Roles and permissions
The authoritative guide to institution roles, access rights, scoped assignments, profile tab visibility, and how roles interact with product packages across Fuxam Web.
Roles and permissions are the access-control foundation of Fuxam Web. A role is a named bundle of rights that determine what a person can see and do. Every user has at least one role, and their effective access is the combination of rights granted by that role, plus any scoped assignments on specific courses, cohorts, study programs, or individual users.
This chapter is the reference point for access across the handbook. OrgHub sidebar visibility, user profile tabs, invitation content, and cohort-level assignments all flow from the same model described here. For how access rights combine with product packages in OrgHub, see Permissions, features and visibility.
Why it matters
Universities run on separation of duties. Admissions staff need applicant data; module organizers need planning tools; students need their own grades — but not everyone else’s. Roles let you express those boundaries in software without creating a separate account type for every job title.
Without deliberate role design, two predictable problems appear: over-permissioning (too many people can change records they should only read) and under-visibility (colleagues cannot find menus they need for their work). Both look like product bugs but are usually configuration gaps. Investing time in roles early pays off across User Management, Study programs and cohorts, course management, and every other module that checks access before showing a page.
How it fits
Roles sit at the center of Fuxam’s access model. Feature packages determine what the institution has licensed; roles determine what each person may do with those capabilities.
Typical workflow order for a new institution:
- Review which Fuxam product packages are enabled (Base, CMS, LMS, Apply).
- Define institution roles that mirror real job functions — Student, Teacher, Course Coordinator, Registry staff, and similar.
- Assign access rights per role, starting with User Management and the OrgHub areas each function needs.
- Assign roles when creating users or adjust them later from the profile Access tab.
- For academic structures, add scoped role assignments on cohorts or courses where organization-wide access would be too broad.
Key concepts
| Term | Meaning |
|---|---|
| Role | A named set of access rights (and optional UI settings) assigned to users. Examples: Student, Teacher, Course Coordinator. |
| Access right (permission) | A single toggleable capability — for example, permission to view the Users table or to update a course. Enabled rights are additive within a role. |
| General / primary role | The organization-wide role on a user’s account, set at creation or on the Overview / Access tabs. |
| Scoped assignment | A role applied to a specific entity — a course, cohort, study program, or individual user. Scoped rights only take effect in that context. |
| Superadmin | A user with full administrative access, listed separately on the Roles & Permissions settings page. |
| Access package | A bundled set of rights linked to a Fuxam product package (Base, CMS, LMS, Apply), managed alongside roles. |
| Feature / product package | An institution-wide product capability (FuxamCMS, FuxamLMS, FuxamApply) that must be enabled before related OrgHub sections and profile tabs can appear. |
| User Information settings | Per-role controls for which profile tabs and dashboard home sections a user sees. |
Organization-wide vs scoped access
Some rights apply organization-wide — for example, permission to view users lets someone see all users in the institution. Others are scoped to a specific course, cohort, study program, or person. Scoped rights only take effect when the role is assigned to that entity.
| Type | Example | When it applies |
|---|---|---|
| Organization-wide | Permission to view users | User can see the full Users table (if they also have that right). |
| Scoped | Permission to view a course | User can see a specific course only when the role is assigned on that course. |
| Scoped | Permission to update a specific user | User can edit a specific person’s record when institution-wide update access is off but a per-user scoped assignment exists. |
The Access tab on a user’s profile shows both general and scoped role assignments. This is especially important for cohort and program staff who need planning or enrollment rights on one intake group but not the entire institution.
Open role configuration
Roles are managed in institution Settings, not in OrgHub.
From your dashboard, open Settings (gear icon or Settings link in the navigation).
In the Settings sidebar, select Roles & Permissions under Organization & Access Rights.
The page includes three sections:
- Superadmins — users with full administrative access.
- Roles & Permissions — the list of institution roles.
- Access packages — bundled sets of rights linked to Fuxam product packages.
Create a role
In the Roles & Permissions section, select Create role (or the add action).
Enter a descriptive Name (for example, “Course Coordinator” or “Student”).
Optionally set a Role code and Color for identification in the UI.
Save. The new role starts with no access rights until you configure them.
Assign access rights
Select a role from the list to open its settings.
Open the Permissions tab.
Browse categories — User Management, Course Management, Settings, and others — and enable or disable individual rights.
Save your changes.
Access rights are additive within a role: everything toggled on is granted to users assigned that role.
Common User Management rights
| What the role can do | Typical use |
|---|---|
| View the Users table | Open User Management and browse accounts |
| Create users | Add people via Add → User or import |
| Update user details | Edit names, emails, custom fields, and related profile data |
| Change user account status | Activate or deactivate accounts |
| Delete users | Remove people from the institution |
| Create and manage invitations | Send, view, and cancel invitation emails |
| View and manage user groups | Work with user groups and membership |
| Create and update user-management columns | Define custom columns / data fields |
| View or edit user access | Open the profile Access tab and change scoped assignments |
| Create a user export | Export users to CSV via bulk actions |
Many other categories cover OrgHub planning, curricula, exams, courses, and settings. The Permissions, features and visibility chapter maps common OrgHub sidebar items to the access they require.
