Arythmatic
Workspace & Account Setup

Roles and Permissions

The three built-in Arythmatic roles — Admin, Instructor, and Learner — plus the Manager and Content Creator permission presets, custom roles, and the school-scoped Group Admin capability.

Roles and Permissions

Arythmatic uses roles to control what users can see and do. Roles apply at the workspace level and are enforced by the backend — the manage dashboard hides menu items based on role, but the API independently verifies permissions on every request.

Every workspace is seeded with three built-in roles: Admin, Instructor, and Learner. Two more roles — Manager and Content Creator — are available as ready-made permission presets you can apply when you create a role. You can also create your own custom roles with a tailored permission set. Separately, a user can be given a school-scoped Group Admin capability, which is described at the end of this page — it is not one of the roles you pick from the Roles field.

Role Management page listing the built-in roles plus custom roles
Role Management — the built-in (protected) roles plus any custom roles you create for your workspace

A single user can hold more than one role. When a user has multiple roles, the manage dashboard shows a Role Switcher in the header so they can change their active context without logging out.


The Built-in Roles

Admin

The Admin role has full access to the workspace. Admins can configure all settings, manage all users and roles, create and publish all content, and access all analytics, payments, and billing information.

Assign the Admin role to:

  • Workspace owners and L&D managers
  • Operations staff who manage the platform day-to-day
  • Anyone who needs to configure workspace-level settings, billing, or branding

Some workspaces are also seeded with elevated Owner and System Admin roles. The backend treats Owner as Admin-equivalent across content, library, and enrollment actions, so an Owner has the same full workspace control as an Admin. Both Owner and System Admin are protected roles that can never be deleted — they join the always-locked built-in Admin, Instructor, and Learner roles on the Roles page.

Manager

The Manager role is a broad operational role just below Admin. It is a permission preset rather than a seeded, protected built-in — apply it when you create a role. Managers can manage users, courses, content, enrollments, batches, groups, and categories, and can view payments and analytics — but they do not get destructive or workspace-configuration powers. Managers cannot delete users or courses, manage roles beyond assigning them, refund payments, or change tenant settings, branding, security, or billing.

Assign the Manager role to:

  • Program managers who run day-to-day operations across teams
  • Staff who onboard users and manage enrollments at scale
  • Leads who need broad content and enrollment control without settings or billing access

Instructor

The Instructor role is for course facilitators. Instructors can create and edit their own courses, build assessments, manage their own batches, upload content, and view analytics for their courses. They work on the courses and content they own — they cannot edit other instructors' courses, manage users or roles, or access payments, billing, or workspace settings.

Assign the Instructor role to:

  • Subject-matter experts who build and maintain their own course content
  • Facilitators who run live sessions or batch cohorts
  • Staff who manage learner progress and completions for their own courses

Content Creator

The Content Creator role is a focused authoring role, offered as a permission preset rather than a seeded, protected built-in. Content Creators can create and edit their own courses and content, upload media, and manage sections — but they cannot publish courses, manage enrollments, run batches, or access analytics, payments, or settings. Use it when you want someone to build material that an Admin, Manager, or Instructor then reviews and publishes.

Assign the Content Creator role to:

  • Instructional designers and writers who produce course material
  • Contractors who author content that someone else publishes

Learner

The Learner role is for end users who consume content. Learners access the learner portal (not the manage dashboard), can enroll in courses, complete assessments, earn badges and certificates, leave reviews, and track their own progress. They have no administrative access.

Assign the Learner role to:

  • Employees, customers, or students who take courses
  • Anyone who should only consume content, not manage it

Permissions Reference

The table below shows which actions each built-in role can perform. "Yes" means access; "Own" means the role can only act on resources they created or are assigned to; "—" means no access. Permissions are defined per role in the platform's RBAC configuration and enforced by the backend.

