Admin GuidesRoles and Permissions

Roles and Permissions

Plan availability (2026-07-23): the seven built-in roles are available on every plan. Creating, cloning, or editing custom roles requires the Growth plan or higher — on a lower plan the custom-roles section shows an inline upgrade banner. Custom roles that were already assigned keep working after a downgrade (nobody loses access), and deleting a custom role is always possible.

EmbayLMS controls what each person can do through roles. This guide explains the seven built-in roles, how to assign them, and how to build your own custom roles from the granular permission catalog.

You manage all of this under Settings → User Management → Roles and Permissions.


Prerequisites

  • You are an Admin or Owner (both can open Roles and Permissions).
  • Only an Owner can grant Owner-level permissions (Billing and the account-level Settings pages).

The seven built-in roles

Built-in roles are fixed and read-only — you can’t edit them, but you can clone any of them into a new custom role. Where a role is scoped, it only reaches the courses, groups, or people it is assigned to; the scope is enforced on the server for every action.

RoleScopeWhat it can do
LearnerThemselvesBrowse the catalog, self-enroll where offered, attend training, track their own progress and credentials.
InstructorAssigned coursesSee their assigned courses and the learners in them, edit course content and attachments, schedule and run ILT/VILT sessions, grade quizzes and assignments, and view analytics for those courses. Not a learner — no catalog or self-enrollment.
ManagerTheir report chainProgress and analytics for everyone who reports to them (directly or indirectly, via the Manager field on a user), and the ability to enroll their team — in courses and, from a session’s page, into ILT/VILT sessions. Sessions are otherwise read-only for them. Dropping enrollments and exporting reports are optional permissions you can add.
Group AdminAssigned groupsMember administration inside their groups: create, deactivate and reactivate members, change their role (up to their own level), manage group membership, enroll and unenroll members, and run and export group-scoped reports. Cannot edit profile details, create groups, appoint group admins or reach other groups. See Group Admin Role.
E-commerce AdminTenantEverything in the E-commerce area — pricing, coupons, orders, refunds, revenue, storefront. Apart from the Owner, no other role gets e-commerce by default.
AdminTenantDay-to-day administration of the whole tenant: users, groups, courses, learning paths, sessions, skills, certificates, templates, analytics and gamification. In Settings an Admin sees only User Management (its Roles and Permissions tab), Data Management (its Data Import and SCORM Packages tabs) and Gamification; not Billing or the account-level Settings pages.
OwnerTenantEverything an Admin can do, plus all of e-commerce, every Settings page (general, content policy, branding, notifications, registration, SSO, SCIM, support access, security, data retention, integrations, audit) and Billing. The account owner. Every tenant always has at least one Owner.

Owner vs. Admin. The important line is Billing and the account-level Settings. Admins run the platform day to day; Owners hold the account-level controls. This keeps administration delegable without handing over billing or security.


Assign a role to a user

  1. Go to Users and open the person’s profile.
  2. Click Edit, choose their primary role in the Role field, and click Save changes.
  3. To give someone more than one role (permissions are cumulative), use the Roles panel on their profile to add extra built-in or custom roles, then click Save roles.

A role change is read when the person signs in, so ask them to sign out and back in to pick it up.

You can only assign a role at your own level or below — an Admin cannot create an Owner, and a Group Admin cannot create an Admin.

Setting up an instructor

Instructor takes two steps, and both are required:

  1. Give them the Instructor role — either as their primary Role, or added in the Roles panel. This grants the permissions (course content, sessions, grading, analytics).
  2. Assign them to courses — open each course, go to the Instructors tab, and add them. This defines which courses those permissions reach.

Do them in that order. The tab’s search lists only people who already hold the Instructor role, so someone without it does not appear there at all — the assignment on its own would confer nothing.

Only Owners and Admins assign instructors. Group admins can assign roles to their own members, but they don’t see the Instructors tab: an instructor assignment reaches every learner in the course, well beyond the group admin’s groups. (A custom role that adds user:assign_role to an instructor reaches only that instructor’s own courses.)

An instructor’s admin screens are scoped to their assigned courses throughout: the course list and folder tree, the enrolled learners on each course, the Planned sessions list, the grading queue, and Analytics all show their courses only.

