Users, roles, and permissions

This article explains how user accounts and roles work across your platform: what each role can do, how one person can hold more than one role, and what actually happens when you add, suspend, remove, or delete an account. It is written for platform admins working in the /admin panel.

Where to find it

Sign in to your admin panel at /admin. Two sidebar entries manage people:

  • Users - the people who belong to your customer organizations or signed up on their own: Students, Group Leaders, and Org Admins. This is the list an organization's plan is billed for.
  • Administrators - your own staff (Admin and Super Admin accounts). Staff belong to no organization and never count against any plan limit, so they are managed on their own page and kept out of the Users list.

Click any row in either list to open that person's detail page.

The roles

The platform runs on five active roles. A number of legacy roles from earlier versions are retired and can no longer be assigned.

Role Panel What it does
Super Admin /admin Full platform access, including settings, billing, and integrations
Admin /admin Manages users, organizations, courses, and reports, but not billing or system settings
Org Admin /org-admin Runs one organization: its users, seats, courses, groups, and reports
Group Leader /org-admin Sees their group members' progress and assigns courses within their group's seat allocation
Student /learner Takes enrolled courses, completes training, and downloads certificates

Two things to know about the table above:

  • "Student" is the default display name for the learner role. Role display names are configured per platform, so your site may show different wording for the same role.
  • Group Leaders do not get a separate panel. They sign in to /org-admin and simply see a slimmer menu than an Org Admin does.

Each role carries a fixed set of permissions, and the admin sidebar only shows the menu items your permissions allow. Permissions are attached to roles, not to individual people, so the way to change what someone can do is to change their roles.

One person, several roles

Roles are checkboxes on the Add User and Edit User forms, so one account can hold several roles at once (for example Org Admin plus Group Leader). Three rules apply:

  • Permissions are a union. A multi-role user can do everything any of their roles allows, on every panel those roles can reach.
  • Switching roles is a viewing choice, not a permission change. Users with more than one role get a role switcher in the panel header. Picking a role takes them to that role's panel and scopes the data they see to that role (for example, acting as a Student shows only their own orders). It never grants or removes abilities.
  • Student and Group Leader are mutually exclusive. Group Leader is an upgrade of the Student role, so an account is never both. Ticking one clears the other, and the server rejects a request that includes both.

The Org Admin role only exists in the context of an organization, so assigning it requires picking one. Group Leaders and Students can optionally be placed in an organization, or left independent at platform level.

Adding an administrator

  1. Open Administrators in the sidebar.
  2. Click + Add Administrator.
  3. Fill in the name and email, and tick the Admin role.
  4. Save.

Only Super Admins can grant the Admin role; other admins will not see the option. The Super Admin role itself is never offered on this form: platform owner accounts are set up by your provider. Administrators are created without an organization on purpose, so they never appear in any organization's billing counts.

Adding users

  1. Open Users and click + Add User.
  2. Enter first name, last name, and email.
  3. Tick one or more roles. An organization picker appears for roles that need or can take one (required for Org Admin, optional for Group Leader and Student).
  4. Choose a status (Active or Suspended) and save.

New users land on the default plan for their role unless you pick a specific plan tier while creating them.

Suspending, removing, and deleting

These are three different actions, available individually and as bulk actions on the Users list:

  • Suspend blocks sign-in (the person sees a message that their account has been suspended) but keeps the account and all of its data intact. Reversible with Activate.
  • Remove from Organization detaches the account from one organization. Unused seats go back to the organization's pool, group memberships end, and the account itself survives. Seats whose training was already finished stay assigned, so the organization's compliance history is not erased. Orders, certificates, and completed enrollments keep their organization link for reporting.
  • Delete removes the account itself. Super Admin accounts cannot be deleted, and you can never delete your own account.

Why did this happen?

Why can't I make someone both a Student and a Group Leader?

Group Leader is an upgrade of the Student role, not a sibling. The form clears one when you tick the other, and the server rejects a save that contains both. Give the person the Group Leader role only; they can still take courses.

Why don't administrators appear in the Users list?

The split is deliberate. Users is the list of people organizations are billed for; administrators are your staff, belong to no organization, and are never counted, so they live on the Administrators page.

Why was I asked what the account becomes when removing someone from an organization?

The Org Admin role only exists inside an organization. If you remove someone from their last organization and Org Admin was their only role, the account would be left with no role at all, so the platform makes you choose what it becomes: keep it as a platform administrator, downgrade it to Group Leader or Student, or delete the account as part of the removal.

Why can't I move a Student into a different organization?

Students and Group Leaders are pinned to their organization, because their enrollments, seats, and certificates are all scoped to it; moving them would silently carry data across organizations. You can still remove them from the organization entirely, which frees their unused seats and leaves the account organization-less, and from there they can join a new organization fresh. Direct transfers are blocked on purpose.

Why could I create two accounts with the same email address?

Email addresses are unique per organization, not across the whole platform. The same person can have separate accounts in two different organizations, plus a platform-level account with no organization, all under one email. Each account signs in on its own website address, and being signed in on your main site does not sign you in on an organization's subdomain or custom domain. A deleted account releases its email address immediately, so the address can be reused.

Why can someone still sign in after I removed them from their organization?

Removal only ends the organization membership; the account itself lives on (possibly in another organization, or organization-less). If you need to block access, suspend the account, or use the removal option that also deletes it.

Still stuck? Contact your support team through support.

Didn't answer your question? Contact support or browse the other Knowledge Base sections.