete meeting marked Translation Required. |
| Translator (School) | Access to records at assigned schools that have an incomplete meeting marked Translation Required. |
| Translator (District) | Access to records in the assigned district that have an incomplete meeting marked Translation Required. |
| Temporarily Block Access | Prevents the user account from logging in to SIRAS. |
Assigning and Reviewing Roles
- Go to Tools → Manage Users / My Account.
- Choose the user and open the User Account tab.
- Confirm the user's designation: Special Education, 504, or SST.
- Identify the required scope: individually assigned students, school/site, district, or SELPA.
- Assign the single role that most closely matches the person's duties.
- Add a specialized role only when a separate function or module requires it.
- Confirm the user's district and school assignments.
- Save the account and test the resulting scope and permissions.
Avoid using broad access to solve an assignment problem.
When the user should work with only particular students, correct the student's provider or user assignment instead of granting district- or school-wide access.
When the user should work with only particular students, correct the student's provider or user assignment instead of granting district- or school-wide access.
Role Assignment Examples
No User Access Roles: the account functions as a General User and accesses individually assigned records.
User Access Role assigned: review the role description and the account's district and school assignments to determine the resulting access.