Instructors edit courses; they do not create or configure them. Outside their remit:

Instructors canInstructors cannot
Edit content, modules, lessons and attachments of assigned coursesCreate, publish, archive or delete a course
Build quizzes and surveys on assigned coursesSet a course’s price (E-commerce Admin / Owner)
Schedule and run sessions for assigned coursesCreate or edit learning paths
Grade, and view analytics for their coursesCreate or edit certificate templates
Issue a certificate by hand on a completed enrollment of an assigned courseRevoke a certificate
—Create course folders or categories

What a manager can do with sessions

A Manager sees the Planned sessions list and can open any session, but the page is read-only for them plus one thing: enrolling their own team.

Managers canManagers cannot
Open the Planned sessions list and any session’s pageCreate, edit, publish or cancel a session
See the roster — their own reports onlySee learners outside their report chain on a roster
Bulk-enroll their reports by email from the session pageEnroll anyone who does not report to them — those names come back as not in your team and are not seated
Promote one of their reports from the waitlistTake attendance, run QR check-in, send announcements, manage the Zoom meeting or recording
Enroll their reports in courses (with a series choice where the course has one)Create recurring assignments (group automation — needs the group side)

The scope is the report chain: everyone whose Manager field points at them, directly or through other managers. A name outside the chain is refused on the server regardless of what the page shows.

Custom roles cloned from Manager. Cloning copies the permission list at the moment you clone. A role cloned before 2026-09-11 does not gain the session permissions automatically — edit it and tick session:view and enrollment:create if you want the same behaviour.


Create a custom role

Use a custom role when the built-ins don’t fit — for example a “Reporting Analyst” who can only view and export analytics.

  1. Open Settings → User Management → Roles and Permissions.
  2. Either click New role to start from scratch, or click Clone on any role (built-in or custom) to start from its permissions.
  3. Give the role a name.
  4. Tick the permission scopes it should have. Scopes you can’t grant yourself are greyed out (you can never grant a permission you don’t hold).
  5. Save. Assign the role to users from their profile.

Permission catalog

Permissions follow a resource:action format and the editor lists them by resource (for example course, content, user, group, enrollment, session, skill, quiz, grading, certificate, template, report, messaging, ecommerce, role, one group per Settings sub-page, and billing). Pick exactly the actions a role needs.

FieldDescription
Role nameDisplay name of the custom role (must be unique; can’t reuse a built-in name).
Permission scopesThe resource:action scopes granted. Greyed-out scopes are ones you don’t hold and therefore can’t grant.
MembersHow many users currently hold this role.

Troubleshooting

SymptomCauseFix
A user can’t see Settings or Billing.They’re an Admin, not an Owner. Billing and the account-level Settings pages are Owner-only; an Admin sees only Roles and Permissions, Data Import, SCORM Packages and Gamification.Have an Owner perform the action, or grant the specific Owner-level permission via a custom role.
”You cannot assign a role above your own level.”You tried to grant a role higher than yours (e.g. an Admin making an Owner).Ask an Owner to make the assignment.
An Owner-level scope is greyed out in the role editor.You don’t hold that permission, so you can’t grant it.An Owner can grant it, or add it to your own role first.
”A tenant must have at least one Owner.”You tried to remove the last Owner.Assign the Owner role to another user first, then change this one.
An instructor sees no courses.They aren’t assigned to any course.Open the course editor → Instructors tab and add them.
A person doesn’t appear in a course’s Instructors search.They don’t hold the Instructor role (the search lists only people who do), or they are already assigned to this course.Give them the Instructor role first (primary Role field, or the Roles panel), then add them to the course.
”This person needs the Instructor role before they can be assigned to a course.”Their Instructor role was removed after you picked them.Give them the Instructor role again, then add them to the course.
An instructor sees no sessions.Sessions belong to courses they aren’t assigned to. The Planned sessions list only shows sessions for their own courses (including drafts).Assign them to the course that owns the session.
An Admin has no Pricing tab on a course.Pricing is an e-commerce permission, and e-commerce belongs to E-commerce Admin and Owner by default — no other role holds it.Give them the E-commerce Admin role, or add ecommerce:pricing to a custom role.
A group admin can’t see a user.The user isn’t a member of any group the admin manages.Add the user to one of their groups.