Arrival and departure lists
Names, travel details, arrival windows, pickup arrangements, and assigned staff in one consistent view.
Every organization needs different reports. A residential camp needs cabin, dietary, medication, and arrival lists. A summer school needs passports, visas, course selections, and airport transfers. A day camp needs pickup permissions, transport routes, and parent contacts. No fixed catalogue of reports covers all of that, so teams export everything to spreadsheets, and data governance quietly falls apart in someone's inbox. The Report Builder replaces that with two governed surfaces. On the template surface, a camp manager defines what a report contains: which columns, from which of your own fields, with which privacy classification, and which filters a generator may apply. On the run surface, the staff the manager has authorized pick a template, apply their filters, and generate a run, a point-in-time snapshot of the matching rows. A template is reusable and lives at the camp level. A run is session-scoped and immutable once generated, a fixed record of what was true when it was created, not a live query someone can quietly change. And every column keeps the privacy classification of the field it came from, so sensitive and special-category data stay protected inside the report, not just inside the form. A report is not a raw export. It's a governed, classified, point-in-time answer.
Names, travel details, arrival windows, pickup arrangements, and assigned staff in one consistent view.
What the kitchen needs to know, delivered to the authorized team, with the underlying protection still attached.
Authorized medical staff prepare for the session without protected health data ever becoming an unrestricted spreadsheet.
Session-specific views for cabins, rooms, teams, and age bands.
Routes, stops, flights, trains, guardians, and emergency contacts, from the fields registration already collected.
Courses, electives, language levels, equipment needs, and every other choice participants made.
A camp manager picks the columns from your fields, sets each column's privacy classification, and defines which filters a generator may apply.
The manager assigns the staff allowed to run this template, per template, not platform-wide.
An authorized staff member picks the template, applies their filters, and generates a run; the administrator is notified.
For the most sensitive reports, a second authorized person signs off before the run completes.
Plain data shows directly, sensitive data shows to authorized readers, special-category data stays masked.
An authorized reviewer reveals one specific value, states the reason, gets a short window, and the reveal is logged.
The run is saved as an immutable point-in-time report, reopened later exactly as it was generated, with the protections still on.
Define and maintain templates, decide who generates each one, receive generation notifications, and act as the operational override for special-category reveals.
Generate the runs made available to them for preparation and delivery, arrival lists, readiness, transport, and save their filter presets, without unrestricted reporting access.
Someone who didn't generate the run approves it where the template requires; authorized reviewers reveal individual protected values, each with a reason and a log.
Work with approved reports containing protected information, under individual disclosure controls, not bulk exposure.
See who can generate what, when reports were produced, and the full disclosure history, an accountable record instead of an assumption.
your field definitions, core and custom, become the available report columns.
family and participant answers provide the data; new runs use the current state, old runs keep theirs.
each column inherits its field's classification, reconciled server-side, nothing gets misclassified at report time.
runs are generated in the session context, combining operational assignments with registration data.
who designs, generates, approves, and reveals follows roles and assignments, not a separate reporting login.
generations are visible, and every protected reveal is recorded alongside the platform's other security events.
The allergy list and the rooming report, without a file of medical data leaving the platform.
The camp decides which reports exist, what they contain, and who runs them, not a vendor's fixed list of generic exports.
Readers see only the columns and rows their report allows, and health values stay masked until an authorized, logged reveal.
Every reveal ties to a person, a reason, and a time; every generation is visible. Access to the most sensitive data is provable, not assumed.
Reusable templates give operations, kitchen, medical, and leadership the same report, instead of five people maintaining five diverging spreadsheets.
An immutable run generated in July still shows exactly what it showed in July, for handovers, reviews, and audits.
In a 30-minute demo, we'll show how your own fields become reusable templates, immutable snapshots, and audited access to the most sensitive data, the answers without the spreadsheet.
© 2026 CampOrganizer. All rights reserved.