Turn the fields you already collect into reports, without exporting a spreadsheet of health records

Governed reports, built from your own fields

Every organization needs different reports. A residential camp needs cabin, dietary, medication, and arrival lists. A summer school needs passports, visas, course selections, and airport transfers. A day camp needs pickup permissions, transport routes, and parent contacts. No fixed catalogue of reports covers all of that, so teams export everything to spreadsheets, and data governance quietly falls apart in someone's inbox. The Report Builder replaces that with two governed surfaces. On the template surface, a camp manager defines what a report contains: which columns, from which of your own fields, with which privacy classification, and which filters a generator may apply. On the run surface, the staff the manager has authorized pick a template, apply their filters, and generate a run, a point-in-time snapshot of the matching rows. A template is reusable and lives at the camp level. A run is session-scoped and immutable once generated, a fixed record of what was true when it was created, not a live query someone can quietly change. And every column keeps the privacy classification of the field it came from, so sensitive and special-category data stay protected inside the report, not just inside the form. A report is not a raw export. It's a governed, classified, point-in-time answer.

Reusable templates, controlled generation, protected data

  • Build templates from your own fields Columns come from participant profiles, form submissions, and staff assignments, from allergies and pickup permissions to passport details, transport routes, and T-shirt sizes. When your data model evolves, your reporting evolves with it.
  • Admins design; they decide who generates Camp managers and owners create templates and choose exactly which staff may generate each one. A person allowed to run the airport-arrival report doesn't automatically get the medical report, designing and running are separate, controlled permissions.
  • Point-in-time snapshots Each generation produces an immutable run: what was true at that moment, saved so it can be reopened later exactly as it was, not recomputed, and never silently rewritten when profiles change.
  • Runtime filters and saved presets Generators filter at run time and save reusable presets, so the same template answers many specific questions without being rebuilt.
  • Approval and visibility for sensitive reports A template can require a second authorized person to approve a run before it completes, and administrators are notified when a report is generated, producing a sensitive dataset is a deliberate, visible act.
  • Sensitive data encrypted at rest Columns classified as sensitive, names, dates of birth, contacts, are encrypted at rest and filterable only by exact match, so a report never turns identifying data into a browsable list.
  • Health data revealed with a reason Special-category columns are masked by default and revealed one value at a time: only by an authorized reviewer, only with a stated reason, only for a short window, and every reveal is recorded.
  • Seeded, editable defaults New camps start with ready-made templates for health and special cases, allergies, and rooming, edit them, archive them, or build your own beside them.

One report builder, every camp-specific list your season needs

Arrival and departure lists

Names, travel details, arrival windows, pickup arrangements, and assigned staff in one consistent view.

Dietary and allergy reports

What the kitchen needs to know, delivered to the authorized team, with the underlying protection still attached.

Medical preparation

Authorized medical staff prepare for the session without protected health data ever becoming an unrestricted spreadsheet.

Accommodation and groups

Session-specific views for cabins, rooms, teams, and age bands.

Transport manifests

Routes, stops, flights, trains, guardians, and emergency contacts, from the fields registration already collected.

Program selections

Courses, electives, language levels, equipment needs, and every other choice participants made.

From a template to a governed, revisitable report

1

Design the template

A camp manager picks the columns from your fields, sets each column's privacy classification, and defines which filters a generator may apply.

2

Decide who can generate it

The manager assigns the staff allowed to run this template, per template, not platform-wide.

3

Staff generate a run

An authorized staff member picks the template, applies their filters, and generates a run; the administrator is notified.

4

Approve, if the template requires it

For the most sensitive reports, a second authorized person signs off before the run completes.

5

Read the rows, protected by classification

Plain data shows directly, sensitive data shows to authorized readers, special-category data stays masked.

6

Reveal a health value, with a reason

An authorized reviewer reveals one specific value, states the reason, gets a short window, and the reveal is logged.

7

Revisit the snapshot later

The run is saved as an immutable point-in-time report, reopened later exactly as it was generated, with the protections still on.

Design, generate, approve, reveal, each a distinct permission

Camp managers and owners

Define and maintain templates, decide who generates each one, receive generation notifications, and act as the operational override for special-category reveals.

Session staff and coordinators

Generate the runs made available to them for preparation and delivery, arrival lists, readiness, transport, and save their filter presets, without unrestricted reporting access.

Approvers and reviewers

Someone who didn't generate the run approves it where the template requires; authorized reviewers reveal individual protected values, each with a reason and a log.

Medical and safeguarding teams

Work with approved reports containing protected information, under individual disclosure controls, not bulk exposure.