Workspace and Settings

ActionAdminManagerInstructorContent CreatorLearner
View workspace settingsYes
Edit workspace settingsYes
Manage branding and themesYes
View audit logYes
Manage billing and subscriptionYes
Manage integrationsYes
Edit own profileYesYesYesYesYes

Users and Roles

ActionAdminManagerInstructorContent CreatorLearner
Invite and create usersYesYes
Edit usersYesYes
Delete usersYes
Create, edit, and delete rolesYes
Assign roles to usersYesYes
View usersYesYes

Courses and Content

ActionAdminManagerInstructorContent CreatorLearner
Create coursesYesYesYesYes
Edit any courseYesYes
Edit own coursesYesYesYesYes
Delete coursesYesOwn
Publish coursesYesYesYes
Manage course categoriesYesYes (create/edit)ViewView
Build learning pathsYesYesOwn
Upload media / manage contentYesYesOwnOwn
Create and edit assessmentsYesYesYesOwn

Enrollments and Batches

ActionAdminManagerInstructorContent CreatorLearner
Enroll learnersYesYes
Bulk enroll via CSVYesYes
View enrollmentsYesYesOwnOwn
Create and manage batchesYesYesOwn
Manage groupsYesYes

The "—" for Instructor on Manage groups means they cannot create or change groups. Instructors do, however, get read-only visibility of the full group list; learners see only their own groups (through the learner portal's My Groups / My Courses views). Only Admins can add, edit, or delete groups.

Payments and Analytics

ActionAdminManagerInstructorContent CreatorLearner
View payments and transactionsYesYesOwn
Refund paymentsYes
Manage couponsYesCreate / edit
Manage memberships and promotionsYes
View workspace-wide analyticsYesYes
View own course analyticsYesYesOwn
Export analyticsYesYes

Assigning and Changing Roles

Roles are set per user from the Users section of the manage dashboard.

To assign a role:

  1. Go to Users in the left sidebar.
  2. Find the user and click their name or the Edit icon.
  3. In the Roles field, select the role or roles to assign. Both built-in and custom roles appear here.
  4. Click Save.

To remove a role, follow the same steps and deselect the role. If you remove all roles from a user, they lose access to the manage dashboard entirely. Learners who lose their Learner role lose access to the learner portal.

A user can hold both Admin and Instructor roles. This is useful for an L&D manager who also authors content — they can switch between admin context and instructor context using the Role Switcher in the header.


Custom Roles

If the built-in roles do not match how your organization is structured, you can create your own custom roles from the Roles page in the manage dashboard.

  1. Go to Roles in the left sidebar.
  2. Click Create Role.
  3. Give the role a name and description.
  4. Select the permissions the role should grant.
  5. Save.

The custom role then appears in the Roles field wherever you assign roles to users. Custom roles can be edited or deleted at any time. The three seeded built-in roles — Admin, Instructor, and Learner — are protected: they are marked with a lock icon on the Roles page and cannot be edited or deleted. Manager and Content Creator are permission presets rather than protected built-ins, so they are not locked.


The Group Admin Capability

Group Admin is not a role you assign from the Roles field. It is a school-scoped capability that appears when a user is designated as the administrator of a group (a School-Aggregator feature). When the backend marks a user as a group administrator, the manage dashboard treats them as a Group Admin — surfacing a My School area and school-scoped navigation — even though "Group Admin" never appears in the list of assignable roles.

A Group Admin manages their own school or group: they can add and remove learners in their group, view courses assigned to their group, and view analytics scoped to their group. They cannot access workspace-wide settings, billing, roles, or content outside their group. A user is made a Group Admin by being assigned as the admin of a group, not by picking a role — see Users & Groups for how schools, groups, and group administration work.

A Group Admin's write access is deliberately narrow: they may manage their group's members (add, remove, bulk-CSV import) and create or cancel non-admin invites. Assigning or removing courses to the group, bulk-assigning courses, promoting or demoting other group admins, and viewing group statistics are all reserved to tenant admins — a Group Admin who attempts them is denied by the API.


Role Switching

Users with multiple roles see a Role Switcher in the manage dashboard header. Switching roles changes the active context — the sidebar menu, accessible routes, and some UI labels update to reflect the active role. The switch is instant and does not require logging out.

If you notice the dashboard looks different from what you expect, check the Role Switcher to confirm which role is active.


Arythmatic