Profile-related view rights
When configuring who can open which profile areas, think in plain outcomes:
| Outcome | What it enables |
|---|---|
| View user overview | See basic identity, contact details, and custom fields |
| View user access | Open the Access tab |
| View user mailing | Open Mailing and invite history |
| View user study plan | Open Study Program |
| View user grades | Open Grades |
| View user documents | Open Documents |
| View user calendar / attendance | Open calendar-related tabs |
| View user time tracking | Open Time Tracking when time tracking is enabled |
| View user insurance | Open Health Insurance when the integration is set up |
| View user tuition | Open Tuition when tuition management is enabled |
Pair each view right with the matching product package (see below) so tabs actually appear.
User profile tab visibility
Each role has User Information settings that control which tabs appear on user profiles (for users with that role) and on the dashboard home screen. This is separate from OrgHub sidebar access — a teacher might see Grades on student profiles without having access to the full Exam Center.
Open a role in Settings → Roles & Permissions.
Go to the User Information (or profile tabs) section.
Enable or disable tabs such as Overview, Study Program, Grades, Documents, and Mailing.
Save. Users with this role see only the enabled tabs (subject to your access rights and product packages).
Some tabs also require a product package (FuxamCMS, FuxamLMS, FuxamApply) or an institution setting to be enabled before they appear at all. A page or tab is visible only when both the user’s role has the required access and the institution has the relevant feature enabled.
See View a user for how profile tabs render for individual accounts.
Access packages and product packages
Access packages on the Roles & Permissions settings page link roles to Fuxam product bundles (Base, CMS, LMS, Apply). Feature packages enabled for your institution determine which OrgHub sections and user profile tabs exist.
Think of the relationship this way:
| Layer | Question it answers | Example |
|---|---|---|
| Product package | Does the institution have this product area? | FuxamCMS — Exam Management |
| Access right | May this role use a capability within that area? | Permission to view exams |
| Institution setting | Is a specific sub-feature switched on? | Exam Center enabled |
| User Information tab | Should this role see a profile tab? | Grades tab enabled for Teachers |
All four layers can apply simultaneously. See Permissions, features and visibility for the full OrgHub sidebar mapping.
Assign a role to a user
Assign roles when:
- Creating a user — pick an initial general role in the Add User form.
- Editing a user — change the general (primary) role in the Users table or on the Overview / Access tabs.
For academic staff who need rights on a specific cohort or study program rather than institution-wide, use scoped assignments on the Access tab or through Bulk actions Access options. You can also revoke a single scoped assignment without changing the person’s primary role.
Role-specific invite settings
Individual roles can override default invitation language, subject, text, and intro video. When set on a role, those values replace the institution defaults for users invited with that role. When not set, the defaults from Invite email settings apply.
This is useful when students and staff should receive different onboarding tone — for example, a welcome video aimed at first-year students versus a concise staff orientation message. Configure overrides on each role under Settings → Roles & Permissions, in the onboarding or invite settings section for that role.
Pending invitations remain tied to the invitee’s email and role until the person activates or the invite is cancelled or resent — see Resend an invite.
Best practices
- Mirror real job functions. Start with a small set of roles (Student, Teacher, Staff, Administrator) and split only when access rights genuinely diverge.
- Prefer scoped access for academic structures. A module organizer for one cohort rarely needs institution-wide permission to view all study programs. Assign the role on the cohort or program instead.
- Separate read from write. Give registry staff permission to view users before permission to update users until you are confident the role definition is correct.
- Document your role matrix. Maintain an internal table of which roles map to which capabilities — auditors and new administrators will ask.
- Test with a colleague. After changing a role, have someone assigned that role sign in and confirm OrgHub visibility matches expectations before rolling out widely.
- Review Superadmins periodically. Full administrative access should be limited to people who actively need it.
- Align invite overrides with audience. Student vs staff invitation tone should match the role you assign at send time.
Common pitfalls
| Symptom | Likely cause | What to check |
|---|---|---|
| OrgHub page missing for one role but visible for another | Access right not enabled on that role | Settings → Roles & Permissions → role → Permissions tab |
| Page missing for everyone | Product package not enabled or institution setting off | Permissions, features and visibility |
| User can see a course in OrgHub but cannot edit it | View access without update access, or scoped view only | Scoped assignment and toggles on the role |
| Profile tab missing | User Information tab disabled for the role, or product package required | Role User Information settings and product packages |
| Invitation email in wrong language | Role-specific invite override set | Role invite settings vs Invite email settings defaults |
FAQ
Can one user have multiple roles?
Users have one general (primary) organization-wide role at a time, but they can hold scoped role assignments on multiple courses, cohorts, study programs, or individual users simultaneously. Effective access combines the general role’s rights with any scoped assignments.
Why can I configure an access right but the page still does not appear?
A page requires both the correct access right on the role and the relevant product package (and sometimes an institution setting) to be active. Configuring a right alone does not bypass a missing product package.
What is the difference between access packages and feature packages?
Feature packages are institution-wide product capabilities (what the institution licensed). Access packages are bundled sets of rights linked to those product packages, managed on the same Settings page as roles. Both interact when Fuxam evaluates what a user can do.
How do cohort permissions relate to user roles?
Cohorts are academic enrollment groups in Study programs and cohorts. Rights such as viewing or updating a cohort are typically scoped — they take effect when a role is assigned on that specific cohort or study program, not automatically for every user with the role.
Related pages
User Management
The hub for creating, editing, and managing institution users.
Permissions, features and visibility
How access rights and product packages control OrgHub sidebar visibility.
Create a user
Assign an initial role when adding a new person.
Invite email settings
Institution defaults and role-specific invitation overrides.
Study programs and cohorts
Where scoped academic roles and cohort enrollment connect to user accounts.
View a user
Profile tabs, access assignments, and what each role can see on a user record.