> For the complete documentation index, see [llms.txt](https://synap.ac/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://synap.ac/docs/platform/advanced-features/access-and-permissions.md).

# Access and permissions

Permissions control what members of your internal team can see and do in Synap's administration area. They are mainly used to give **Educator** and **Marker** groups clearly defined responsibilities—for example, allowing tutors to edit Library content without letting them publish Exams or manage Users.

Permissions are deliberately flexible. This makes them useful for larger teams, but it also means that a complicated permission structure can be difficult to reason about. Start with the simplest arrangement that meets your needs.

{% hint style="info" %}
**Permissions are for staff access, not student access.** Use User Groups, Assignments, Collection access and Exam scheduling to decide what Students can study or take. Those delivery controls are described on the relevant product pages.
{% endhint %}

### Who permissions apply to

| User type         | How access is normally controlled                                                                                                                          |
| ----------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Administrator** | Has full access to the portal. Administrators do not need individual permissions.                                                                          |
| **Manager**       | Has broad administrative access, apart from certain portal-wide actions reserved for Administrators. Managers do not normally need individual permissions. |
| **Educator**      | Receives administrative permissions through one or more Educator User Groups. This is the main audience for advanced permissions.                          |
| **Marker**        | Receives a smaller set of Exam and marking permissions through Marker User Groups.                                                                         |
| **Student**       | Uses the simpler student-access system. The configurable permissions described on this page do not determine which learning content a Student can use.     |

A permission does not normally belong directly to one person. It is granted to a User Group, and every active member of that group receives it. You can view an individual user's **Permissions** page to see their combined effective access and where each permission came from.

### The two parts of every permission

It helps to separate two questions:

1. **Who receives the permission?** An Educator or Marker User Group.
2. **What does the permission cover?** Every resource of a type, or one specific resource.

For example, you could give the **Biology tutors** Educator group permission to edit every Library item, or permission to edit only the **Year 11 Biology notes** item.

#### Global permissions

A global permission applies across an entire area of the portal. **Edit Collections**, for example, allows the group to edit all Collections, including Collections created later.

Manage global permissions from the **Global Permissions** tab of an Educator or Marker User Group. Global permissions are best for a stable role whose members genuinely need the same access throughout the portal.

Some actions only make sense globally. **Create Exams**, for example, cannot be limited to a particular Exam because the Exam does not exist yet.

<figure><img src="/files/kNiJW48ctaxce3su1QWD" alt=""><figcaption></figcaption></figure>

#### Permissions assigned to a User Group

The User Group is the recipient of a permission. A member receives the combined permissions of every group they belong to, including permissions inherited through parent groups.

If User A belongs to both Group A and Group B, their effective access is:

> **Group A permissions + Group B permissions + inherited parent-group permissions**

Permissions are additive. A permission granted by one group is not cancelled because another group does not grant it. Similarly, a permission inherited from a parent group cannot be removed from a child group.

{% hint style="warning" %}
Before adding a person to another Educator or Marker group, check what that group already permits. Group membership can increase access in several product areas at once.
{% endhint %}

#### Specific permissions

A specific permission applies to one resource, such as one Exam, Collection, Library item, Assignment, Course or User Group. You normally assign it from that resource's **Access** or **Permissions** page.

<figure><img src="/files/E1inQAJo9051NlUEcn25" alt=""><figcaption></figcaption></figure>

Specific permissions are useful when a team is responsible for a defined part of the portal. For example:

* Biology tutors can edit the Biology question bank but not other Library items.
* Invigilators can view attempts for one Exam without being able to edit the Exam.
* A regional support team can view and edit users in one Student User Group.

A specific permission adds access; it does not restrict a global permission. If a group can already edit every Exam, removing it from one Exam's Access page will not stop its members editing that Exam.

#### Permissions for a specific User Group

A User Group can also be the resource being managed. These permissions answer questions such as:

* Can this Educator group see the members of the **Year 11 Students** group?
* Can it add, edit or invite users in that group?
* Can it view the learning content assigned to that group?
* Can it export the group's users or manage their learning records?

This is a type of specific permission. It is different from the permissions *held by* the Educator group. One group is receiving the permission; the other User Group is the resource the permission applies to.

### How Synap combines and checks permissions

When a member opens a page or performs an action, Synap checks all applicable permissions from their direct groups and those groups' parents. The action is allowed when any applicable permission grants it.

