Roles & permissions
A role is a named bundle of permissions, and a permission is one action — invite a person, build a course, view a report. Lurno ships a set of built-in roles that every organization gets; on top of those you can build custom roles that grant exactly what your own teams need. Assigning a role to someone is always scoped: to the whole organization, or to one sub-organization, branch, group, or program.
What this does
Section titled “What this does”Three surfaces cover roles, and they are not the same screen:
| Surface | Where | What it’s for |
|---|---|---|
| Roles tab | Organization settings | Build and edit your organization’s custom roles; view the built-in ones read-only |
| Permissions catalog | Avatar menu | Reference list of every permission on the platform, grouped by category |
| My access | Avatar menu | The roles and permissions on your own account, across organizations |
There is also a System permissions page that edits the built-in roles for every customer at once. It is a Lurno platform-operator surface, gated on a platform-level permission — organization administrators never see it, and the built-in roles cannot be edited from inside a tenant.
The built-in roles
Section titled “The built-in roles”Every organization sees the same built-in set. They carry a System badge on the Roles matrix and are read-only: you can look at what each one grants, and assign it, but you cannot change its permissions.
| Role | Shipped for |
|---|---|
| Platform Admin | Lurno staff. Carries the platform-wide wildcard and is never offered when inviting. |
| Client Admin | The organization administrator. Manages people, roles, groups, org settings, and the audit log. Some screens label this role Customer admin. |
| Instructor | Teaches a course or cohort. Cohort-scoped read plus limited updates. |
| Facilitator | Facilitates a cohort. Same starting grants as Instructor. |
| Manager | Line manager of learners. View-level by default. |
| Mentor | Mentors a learner. View-level by default. |
| Reviewer | Reviews submissions. View-level by default. |
| Learner | The default end-user role. Self-view only. |
| Guest | Read-only visitor. Ships with nothing granted, so assignments stay visible in the audit trail. |
| Guardian | Views a linked dependent’s learning data, read-only. See Guardians. |
| Sub-Org Admin Manager | Appoints or replaces a sub-organization’s admin without day-to-day member management power. |
Several of these are deliberately thin on their own — domain modules such as enrollment, assessments, and reporting grant their own permissions on top. If the built-in shape doesn’t match how you work, build a custom role rather than trying to bend one of these.
Role names are not yet consistent between screens. The Roles matrix shows the names above; the invite wizard and the Assign role panel currently fall back to the internal identifier for the roles that have no display name yet, so you may see something like sub_org_admin_manager there. It’s the same role.
Create a custom role
Section titled “Create a custom role”- Open Organization settings and choose the Roles tab. If you have no custom roles yet, a banner offers Create your first role; otherwise use New role above the matrix.
- Step 1 — Start from. Clone one of the built-in roles as a base, or Start blank. Wildcard grants are never copied onto a custom role — only concrete permissions come across.
- Step 2 — Name. Give it a clear name and an optional description. An Advanced disclosure exposes the internal key, auto-derived from the name; leave it alone unless you have a reason.
- Step 3 — Permissions. Tick what the role should be allowed to do. Permissions are grouped by category with plain-English labels, and cloning shows how many you inherited from the template.
- Step 4 — Confirm. Review the name, the base you started from, the permission count, and the What this role will be able to do preview. Choose Create role.
Edit a role
Section titled “Edit a role”The Roles tab renders a matrix — roles down one axis, permissions across the other. Only your organization’s own custom roles are editable; built-in rows are read-only.
- Click a cell to grant the permission, and click again to clear it.
- Shift-click a cell to set an explicit Deny; shift-click again to clear it.
- Click a permission’s column header to apply the same change to every editable role at once. Above five cells, Lurno asks you to confirm first.
- Click a role’s name to open its detail drawer: rename it, edit its description, review its permission grants, see who currently holds it, revoke individual assignments, or archive the role.
Archiving hides a role from the matrix. Assignments people already hold keep working until you revoke them, and you can restore the role within 30 days.
When Lurno pushes back
Section titled “When Lurno pushes back”Some edits open a Review this change dialog before saving. Lurno flags:
- granting a destructive permission to a role it considers low-trust,
- changing a permission on a role you yourself hold, which could lock you out of admin screens,
- granting an action without the view permission it depends on, or revoking a view while the action it supports is still allowed,
- putting a wildcard on a custom role, which will never scope correctly.
Warnings you can save through need only a confirmation. Blocking ones require a written reason of at least six characters, which is stored on the audit trail.
Assign a role to people
Section titled “Assign a role to people”Role assignment happens from the directory, in bulk, not from a person’s profile.
- Open People and tick the people you want. A selection bar appears at the bottom of the screen with the count.
- Choose Assign role.
- Pick the role from the searchable list. Built-in roles are labelled System.
- Pick the scope — the whole organization by default, or a sub-organization, branch, group, or program you’re allowed to assign at.
- Read the capability preview, which spells out what those people will be able to do, then choose Confirm assignment.
A person can hold more than one role, each at its own scope. New access shows up for them on their next page load or sign-in.
To take a role away, open that role from the Roles tab and revoke the assignment on its Assignments list.
How Lurno decides
Section titled “How Lurno decides”Two rules are worth knowing.
Deny beats allow. If any role a person holds explicitly denies a permission, they don’t get it — no matter how many other roles allow it. A permission left unset is simply not granted; only an explicit Deny actively blocks. Use Deny sparingly, because it is a hard block, not a lower priority.
Every action is checked three times. The interface hides controls you can’t use, the server re-checks the same permission before it does anything, and the database enforces it again on the rows themselves. That means hiding a button is never the security boundary — someone who reaches a screen they shouldn’t still gets refused by the server. It also means a permission change is fully effective the moment it saves, even if a stale browser tab still shows the old menu.
Reference
Section titled “Reference”| Term | What it means |
|---|---|
| Allow | Grants the action. |
| Deny | Blocks the action, even if another of the person’s roles allows it. |
| Unset | Neither grants nor blocks. Treated as not granted. |
| System role | A built-in role. Read-only inside your organization. |
| Custom role | A role your organization created. Editable and archivable. |
| Scope | Where an assignment applies: organization, sub-organization, branch, group, or program. |
| Not delegable | A permission the catalog marks as reserved for built-in roles. |
Troubleshooting
Section titled “Troubleshooting”I can’t find the Roles screen. It’s a tab inside Organization settings, not a top-level menu entry, and the whole page needs permission to update the organization.
I can open the Roles tab but creating a role is refused. Opening the page and creating a role are separate permissions. Ask whoever manages roles to grant you the second one.
A cell won’t respond to clicks. That row is a built-in role. Clone it into a custom role and edit the copy.
A cell refuses to save. The permission is marked Not delegable in the Permissions catalog, which means it can only sit on a built-in role. Wildcards don’t appear in the role builder at all.
Someone can’t do something you expected. Check every role they hold and every scope. An explicit Deny on any one of them wins. Their own My access page lists exactly what they hold and where.
Someone can do more than intended. They likely hold a second role, or hold one at a scope higher up your organization tree than you meant. Open the role’s Assignments list and revoke the one that’s wrong.
The change hasn’t taken effect for them. The server applies it immediately; their browser may still be showing a cached menu. Ask them to reload or sign in again.