It is probably the concept that generates the most support tickets across the entire campus. And the confusion is almost always the same: believing that "granting permissions" is enough. In reality there are three distinct keys, and understanding how they fit together saves you half of your access problems.
Knowing who can do what inside the platform takes more than a single setting. There are three independent keys, and each one opens a different door. They look alike, they overlap, but they are not the same: when something "won't let me," it is almost always because one of them is missing.
The three keys to access
🗝️Role — do you get into the Administration, and to which classrooms?
Webmaster (all classrooms), Administrator (the ones assigned to them), or Manager (limited access). It lives in the back office: it is a technical key.
🗝️Profile — what are you inside a specific classroom?
Student, Teacher, Assistant, Director, Coordinator, Guest. It is assigned per classroom —you can be different in each one— and the names can be customized. It is your pedagogical identity.
🗝️Permission — what does that profile let you do in each section?
View, post, edit, grade, moderate, delete. It is the specific action in each space of the classroom.
🚪Think of them as three doors in a row
The role lets you into the building, the profile gives you a credential inside each classroom, and the permission defines which buttons you can press. All three are necessary; none replaces another.
The most common confusion
It is almost always assumed that having an administrative role automatically grants access to a classroom's content. That is not the case. Being a Webmaster lets you configure the classroom from the Administration, but your profile inside it defines what you can do as a user.
The case of Lucía, the Webmaster
Lucía can enter the Administration of every classroom. But when she enters "Mathematics I," the system assigns her the Guest profile. From the Administration she creates sections, registers users, and views reports; yet, as a user, she does not appear in Contacts and cannot take part in the forums. Why? Because her role is technical, not pedagogical. If she needs to participate, someone changes her profile (Guest → Teacher). The role stays untouched.
✗Common mistake
"I want Carlos to grade, so I'll change his role." That solves nothing: the role already gave him access to the Administration.
✓Correct diagnosis
Carlos needs the Teacher profile in the classroom, and that profile must have the entry permission in Grades. You don't touch the role: you adjust the profile and the permission.
The permissions matrix
The matrix translates the triangle into concrete actions: each cell answers "what can this profile do in this section?". This is a typical balanced policy for participation spaces: students take part, teachers moderate, and assistants sit in between.
| Section / Profile | Student | Assistant | Teacher | Guest |
|---|---|---|---|---|
| Forums | View and post | View, post, edit own, move threads | View, post, edit all, delete, moderate | View only |
| Discussions | View and participate | View, participate, edit own | View, participate, moderate, grade | View only |
| Wikis | View and edit | View, edit, supervise changes | View, edit, moderate, restore history | View only |
| Internal messaging | Send and receive among participants | Send and receive | Group messages, view all threads | No access |
You read it by cross-reference: each row is a section, each column a profile, and the intersection tells you what can be done there. The same user, with the Student profile, views and posts in Forums; with the Teacher profile, they also moderate.
Where it is configured
The matrix is defined at two levels, with nesting-doll logic: the general is inherited by the particular.
- 🏛️ Campus level (defaults):in Administration → Settings → Defaults → Permissions. This is the institutional policy that every new classroom inherits.
- 🚪 Classroom level:inside each classroom, in Users → Permissions. You adjust the matrix for that specific classroom and, if needed, override the default.
How to diagnose an access problem
When you hit a "it won't let me…," don't touch everything. Identify which of the three keys is missing, in this order:
- 1Can they get into the Administration? → it is a matter of role.
- 2What profile do they have in that classroom? → if it is the wrong one, that is the problem.
- 3Does that profile have the permission in that section? → you adjust it in the matrix.
Understanding the triangle is not a technicality: it is what lets you grant just the right access, resolve things quickly when something doesn't work, and prevent anyone from being able to do more —or less— than they should.
educativa Blog · E-learning Best Practices