This has several practical consequences:

* **Access accumulates.** Membership of more groups can only add effective permissions.
* **Global access continues to apply on specific resources.** A local Access page cannot take away a global grant.
* **Parent permissions flow down.** Put a permission on a parent group only when every relevant child group should receive it.
* **Permissions are action-specific.** Being able to view a resource does not automatically allow editing, deleting, publishing or managing its access.
* **Manage access is powerful.** It allows a group to assign specific administrative permissions to other groups for the relevant resource; it does not mean granting student access unless the permission is explicitly called **Grant or revoke access**.

### When to use advanced permissions

Advanced permissions are most helpful for larger internal teams that need clear separations of responsibility—for example, separate content authors, exam administrators, markers and reporting teams.

For a small team, using Administrators and Managers for most staff access is usually easier to understand and maintain. Add Educator roles only where someone needs a narrower set of capabilities, and avoid creating a different group for every small variation unless there is a clear operational need.

Permissions are intended to separate responsibilities **within one organisation**. They are not the recommended way to create a security boundary between different customers, clients or partner organisations. If you provide non-Student access to external organisations—such as an extended-enterprise or business-to-business-to-consumer (B2B2C) service—use **Subportals** to create that organisational separation.

### A practical setup pattern

Suppose a tutoring company has lead tutors, assistant tutors and freelance markers:

1. Keep the owner and trusted operational leads as Administrators or Managers.
2. Create an **Assistant tutors** Educator group with global permission to view Library items and Collections.
3. Give that group specific edit permission only on the Library items and Collections it maintains.
4. Create a **Freelance markers** Marker group and assign it only to the relevant Exams, with view-attempt and marking permissions.
5. Open the effective Permissions page for a test member of each group and confirm the sources of their access.
6. Sign in as those test users and test representative view, edit, export, marking and access-management actions.

This keeps broad operational access simple while using specific permissions only where the separation is valuable.

### Test changes carefully

{% hint style="warning" %}
Permission changes can affect several pages and workflows at once. Test them with representative non-Administrator accounts before relying on them in a live Exam or operational process.
{% endhint %}

For each role, test both sides of the boundary:

* an action the role **should** be able to perform;
* a similar action it **should not** be able to perform;
* a resource covered by a global permission;
* a resource covered only by a specific permission;
* a user who belongs to more than one group;
* any inherited permission from a parent group; and
* sensitive actions such as deleting, exporting, publishing, releasing results or managing access.

Recheck the role after changing group membership or a parent group's permissions. Keep a short record of the intended role and its required permissions so future changes can be compared with the original design.

### Permission matrix

The tables below describe the configurable permissions available to Educator groups. Marker groups are offered a smaller relevant subset, mainly Exam attempts, marks and proctoring.

**Global** means the permission can apply to every resource in that area. **Specific** means it can be assigned for one resource. **Both** means either scope is available.

The options shown on your portal can vary with enabled features. Internal system permissions and actions available only to Administrators or Managers are not included.

#### Library content

Library content includes Quizzes, Surveys, Notes, Shareable Content Object Reference Model (SCORM) packages, files and other supported Library item types.

| Permission        | Scope  | What it allows                                                                |
| ----------------- | ------ | ----------------------------------------------------------------------------- |
| **Create**        | Global | Create new Library items.                                                     |
| **View**          | Both   | Find and open Library items in the administration area.                       |
| **Edit**          | Both   | Change the content and settings of Library items.                             |
| **Delete**        | Both   | Delete Library items.                                                         |
| **Manage access** | Both   | Assign specific administrative permissions for Library items to other groups. |

#### Collections

| Permission                 | Scope  | What it allows                                                                    |
| -------------------------- | ------ | --------------------------------------------------------------------------------- |
| **Create**                 | Global | Create new Collections.                                                           |
| **View**                   | Both   | Find and open Collections in the administration area.                             |
| **Edit**                   | Both   | Change Collection details, content and configuration.                             |
| **Grant or revoke access** | Both   | Control which Students and Student groups can use Collections.                    |
| **Delete**                 | Both   | Delete Collections.                                                               |
| **Manage access**          | Both   | Assign specific administrative permissions for Collections to other staff groups. |

