Admin Systems Management
MOL Administrator Permissions Management - S-1 Procedural Page
Manage Marine Online access through NIS, assign module-level permissions, activate UD/MIPS users, and remove access at detach or role change.
T&R Event Details
- Event Code
- 0102-GENA-1015
- Source Policy
- NAVMC 3500.3E
- MOS Performing
- 0102, 0111, 0170
- Grades
- Sgt, SSgt, GySgt
- Sustainment Interval
- 12 months
- Evaluation-Coded
- No
- Readiness-Coded
- No
Performance Steps (T&R)
- Publish command guidance on MOL access scope
- Acquire MOL administrator entitlements through MISSA
- Identify required users by billet and module
- Assign module-level permissions
- Validate access in each assigned module
- Train users on assigned modules
- Document permission assignments in a Page 11 entry
- Audit permissions monthly against the billet roster
- Activate UD/MIPS users in Manage Users from pending to active
- Run the DTMS Manage Permissions Annual Review
- Remove permissions on detach or role change
- Reconcile the permission roster against the billet roster
Role and responsibility
The S-1 officer (0102) owns command guidance on MOL access scope. The S-1 chief (0111 SSgt or higher) holds MOL administrator entitlements and assigns module-level access to clerks. The S-1 clerk operates within the assigned module set. The unit security manager audits MOL permissions during the quarterly account review.
Source documents flow from command guidance memos, billet assignments, and the NIS access requests tied to Marine Online access. Administrator actions live inside NIS Manage Permissions for DTMS and UD/MIPS Manage Users, and inside the MOL administrator interface for the remaining modules. MISSA is the functional manager for MOL Permission Management and User Management. Outputs include the permission roster, the Page 11 entries documenting access, and the OMPF Field Folder systems tab entry per Marine.
MCAAT inspects the permission roster against the billet roster, the command guidance memo, and the monthly audit signature. Blanket permissions, stale permissions on departed Marines, and permissions assigned without command guidance trigger findings under MCO 5239.2BMCO 5239.2B.
Trigger events
- New command guidance published changing MOL access scope.
- Inbound clerk needs MOL access for assigned billet.
- Billet change moves a clerk to a new module set.
- New MOL module released requiring permission assignment.
- Departing clerk needs permission removal at detach.
- Quarterly review identifies stale permissions.
- Misconduct event requires permission suspension.
Processing workflow
- Publish command guidance. The S-1 officer issues a command memo defining MOL access scope by billet, module, and grade per NAVMC 3500.3ENAVMC 3500.3E T-R event 0102-GENA-1015 performance step 1.
- Acquire MOL administrator entitlements. The S-1 chief requests the MOL administrator entitlements through MISSA, the functional manager for MOL Permission Management, per MCO 5000.14DMCO 5000.14D enclosure 6.
- Identify required users. Cross-check the billet roster against the command guidance to identify which users need which modules.
- Assign module-level permissions. Use the MOL administrator interface to assign permissions per user per module. Cover CLA, DTMS, MROWS, promotions, pro and con marks, APES, OMPF, personnel information, UMSR, BIC assignment, leave management, and permissions per the T-R event misc note.
- Validate access. Confirm the user navigates each assigned module per NAVMC 3500.3ENAVMC 3500.3E T-R event 0102-GENA-1015 performance step 4.
- Train users on assigned modules. Run module-specific training before the user submits live transactions. The S-1 chief trains.
- Document permission assignments. Cut a Page 11 entry recording each user's MOL access per MCO P1070.12KMCO P1070.12K Chapter 6.
- Audit permissions monthly. Pull the permission roster and reconcile against the billet roster. Flag stale or over-permissioned accounts.
- Remove permissions on detach. Remove all module-level permissions at certified detach per NAVMC 3500.3ENAVMC 3500.3E T-R event 0102-GENA-1015 performance step 5.
- Reconcile against the billet roster. Update the permission roster after every change. Reconcile at the next quarterly review.
NIS Manage Users and Manage Permissions
NIS carries user activation and annual review for Marine Online applications.
- Activate the UD/MIPS user. After the Information Owner approves the request, open Manage Users in UD/MIPS and set the account from pending to active. The account stays inactive until you make this change.
- List RUC users. Manage Users lists all RUC user information for the Certifier Commander and Certifier Account Provisioner roles. The list ties to those Certifier roles and does not assign outside those NIS UD/MIPS entitlements.
- Run the DTMS Annual Review. For DTMS-enabled organizations, the Manage Permissions Annual Review lists all DTMS assigned users. The review keeps the ability to unsuspend users held for inactivity.
