Permissions (summary)
Access depends on the user’s role after sign-in. The left menu shows only the sections available to your role; opening a URL you cannot use is denied.
Roles
| Role | How it is set | Scope |
|---|---|---|
| Admin | admin flag on the user |
Whole system |
| Global tutor admin | kind = Global tutor admin |
All campuses; Content catalogue is mostly read-only |
| Local tutor admin | kind + link to a Tutor card |
One campus: the school of that Tutor, not a campus field on the user |
| Simple tutor | kind + link to a Tutor |
Assigned subjects/classes and their students |
| Secretary | kind + school (campus) on the user |
Campus operations |
| Student | kind + link to a student |
Own reports only |
| not assigned | No role set | No data access |
Local tutor admin and Simple tutor have no data access until the user is linked to a Tutor card. For local admin the campus is that Tutor’s school.
What appears in the menu
| Menu section | Admin | Global tutor admin | Local tutor admin | Simple tutor | Secretary | Student |
|---|---|---|---|---|---|---|
| Users | ✓ | ✓ | — | — | — | — |
| Admin → Changes | ✓ | — | — | — | — | — |
| Admin → SMTP | ✓ | — | — | — | — | — |
| Campuses | ✓ | ✓ | — | — | — | — |
| Classes | ✓ | ✓ | ✓ | ✓ (+ My classes) | ✓ | — |
| Subjects | ✓ | ✓ | ✓ | ✓ (+ My subjects) | ✓ | — |
| Tutors | ✓ | ✓ | ✓ | — | —* | — |
| Students | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Contacts | ✓ | ✓ | —** | — | —** | — |
| My (own classes/students) | — | ✓ | ✓ | — | — | — |
| Academic | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Content (Patterns, Questions, Lists) | ✓ | ✓ | — | — | ✓ | — |
| Content → Question Groups | ✓ | ✓ | —*** | — | ✓ | — |
| Reports | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
* A secretary manages campus tutors through cards/links; there is no Tutors item in the menu.
** Local admin can access contacts via Ability, but there is no Contacts item in the local admin menu — usually via the student card. Simple tutor does not read contacts.
*** Question Groups sit under Content. Global tutor admin and Local tutor admin can open the Question groups tab on a class or subject card and see which groups are linked (read-only). Only Admin can assign or unlink them. Local tutor admin has no Content menu item. Simple tutor does not see Question Groups in the menu; the questions appear on Assessment once a group is already assigned, and only a subject's primary tutor can open that tab. Secretary can open the Content catalogue read-only, but cannot assign groups to classes or subjects.
Action matrix by entity
Legend: M = full manage (create/edit/delete), R = read, U = edit in own scope, C = create in own scope, — = none.
| Entity / action | Admin | Global | Local | Simple | Secretary | Student |
|---|---|---|---|---|---|---|
| Users | M | M (except admin accounts) | campus tutor logins | — | — | — |
| Changes log (all objects and tabs) | R | — | — | — | — | — |
| SMTP settings | M | — | — | — | — | — |
| Campuses | M | M | R (own) | R (own) | R (own) | — |
| Classes | M | M | M (campus) | R campus; U own | M | — |
| Subjects | M | M | M (campus) | R campus; U own | M | — |
| Tutors | M | M | M (campus) | R campus; U self | M (campus) | — |
| Create tutor (New Tutor) | ✓ | ✓ | ✓ (own campus) | — | ✓ (campus) | — |
| Create tutor login | ✓ | ✓ | ✓ (campus) | — | ✓ (campus) | — |
| Manage tutor login | ✓ | ✓ | ✓ (campus Simple/Local) | — | show (campus) | — |
| Students | M | M | M (campus) | R campus; U own students | M | — |
| Contacts | M | M | M (campus) | — | M | — |
| Deleted lists / Restore | M | — | — | — | — | — |
| Assessment / Answers | M | M | M | M if subject primary tutor; otherwise — | R Assessment | — |
| Reports | M | M | M (campus) | C/R/U own students | M | R own |
| Batch reports for a class | ✓ | ✓ | ✓ | own classes | ✓ | — |
| Patterns | M | R | R | R | R | — |
| Question Groups / Questions / Lists | M | R | R | R | R | — |
| Link QG to Subject/Class | M | R | R (campus) | — | — | — |
| Academic Years / Years / Periods | M | M* | R | R | R | — |
| Own profile (password) | U | U | U | U | U | U |
* Global tutor admin has broad manage :all, but the Content catalogue (Patterns, Lists, Questions, Question Groups, and QG assignment links) is forced read-only. Local tutor admin can view campus QG links on class and subject cards, but cannot assign or unlink them.
New Tutor and Create login (from the Tutor card):
- Local tutor admin sees New Tutor on Campus → Tutors. The form is limited to their campus (the school of the linked Tutor card); they cannot create a tutor on another campus.
- Local tutor admin can open, edit, change the password, and lock/unlock Simple tutor and Local tutor admin logins of their campus from the Tutor card. They cannot open the Users list, create users from Users, or manage Global tutor admin / administrator accounts.
- Secretary can create campus tutors and logins if they open a tutor card or the tutors URL; there is no Tutors item in their menu.
- When creating a login, Admin may assign Simple tutor, Local tutor admin, or Global tutor admin. Global, Local, and Secretary may assign Simple tutor or Local tutor admin only. Nobody except system Admin can set the Admin flag.
Limits for everyone
- System Lists / List items (
system: true) cannot be changed or deleted, even by Admin. - Only a system administrator can set the Admin flag on a user.
- Only a system administrator can change Admin → SMTP (the mail server for notifications and password-reset emails).
- Local tutor admin cannot create or edit tutors (or tutor logins) on another campus.
- Local tutor admin can set a class primary tutor only for classes on their campus.
Delete and restore
Delete hides a campus, class, subject, tutor, student, or contact instead of removing it permanently. Everyday lists hide the record. A red deleted label appears next to the name.
System Admin can open Deleted on those lists and Restore from a deleted record’s card. Restore brings the record back, including class, subject, and contact memberships. Logins linked to a deleted tutor or student (and secretary logins on a deleted campus) are locked until restore.
Deleting a campus also hides its classes, subjects, tutors, and students. Restoring the campus restores those records too.
Other roles can still delete records they are allowed to manage, but they cannot open Deleted lists or restore.
Practical takeaways
- Simple tutor works with their subjects, classes, and students. Only a subject's primary tutor can fill Assessment, and only for those primary subjects; other simple tutors cannot. Reports stay available; Contacts are not.
- Local tutor admin runs the structure of one campus, including tutors (New Tutor on Campus → Tutors, own campus only), campus tutor logins, and reports.
- Secretary handles day-to-day classes, subjects, students, contacts, and reports; Content templates are view-only.
- Student sees only the Reports section with their own files.
- Report templates (Patterns, Question Groups, questions) are set up by Admin (Global can see the catalogue but not edit it). Only Admin assigns question groups to subjects and classes; Global and Local tutor admin see those links read-only.
See also: user guide home.