#### Courses

| Permission        | Scope  | What it allows                                                          |
| ----------------- | ------ | ----------------------------------------------------------------------- |
| **Create**        | Global | Create new Courses.                                                     |
| **View**          | Both   | Find and open Courses in the administration area.                       |
| **Edit**          | Both   | Change Course details, structure and settings.                          |
| **Delete**        | Both   | Delete Courses.                                                         |
| **Manage access** | Both   | Assign specific administrative permissions for Courses to other groups. |

#### Assignments

| Permission                   | Scope  | What it allows                                                              |
| ---------------------------- | ------ | --------------------------------------------------------------------------- |
| **Create**                   | Global | Create new Assignments.                                                     |
| **View**                     | Both   | Find and open Assignments in the administration area.                       |
| **Edit**                     | Both   | Change Assignment content and settings.                                     |
| **Export attempts**          | Both   | Export attempt data collected through Assignments.                          |
| **Export surveys**           | Both   | Export Survey responses collected through Assignments.                      |
| **Edit deadline**            | Both   | Change a learner's Assignment deadline.                                     |
| **Reset**                    | Both   | Reset an Assignment for a learner so they can start again.                  |
| **Revoke**                   | Both   | Revoke a learner's Assignment.                                              |
| **Internal review item**     | Both   | Leave an internal review or share item feedback with the learner.           |
| **Manual review item**       | Both   | Approve or reinstate individual submitted items.                            |
| **Manual review assignment** | Both   | Approve or reject a submitted Assignment.                                   |
| **Reissue**                  | Both   | Reissue an Assignment.                                                      |
| **Delete**                   | Both   | Delete Assignments.                                                         |
| **Manage access**            | Both   | Assign specific administrative permissions for Assignments to other groups. |

#### Exams

Exam permissions are more granular because building, delivering, marking and releasing an Exam can be divided between different teams.

**Exam setup and delivery**

| Permission                     | Scope                       | What it allows                                                                                                          |
| ------------------------------ | --------------------------- | ----------------------------------------------------------------------------------------------------------------------- |
| **Create**                     | Global                      | Create new Exams.                                                                                                       |
| **View**                       | Both                        | Find and open Exams in the administration area.                                                                         |
| **View attempts**              | Global or specific variants | View attempts across all Exams or only the selected Exam. This does not by itself allow marking or changing an attempt. |
| **Edit**                       | Both                        | Change Exam settings.                                                                                                   |
| **Edit content**               | Both                        | Change the sections and content used by an Exam.                                                                        |
| **Publish**                    | Both                        | Publish a new version of an Exam. Some older portals may also show a legacy **Schedule** permission.                    |
| **Message**                    | Both                        | Send supported Exam emails or resend registration messages.                                                             |
| **Delete**                     | Both                        | Delete Exams.                                                                                                           |
| **Manage access**              | Both                        | Assign specific administrative permissions for Exams to other groups.                                                   |
| **Export question statistics** | Both                        | Export question-level performance statistics for Exams.                                                                 |

**Markers and proctoring**

| Permission                  | Scope                       | What it allows                                                       |
| --------------------------- | --------------------------- | -------------------------------------------------------------------- |
| **Manage markers**          | Global or specific variants | Manage the Marker groups used across Exams or for one selected Exam. |
| **Assign markers**          | Specific                    | Assign Markers to attempts for one Exam.                             |
| **View proctoring**         | Both                        | View Synoptic proctoring footage and evidence.                       |
| **Review proctoring**       | Both                        | Review and comment on Synoptic proctoring footage and evidence.      |
| **Edit attempt proctoring** | Both                        | Change the proctoring state recorded against attempts.               |