Directors and compliance

See who can generate what, when reports were produced, and the full disclosure history, an accountable record instead of an assumption.

Reports begin with the same fields your operation runs on

From the Form Builder

your field definitions, core and custom, become the available report columns.

From registration and profiles

family and participant answers provide the data; new runs use the current state, old runs keep theirs.

From the classification model

each column inherits its field's classification, reconciled server-side, nothing gets misclassified at report time.

From sessions and Teams

runs are generated in the session context, combining operational assignments with registration data.

From staff management

who designs, generates, approves, and reveals follows roles and assignments, not a separate reporting login.

Into notifications and the audit trail

generations are visible, and every protected reveal is recorded alongside the platform's other security events.

The point of the Report Builder is governed access, not more access

  • No raw export Reports are governed templates and immutable runs, not a "download everything" button. The most sensitive data never becomes an unprotected spreadsheet.
  • Sensitive data encrypted at rest Sensitive columns are encrypted at rest with keys derived per report run, shown to authorized readers but never turned into a browsable, substring-searchable list, and sensitive filter values are never echoed back or stored in a preset.
  • Masked until an audited reveal Health and allergy values stay masked by default. Revealing one takes an authorized reviewer, a stated reason, and a short time window, and each reveal is recorded, "who looked at this child's medical note, and why" always has an answer.
  • Immutable, approvable, visible runs A run is a fixed snapshot; sensitive templates can require a second person's approval, and administrators are notified on generation. And opening an old snapshot doesn't unseal it, special-category values stay masked and logged there too.
  • Certified security management Data is encrypted in transit and at rest, and CampOrganizer's information security management system is certified according to ISO/IEC 27001:2022 by an independent certification body, covering both standard and white-label deployments. The certificate and certified scope are published on the Trust page.

The answers you need, without the exposure you fear

No more spreadsheets of children's data

The allergy list and the rooming report, without a file of medical data leaving the platform.

Your fields, your reports

The camp decides which reports exist, what they contain, and who runs them, not a vendor's fixed list of generic exports.

Data minimized by design

Readers see only the columns and rows their report allows, and health values stay masked until an authorized, logged reveal.

Access you can account for

Every reveal ties to a person, a reason, and a time; every generation is visible. Access to the most sensitive data is provable, not assumed.

One agreed definition of every report

Reusable templates give operations, kitchen, medical, and leadership the same report, instead of five people maintaining five diverging spreadsheets.

A record you can trust later

An immutable run generated in July still shows exactly what it showed in July, for handovers, reviews, and audits.

Frequently asked questions about camp reporting

Can I build custom reports from my own fields?
Yes. Camp managers build templates from the columns you already collect, participant profiles, form submissions, staff assignments, and define which filters a generator may apply.
Who creates reports, and who can run them?
Managers and owners design templates and assign generators per template. Designing and generating are separate, controlled permissions, access to one report doesn't grant access to the rest.
Does anyone know when a report is generated?
Yes. The relevant administrator is notified when an authorized user generates a report, so sensitive datasets are never produced without oversight.
How is sensitive data protected in a report?
Sensitive columns, names, dates of birth, contacts, are encrypted at rest and filterable only by exact match, so a report never becomes a browsable list of identifying data.
How is health and other special-category data handled?
Masked by default, revealed one value at a time, only by an authorized reviewer, only with a stated reason, for a short window, and every reveal is logged. Opening a report never discloses health values in bulk.
Can I look at an old report again later?
Yes. Every run is an immutable point-in-time snapshot, and reviewing it later doesn't remove the protections: special-category values stay masked and logged in the snapshot too.
Do some reports need approval?
Yes. A template can require a second authorized person to approve a run before it completes, useful for the reports touching the most sensitive data.
Does the Report Builder export raw data?
No. It replaces raw exports with governed templates and classified, auditable runs, so sensitive data stays inside the platform's controls.
Are there ready-made reports to start from?
Yes. New camps are seeded with templates for health and special cases, allergies, and rooming, edit, archive, or extend them.
Does this replace every spreadsheet?
It replaces the recurring ones built from data already in CampOrganizer, the arrival list, the allergy report, the rooming plan. Processes outside the platform may still use their own files; what disappears is the repeated manual assembly and the uncontrolled copies of sensitive data.

See governed reporting in your season

In a 30-minute demo, we'll show how your own fields become reusable templates, immutable snapshots, and audited access to the most sensitive data, the answers without the spreadsheet.

© 2026 CampOrganizer. All rights reserved.