Recommended Permission Assignments
By Organizational Position
Quick Decision Guide
Need full control?
Use ADMINFor executives and IT administrators who need access to everything.
Managing members?
Use HRFor HR staff, secretaries, and membership officers.
Handling money?
Use FINANCIALFor treasurers and finance officers.
Running events?
Use EVENTFor event coordinators and activity managers.
Sending communications?
Use COMMUNICATIONFor communications officers and community managers.
Helping with validation?
Use HR_ASSISTANTFor volunteers helping with identity checks and gamification.
Assigning Permissions
Via Roles (Recommended)
Attach permissions to roles, then assign roles to users:1
Create or edit a Role
Go to Settings → Roles
2
Attach permissions
Select which permissions this role grants
3
Assign role to users
Users with this role automatically get the attached permissions
Direct Assignment
For exceptions, assign permissions directly to a user’s profile.Testing Permissions (Impersonation)
Administrators can test the platform with different permissions:1
Click impersonation icon
Shield icon in the header
2
Select permissions to test
Choose which permission level to simulate
3
Browse as that user
See exactly what users with those permissions see
4
Exit impersonation
Click the badge to return to normal
Troubleshooting
User can't access a feature
User can't access a feature
Check if they have the correct domain permission. Use the Domain Comparison table to find which permission controls that feature.
User sees too much data
User sees too much data
They probably have
_TENANT scope instead of _LOCAL. Change to the appropriate scope level.Permission seems to not work
Permission seems to not work
Check if it’s automatically included by another permission. For example, HR already includes HR_ASSISTANT.
Can't find LOCAL/PARENT_LOCAL options
Can't find LOCAL/PARENT_LOCAL options
Local center features might be disabled. Enable in Settings → Modules → Local Centers.
Seeing who currently holds which permissions
Assigning and removing permissions is done per member, which makes it easy to lose track of who has what across a whole organisation. To review:1
Open the member list
Members, then filter by role.
2
Filter to each administrative role in turn
Work through the roles you care about — organisation administrator, HR,
financial — rather than scanning the full list.
Do this whenever someone leaves the organisation. Removing a member’s account
does not by itself guarantee that every permission they were granted has been
reviewed, and a departing administrator is the case where a stale permission
matters most.
Related
- Permissions — the permission model itself
- Roles — organizational positions
- Role Groups — automatic role assignment