**Exam attempts, marking and results**

| Permission             | Scope | What it allows                                                        |
| ---------------------- | ----- | --------------------------------------------------------------------- |
| **Generate attempt**   | Both  | Generate an Exam attempt for a user.                                  |
| **Issue voucher**      | Both  | Issue an Exam voucher where voucher access is used.                   |
| **Edit lock**          | Both  | Change whether an attempt is locked.                                  |
| **Close**              | Both  | Close an attempt before the candidate submits it normally.            |
| **Edit timer**         | Both  | Adjust the time available on an attempt.                              |
| **Mark**               | Both  | Mark Exam attempts.                                                   |
| **Mark provisionally** | Both  | Record provisional marks without completing the final marking stage.  |
| **View marks**         | Both  | View marks for Exam attempts.                                         |
| **Override marking**   | Both  | Override calculated or previously recorded attempt results.           |
| **Finalise**           | Both  | Finalise marks for Exam attempts.                                     |
| **Release**            | Both  | Release attempt results to candidates according to the Exam workflow. |
| **Revoke**             | Both  | Revoke an Exam attempt.                                               |
| **Export attempts**    | Both  | Export Exam attempt data.                                             |
| **Edit attributes**    | Both  | Change attributes stored against Exam attempts.                       |
| **Edit configuration** | Both  | Change an individual attempt's configuration.                         |

{% hint style="warning" %}
Treat **Override marking**, **Finalise**, **Release**, **Revoke**, **Edit timer**, **Close** and **Edit configuration** as sensitive operational permissions. Test the intended Exam workflow with the exact role that will use it.
{% endhint %}

#### User Groups and learning records

These permissions control staff access to User Groups. They do not make learning content available to Students.

| Permission                  | Scope    | What it allows                                                                    |
| --------------------------- | -------- | --------------------------------------------------------------------------------- |
| **Create User Group**       | Global   | Create new User Groups.                                                           |
| **View User Groups**        | Both     | Find and open User Groups.                                                        |
| **View users**              | Specific | View the users within selected User Groups.                                       |
| **Create users**            | Specific | Create or generate users within selected User Groups.                             |
| **Edit users**              | Specific | Edit users who belong to selected User Groups.                                    |
| **Add or remove users**     | Both     | Add existing users to, or remove them from, User Groups.                          |
| **Invite**                  | Both     | Invite new users to User Groups.                                                  |
| **Message**                 | Both     | Send messages to users in User Groups.                                            |
| **View content**            | Specific | View Exams, Collections and Assignments assigned to selected User Groups.         |
| **Export users**            | Both     | Export users from User Groups.                                                    |
| **Edit User Group**         | Both     | Change User Group details and settings.                                           |
| **Delete User Group**       | Both     | Delete User Groups.                                                               |
| **Manage access**           | Both     | Assign specific administrative permissions for User Groups to other staff groups. |
| **Create learning records** | Both     | Add learning records for users in User Groups.                                    |
| **View learning records**   | Both     | View learning records for users in User Groups.                                   |
| **Edit learning records**   | Both     | Change learning records for users in User Groups.                                 |
| **Delete learning records** | Both     | Delete learning records for users in User Groups.                                 |

#### Individual users

These permissions apply across individual user profiles. When a role only needs to work with the members of particular groups, prefer the more narrowly scoped User Group permissions above.

| Permission        | Scope  | What it allows                                                                                                     |
| ----------------- | ------ | ------------------------------------------------------------------------------------------------------------------ |
| **Create**        | Global | Create or generate user accounts.                                                                                  |
| **View**          | Global | View individual user profiles.                                                                                     |
| **View attempts** | Global | View attempts from an individual user's profile. Access to a particular Exam may still depend on Exam permissions. |
| **Edit**          | Global | Change individual user details.                                                                                    |
| **Message**       | Global | Send messages to individual users.                                                                                 |
| **Delete**        | Global | Delete individual user accounts.                                                                                   |

### Common mistakes

#### Giving View but not the related action

**View** usually makes a resource visible in administration pages. It does not automatically allow editing, exporting, marking, publishing or releasing results. Grant each required action deliberately.

#### Trying to remove a global permission locally

Specific permissions are additive. If a person receives a global permission through any group, the resource's Access page cannot make an exception for that person. Move the global permission to a narrower group or replace it with specific permissions.

#### Confusing Manage access with student access

**Manage access** usually means managing which staff groups have administrative permissions. Student availability is normally controlled elsewhere. Collections additionally have a separate **Grant or revoke access** permission for controlling their Student audience.

#### Building an organisational boundary from permissions

Permissions are suitable for teams within one organisation that share a portal. Use Subportals when separate organisations need their own administrators, users, content or operational boundary.

#### Testing only with an Administrator account

Administrators bypass the restrictions you are trying to test. Always use representative Educator and Marker accounts, including an account with multiple group memberships.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://synap.ac/docs/platform/advanced-features/access-and-permissions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
