Group Admin Role
Overview
The Group Admin role lets you delegate administrative access to a specific user without promoting them to full tenant admin. A group admin administers the members of the groups they are assigned to, and only those groups.
Within their groups a group admin can:
- Create members. A user they create is added to their groups automatically.
- Deactivate and reactivate members.
- Change a member’s role, up to their own level: Learner, Instructor, Manager, E-commerce Admin or Group Admin, never Admin or Owner.
- Add and remove group members. They can add only people who are already members of one of the groups they administer, for example to move someone from one of their groups to another. Anyone else is added by an Owner or Admin, or created by the group admin (a user they create joins their groups automatically).
- Enroll and unenroll members in courses and learning paths, and assign courses to their groups.
- Run and export reports scoped to their groups.
They cannot:
- edit a member’s profile details (name, email, account type, manager, custom fields);
- create, rename or delete groups, or appoint other group admins (Owners and Admins do that);
- reach users outside their groups;
- import users from a CSV file;
- open the account-level Settings pages or Billing;
- assign instructors to courses, or revoke certificates;
- assign a course, add an automatic enrollment rule or create a recurring assignment for a group they don’t administer, or add a rule based on course completion or a user attribute (those select learners across the whole organization).
This is useful for team leads, department managers, or regional coordinators who need to manage their own people without accessing the rest of the organization. For the full role model, see Roles and Permissions.
Permission Matrix
The default permissions of each built-in role, as the app enforces them. Their groups means members of the groups the group admin is assigned to; their report chain means everyone whose Manager field points at the manager, directly or through other managers.
| Capability | Learner | Manager | Group Admin | Admin | Owner |
|---|---|---|---|---|---|
| See users | Themselves | Their report chain | Their groups | Everyone | Everyone |
| Create users | No | No | Yes, added to their groups | Yes | Yes |
| Edit profile details | No | No | No | Yes | Yes |
| Deactivate or reactivate users | No | No | Their groups | Yes | Yes |
| Change a user’s role | No | No | Their groups, up to Group Admin | Up to Admin | Any role |
| Import users from CSV | No | No | No | Yes | Yes |
| Add or remove group members | No | No | Their groups, adding only people already in one of them | Yes | Yes |
| Create, rename or delete groups | No | No | No | Yes | Yes |
| Appoint group admins | No | No | No | Yes | Yes |
| Enroll users in courses | Themselves only | Their report chain | Their groups | Yes | Yes |
| Unenroll users | No | No (grantable) | Their groups | Yes | Yes |
| View reports | No | Their report chain | Their groups | Everyone | Everyone |
| Export reports | No | No (grantable) | Their groups | Yes | Yes |
| Settings pages | No | No | No | Roles and Permissions, Data Import, SCORM Packages, Gamification | All, plus Billing |
Grantable means the permission is not in the built-in role but can be added through a custom role (see Roles and Permissions).
Step-by-Step: Assign a Group Admin
Two steps, and both are required: the role grants the permissions, the group assignment decides which members those permissions reach. Assigning groups to someone who does not hold the role gives them nothing.
1. Give them the role
- Navigate to Users and open the person’s profile.
- Click Edit, choose Group admin in the Role field, and click Save changes. (Or keep their primary role and add Group admin as an extra role in the Roles panel, then click Save roles.)
2. Assign their groups
- On the same profile, scroll to the Group Admin Assignments section.
- Open the Select a group to add… dropdown and choose a group.
- Click Add group.
- Repeat for each group this user should administer.
You can also start from the group: in the Groups list, click Manage on the group’s row, pick the person in Add a group admin (type part of their name or email) and click Assign.
A group assignment applies from the group admin’s next page load. A role change is read when they sign in, so ask them to sign out and back in after you change their role.
Note: The Group Admin Assignments section is shown to anyone whose role grants the
group:admin_assignpermission: Owners and Admins by default, or a custom role that includes it. A group admin cannot appoint other group admins.
Step-by-Step: Remove a Group Admin Assignment
- Navigate to Users and open the group admin’s profile.
- In the Group Admin Assignments section, find the group you want to remove.
- Click the × button next to the group name.
- The assignment is removed immediately.
From the group side, click Manage on the group’s row in the Groups list and click Remove next to the person.
If you remove every group from a group admin, they keep the role but see no members, enrollments or report data. To fully demote them, also change their role: open their profile, click Edit, choose another role in the Role field and click Save changes.
Configuration Reference
| Field | Description | Required |
|---|---|---|
| User | The user receiving group admin access. Must hold the Group Admin role. | Yes |
| Group | The group they will administer | Yes |
| Assigned by | Set automatically to the acting admin | Auto |
| Assigned at | Timestamp of assignment | Auto |
Multiple groups can be assigned to a single user. Each assignment is independent.
What the Group Admin Sees
When a group admin signs in, they see:
- Users — members of their assigned groups only. They can create members (Create User) and open a member’s profile to deactivate them, change their role or enroll them.
- Groups — their assigned groups only. Opening a group lets them add and remove members (adding only people already in one of their groups) and assign courses to it (see Assigning Courses to Groups).
- Analytics — the KPI cards and the Course Compliance Matrix cover the members of their groups. With no group filter selected they see all of their groups together; they can filter to one or several of their groups, and Export CSV exports what they see. Choosing a group they are not assigned to is refused.
They cannot see other users, other groups, or the account-level Settings pages.
Troubleshooting
| Symptom | Cause | Resolution |
|---|---|---|
| Group admin sees an empty user list | No groups assigned, or the assigned groups have no members | Assign at least one group from the user’s profile, and check the group has members |
| Group admin sees nothing even though groups are assigned | The user does not hold the Group Admin role, or has not signed in again since the role change | Give them the role (primary Role field or the Roles panel), then ask them to sign out and back in |
| ”Access restricted to your assigned groups” error | The group admin tried to reach a group they are not assigned to | Expected behavior: assign the group, or use a higher-privilege account |
| ”You cannot assign a role above your own level.” | The group admin tried to make someone an Admin or Owner | Ask an Admin or Owner to make the change |
| Group Admin Assignments section not visible | You are not an Owner or Admin | Only Owners and Admins can appoint group admins |
| Group admin cannot add someone to their group | The person is not a member of any group the group admin administers. A group admin cannot bring in people from elsewhere in the organization | Ask an Owner or Admin to add the person, or have the group admin create them as a new user |
| Group admin cannot edit a member’s name or email | Editing profile details needs the user:update permission, which the role does not include | Ask an Admin or Owner, or grant the permission through a custom role |
SOC 2 Notes
All group admin assignments and removals are written to the audit_log table with:
action: "group_admin.assigned"or"group_admin.unassigned"resourceType: "group_admin_assignment"- Before/after state, actor identity, IP address, and user agent
This satisfies SOC 2 CC6.3 (role changes logged with before/after state).