Permissions
What a role can grant, and how far a grant reaches.
Beyond a valid access token, most endpoints require one of the permissions below — each endpoint's description names the one it checks. Permissions are granted through department roles: a role lists the permission strings it grants, and every holder of the role holds them. The set is closed; a role granting any other string grants nothing.
Learning records
View learning records and their supporting evidence.
Create, edit, approve and archive records and their evidence.
Permanently delete learning records together with their evidence, so the hours and completions they credited disappear — people can lose progress toward, or eligibility for, certifications. Separate from records:write, which only archives.
Subject matters
View the subject matters records are recorded against.
Create, edit and archive subject matters.
Permanently delete subject matters. Every record, event, quiz, course and certification type tagged with one loses the tag, so hours filed under it stop counting. Separate from subjects:write, which only archives.
Certifications
View certification types, role requirements, and other users' status.
Manage and duplicate certification types, rules and role requirements; set due dates, record sign-offs, decide requests, and grant or revoke certifications.
Permanently delete certification types together with every award of them — holders lose the certification and past awards vanish. Separate from certifications:write, which only archives.
Quizzes
View question banks with their answers, quiz configuration, assignments, and other users' attempts and results.
Manage question banks and questions, and copy or move questions between banks; create, duplicate, configure, assign, publish and archive quizzes; release held-back results.
Work the grading queue: award points and feedback on manually graded questions and finalize attempts. Does not include reading banks or releasing results.
Permanently delete question banks together with their questions: quizzes stop drawing from them, and past attempts lose those questions' answers. Separate from quizzes:write, which only archives.
External LMS
View the catalogue of external LMS servers, their courses, external-user mappings, and imported course grades.
Manage external LMS servers, their courses and external-user mappings. Importing grades needs records:write instead, since it writes learning records.
Permanently delete catalogue courses together with their imported grades and the learning records those created. Separate from external-lms:write, which only archives.
SCORM courses
View the hosted SCORM course catalogue, and other users' attempts and results. Also admits its holder to trainers-only courses.
Upload SCORM packages, replace a course's package, edit course metadata and audience, and archive courses. Taking a course for trainees needs no grant; its audience — the organization, or its owning department — is the authorization. Trainers-only courses need scorm:read.
Permanently delete courses together with every attempt, the completion records they reported, and the package. Separate from scorm:write, which only archives.
Job aids
View the job aid catalogue, and who has viewed each aid. Also admits its holder to trainers-only job aids.
Create and duplicate job aids, upload, replace and arrange their files, edit their text, subjects and audience, and archive them. Reading an aid for trainees needs no grant; its audience — the organization, or its owning department — is the authorization.
Permanently delete job aids together with their files, their view history and the proof rules that required viewing them. Separate from job-aids:write, which only archives.
Training events
View training events, their subject tags, trainers, and participant rosters with attendance. Participants and trainers see their own events without this grant.
Create, duplicate, edit, cancel and archive training events; tag subjects, schedule trainers, manage participants and mark attendance — which writes a completed learning record for each attendee.
Permanently delete events together with their rosters and the learning records attendance wrote, so the hours those credited disappear. Separate from events:write, which archives or cancels.
QR codes
View the QR code catalogue — each code's destination and its history of changes — and who has scanned each code. Also admits its holder through raw-URL codes of its owner.
Create QR codes, point them at a job aid, course, quiz or URL, change where an existing code points, and archive codes. Scanning needs no grant; the destination's audience — or, for a URL, the code's owner — is the authorization.
Permanently delete QR codes together with every recorded scan and the history of their destinations. Separate from qr-codes:write, which only archives.
Forums
Read the forums, discussions and replies of the departments in scope without holding a role there, for oversight. Read only. Taking part in a department's forums needs no grant; everyone holding a role in it, or in a department beneath it, may.
Create forums for the departments in scope, rename and describe them, and archive or restore them — an archived forum stays readable but takes no new posts. Permanently deleting a forum needs forums:delete.
Pin and unpin discussions, lock and unlock them, and reply to locked ones. Also reads and takes part in the discussions it moderates. Deleting other people's posts needs forums:delete.
Permanently delete anyone's discussions — with every reply beneath them — and replies, and whole forums with every discussion in them. Authors may always delete their own replies, and their own discussions until someone else replies. Its holder still needs to see the forum.
Directory
Create departments beneath the organizations and departments in scope, and the roles departments define, and assign those roles to members who already hold a role in scope. Creating organizations stays superuser-only.
Permanently delete roles of the departments in scope. Everyone holding one loses every permission it granted, its reporting lines, certification requirements and assignments are removed, and nothing records who ever held it. Separate from directory:write, which only edits roles.
Scope
A permission applies within the department whose role granted it: it covers rows owned by that department, by any department nested beneath it at any depth, and by the department's organization directly — but not by sibling departments. A row the caller cannot read answers 404, not 403.
Exemptions
- Superusers bypass every permission check.
- Any valid token may read learning records whose learner is the token's own subject, and submit pending records about themselves. A record flagged hidden from learner opts out of that read: its learner sees it only through records:read over the owner.
- Signed-in users see their own certification status, and may claim or request the certifications their active roles require — no grant needed.
- Taking an assigned quiz needs no grant.
- Reading the directory needs no permission, and creating organizations is superuser-only — no departmental grant covers the top of the hierarchy.