Skip to main content
Working with permissions day to day. For what each domain and scope level actually controls, see Permissions.

By Organizational Position

Quick Decision Guide

Need full control?

Use ADMINFor executives and IT administrators who need access to everything.

Managing members?

Use HRFor HR staff, secretaries, and membership officers.

Handling money?

Use FINANCIALFor treasurers and finance officers.

Running events?

Use EVENTFor event coordinators and activity managers.

Sending communications?

Use COMMUNICATIONFor communications officers and community managers.

Helping with validation?

Use HR_ASSISTANTFor volunteers helping with identity checks and gamification.

Assigning Permissions

Attach permissions to roles, then assign roles to users:
1

Create or edit a Role

Go to SettingsRoles
2

Attach permissions

Select which permissions this role grants
3

Assign role to users

Users with this role automatically get the attached permissions

Direct Assignment

For exceptions, assign permissions directly to a user’s profile.
Direct assignment is harder to audit. Use roles whenever possible.

Testing Permissions (Impersonation)

Administrators can test the platform with different permissions:
1

Click impersonation icon

Shield icon in the header
2

Select permissions to test

Choose which permission level to simulate
3

Browse as that user

See exactly what users with those permissions see
4

Exit impersonation

Click the badge to return to normal

Troubleshooting

Check if they have the correct domain permission. Use the Domain Comparison table to find which permission controls that feature.
They probably have _TENANT scope instead of _LOCAL. Change to the appropriate scope level.
Check if it’s automatically included by another permission. For example, HR already includes HR_ASSISTANT.
Local center features might be disabled. Enable in SettingsModulesLocal Centers.

Seeing who currently holds which permissions

Assigning and removing permissions is done per member, which makes it easy to lose track of who has what across a whole organisation. To review:
1

Open the member list

Members, then filter by role.
2

Filter to each administrative role in turn

Work through the roles you care about — organisation administrator, HR, financial — rather than scanning the full list.
There is no single report today that lists every member with elevated permissions in one view. If you audit access periodically, for example when someone leaves, the practical approach is to check each administrative role in turn and remove what is no longer needed.
Do this whenever someone leaves the organisation. Removing a member’s account does not by itself guarantee that every permission they were granted has been reviewed, and a departing administrator is the case where a stale permission matters most.