Admin GuidesGroup Admin Role

Group Admin Role

Overview

The Group Admin role lets you delegate administrative access to a specific user without promoting them to full tenant admin. A group admin administers the members of the groups they are assigned to, and only those groups.

Within their groups a group admin can:

  • Create members. A user they create is added to their groups automatically.
  • Deactivate and reactivate members.
  • Change a member’s role, up to their own level: Learner, Instructor, Manager, E-commerce Admin or Group Admin, never Admin or Owner.
  • Add and remove group members. They can add only people who are already members of one of the groups they administer, for example to move someone from one of their groups to another. Anyone else is added by an Owner or Admin, or created by the group admin (a user they create joins their groups automatically).
  • Enroll and unenroll members in courses and learning paths, and assign courses to their groups.
  • Run and export reports scoped to their groups.

They cannot:

  • edit a member’s profile details (name, email, account type, manager, custom fields);
  • create, rename or delete groups, or appoint other group admins (Owners and Admins do that);
  • reach users outside their groups;
  • import users from a CSV file;
  • open the account-level Settings pages or Billing;
  • assign instructors to courses, or revoke certificates;
  • assign a course, add an automatic enrollment rule or create a recurring assignment for a group they don’t administer, or add a rule based on course completion or a user attribute (those select learners across the whole organization).

This is useful for team leads, department managers, or regional coordinators who need to manage their own people without accessing the rest of the organization. For the full role model, see Roles and Permissions.


Permission Matrix

The default permissions of each built-in role, as the app enforces them. Their groups means members of the groups the group admin is assigned to; their report chain means everyone whose Manager field points at the manager, directly or through other managers.

CapabilityLearnerManagerGroup AdminAdminOwner
See usersThemselvesTheir report chainTheir groupsEveryoneEveryone
Create usersNoNoYes, added to their groupsYesYes
Edit profile detailsNoNoNoYesYes
Deactivate or reactivate usersNoNoTheir groupsYesYes
Change a user’s roleNoNoTheir groups, up to Group AdminUp to AdminAny role
Import users from CSVNoNoNoYesYes
Add or remove group membersNoNoTheir groups, adding only people already in one of themYesYes
Create, rename or delete groupsNoNoNoYesYes
Appoint group adminsNoNoNoYesYes
Enroll users in coursesThemselves onlyTheir report chainTheir groupsYesYes
Unenroll usersNoNo (grantable)Their groupsYesYes
View reportsNoTheir report chainTheir groupsEveryoneEveryone
Export reportsNoNo (grantable)Their groupsYesYes
Settings pagesNoNoNoRoles and Permissions, Data Import, SCORM Packages, GamificationAll, plus Billing

Grantable means the permission is not in the built-in role but can be added through a custom role (see Roles and Permissions).


Step-by-Step: Assign a Group Admin

Two steps, and both are required: the role grants the permissions, the group assignment decides which members those permissions reach. Assigning groups to someone who does not hold the role gives them nothing.

1. Give them the role

  1. Navigate to Users and open the person’s profile.
  2. Click Edit, choose Group admin in the Role field, and click Save changes. (Or keep their primary role and add Group admin as an extra role in the Roles panel, then click Save roles.)

2. Assign their groups

  1. On the same profile, scroll to the Group Admin Assignments section.
  2. Open the Select a group to add… dropdown and choose a group.
  3. Click Add group.
  4. Repeat for each group this user should administer.

You can also start from the group: in the Groups list, click Manage on the group’s row, pick the person in Add a group admin (type part of their name or email) and click Assign.

A group assignment applies from the group admin’s next page load. A role change is read when they sign in, so ask them to sign out and back in after you change their role.

Note: The Group Admin Assignments section is shown to anyone whose role grants the group:admin_assign permission: Owners and Admins by default, or a custom role that includes it. A group admin cannot appoint other group admins.


Step-by-Step: Remove a Group Admin Assignment

  1. Navigate to Users and open the group admin’s profile.
  2. In the Group Admin Assignments section, find the group you want to remove.
  3. Click the × button next to the group name.
  4. The assignment is removed immediately.

From the group side, click Manage on the group’s row in the Groups list and click Remove next to the person.

If you remove every group from a group admin, they keep the role but see no members, enrollments or report data. To fully demote them, also change their role: open their profile, click Edit, choose another role in the Role field and click Save changes.


Configuration Reference

FieldDescriptionRequired
UserThe user receiving group admin access. Must hold the Group Admin role.Yes
GroupThe group they will administerYes
Assigned bySet automatically to the acting adminAuto
Assigned atTimestamp of assignmentAuto

Multiple groups can be assigned to a single user. Each assignment is independent.


What the Group Admin Sees

When a group admin signs in, they see:

  • Users — members of their assigned groups only. They can create members (Create User) and open a member’s profile to deactivate them, change their role or enroll them.
  • Groups — their assigned groups only. Opening a group lets them add and remove members (adding only people already in one of their groups) and assign courses to it (see Assigning Courses to Groups).
  • Analytics — the KPI cards and the Course Compliance Matrix cover the members of their groups. With no group filter selected they see all of their groups together; they can filter to one or several of their groups, and Export CSV exports what they see. Choosing a group they are not assigned to is refused.

They cannot see other users, other groups, or the account-level Settings pages.


Troubleshooting

SymptomCauseResolution
Group admin sees an empty user listNo groups assigned, or the assigned groups have no membersAssign at least one group from the user’s profile, and check the group has members
Group admin sees nothing even though groups are assignedThe user does not hold the Group Admin role, or has not signed in again since the role changeGive them the role (primary Role field or the Roles panel), then ask them to sign out and back in
”Access restricted to your assigned groups” errorThe group admin tried to reach a group they are not assigned toExpected behavior: assign the group, or use a higher-privilege account
”You cannot assign a role above your own level.”The group admin tried to make someone an Admin or OwnerAsk an Admin or Owner to make the change
Group Admin Assignments section not visibleYou are not an Owner or AdminOnly Owners and Admins can appoint group admins
Group admin cannot add someone to their groupThe person is not a member of any group the group admin administers. A group admin cannot bring in people from elsewhere in the organizationAsk an Owner or Admin to add the person, or have the group admin create them as a new user
Group admin cannot edit a member’s name or emailEditing profile details needs the user:update permission, which the role does not includeAsk an Admin or Owner, or grant the permission through a custom role

SOC 2 Notes

All group admin assignments and removals are written to the audit_log table with:

  • action: "group_admin.assigned" or "group_admin.unassigned"
  • resourceType: "group_admin_assignment"
  • Before/after state, actor identity, IP address, and user agent

This satisfies SOC 2 CC6.3 (role changes logged with before/after state).