Systems of record and forms
Systems
- NIS Manage Permissions. Assigns and reviews DTMS permissions, including the Annual Review of DTMS assigned users.
- UD/MIPS Manage Users. Lists RUC users and activates accounts from pending to active for the Certifier Commander and Certifier Account Provisioner roles.
- MOL Administrator Interface. Source of truth for assigned permissions per user per module.
- MOL Modules. CLA, DTMS, MROWS, promotions, pro and con marks, APES, OMPF, personnel information, UMSR, BIC assignment, leave management, and permissions.
- MISSA. Functional manager for MOL Permission Management and User Management.
Forms
- NIS Access Request. Submission for MOL administrator entitlements through MISSA.
- Command Guidance Memo. Defines access scope.
- MOL Permission Roster. Local register of assigned permissions.
- NAVMC 118 (11) Administrative Remarks. Page 11 documenting MOL access.
Common pitfalls
- Blanket permissions assigned. Every clerk gets every module. The principle of least privilege fails. Assign per command guidance, not by default per MCO 5239.2BMCO 5239.2B.
- Permissions not removed at detach. The departing clerk retains MOL access. Refer to the Account Closure at Detach workflow within 24 hours per NAVMC 3500.3ENAVMC 3500.3E performance step 5.
- Command guidance memo not published. Permissions assigned without authority. Publish the memo before assigning per NAVMC 3500.3ENAVMC 3500.3E performance step 1.
- New module released, permissions not refreshed. Users miss access to new functionality. Refresh permissions on each MOL release per the MOL Users ManualMOL Users Manual.
- Permission roster diverges from MOL administrator interface. The local roster is wrong. Pull the roster from the administrator interface, not the local copy.
Decision points
- Module assignment by billet versus by individual. The command guidance assigns by billet. Individual exceptions route through the S-1 officer for written waiver per MCO 5239.2BMCO 5239.2B.
- Permission suspension on misconduct. The clerk is under investigation affecting record integrity. The S-1 officer suspends MOL access pending resolution per MCO P1070.12KMCO P1070.12K.
- Cross-unit permissions for IPAC support. The IPAC clerk needs MOL access to multiple unit RUCs. The S-1 chief coordinates with the IPAC and MISSA on the cross-unit permission scope.
Authority
This sub-page sits under NAVMC 3500.3ENAVMC 3500.3E T-R event 0102-GENA-1015 Manage Marine Online (MOL) modules, which defines all five performance steps. MCO 5000.14DMCO 5000.14D MCAP enclosure 6 establishes MISSA support for MOL administrator access. MCTFS FoS Access Policy and Procedures 8.0MCTFS FoS Access Policy and Procedures 8.0 covers MOL service responsibility and access control. MCO 5239.2BMCO 5239.2B Marine Corps Cybersecurity Program sets least-privilege and need-to-know rules. The MOL Users ManualMOL Users Manual documents module functionality and release notes.
Related references
- NAVMC 3500.3E Manpower and Administration T-R Manual. Event 0102-GENA-1015 governs MOL administrator permissions.
- MCO 5000.14D Marine Corps Administrative Procedures. MISSA support for MOL administrator access.
- MCTFS FoS Access Policy and Procedures 8.0. MOL service responsibility and access control.
- MCO 5239.2B Marine Corps Cybersecurity Program. Least-privilege framework.
- MCO P1070.12K Individual Records Administration Manual. Page 11 entries documenting MOL access.
- MOL Users Manual. Module functionality and release notes.
Same topic, other roles
References
- NAVMC 3500.3E Manpower and Administration T-R Manual
- MCO 5000.14D Marine Corps Administrative Procedures
- MCO 5239.2B Marine Corps Cybersecurity Program
- MCO P1070.12K Individual Records Administration Manual
- MOL Users Manual
- MCTFS FoS Access Policy and Procedures 8.0
- Naval Identity Services (NIS) FAQs UDMIPS and DTMS, 13 March 2026
Related Pages
- Admin
New System Release Onboarding - S-1 Procedural Page
same topic - same function - same T&R event - 7 shared references
- Admin
Account Closure at Detach - S-1 Procedural Page
same topic - same function - same T&R event - 6 shared references
- Admin
Account Provisioning and SAAR-N Processing - S-1 Procedural Page
same topic - same function - same T&R event - 6 shared references
- Admin
Admin Systems Management - S-1 Procedural Page
same topic - same function - same T&R event - 6 shared references
- Admin
Privileged Certifier Account Authorization - S-1 Procedural Page
same topic - same function - same T&R event - 6 shared references