Before You Start
Only Super Admins can configure Roles & Permissions
Access permissions under Settings → Platform Settings → Roles & Permissions
Overview
Lumofy uses a role-based access model. Every user is assigned at least one role, and each role defines what that user can see and do in the platform. The Super Admin controls which permissions are active for each role, and those assignments apply immediately across the entire organisation.
There are four built-in roles: Super Admin, Admin, Manager, and Talent. Custom roles can also be created if the built-in roles do not fit your needs.
The Four Built-in Roles
Super Admin
The Super Admin has complete, unrestricted access to every area of Lumofy including all modules, all settings, and all user data. Super Admin permissions cannot be removed or scoped.
The Super Admin is responsible for:
Assigning and adjusting permissions for every other role
Managing platform-wide configuration and settings
Creating, editing, and removing any user account
💡 Tip: Assign Super Admin only to users who need complete ownership of the platform. It cannot be limited to specific modules or actions.
Admin
The Admin role is the operational management role. Admins can perform whatever actions their permissions allow — nothing more. By default, Admins have broad platform access, but the Super Admin can tighten or expand this at any time.
Typical Admin responsibilities include:
Configuring and running performance cycles
Building and managing competency frameworks
Creating learning content and pathways
Managing Talents and their assignments
📝 Note: A user can hold both the Admin and Manager roles simultaneously. This is useful when someone manages a direct team and also needs platform configuration access.
Manager
The Manager role is activated when a user has direct reports. Managers can only see and act on data for their own team — they have no visibility into other Talents.
Manager access covers:
Viewing and contributing to direct reports' Performance Sheets
Conducting Check-Ins on team goals
Submitting approvals for their direct reports
Managers do not have access to Develop or Engage areas by default. To give a Manager broader access, also assign them the Admin role.
Talent
Talent is the end-user role. Talents cannot configure anything — their access is focused on their own development and performance.
Talents can:
Access assigned learning content in the Develop area
View and complete their Performance Sheet during active cycles
Set and track Smart Goals
Acknowledge performance results and submit Appeals if allowed
View the Leaderboard and XP scores
How Permissions Work
Permissions are grouped by feature area. Each group contains one or more permission types such as Can Create, Can Edit, or Can Manage. For each permission type, the Super Admin selects which roles are allowed.
Super Admin is always included in every permission and cannot be removed.
Permission groups:
Group | Permission Types |
Competencies | Can Create, Can Edit |
Performance Management | Can Manage |
Content Creation | Can Create, Can Edit |
💡 Tip: Permission changes take effect immediately. A role that loses a permission loses access to that feature instantly, with no restart or re-login needed.
Configuring Permissions
Go to Settings from your user menu (bottom left)
Click the Platform Settings tab
Select Roles & Permissions from the left menu
Find the permission group you want to configure
Expand the group to see the permission types inside
Click the dropdown next to a permission type
Add or remove roles by selecting them from the dropdown or clicking the × on an existing role tag
Changes save automatically
⚠️ Warning: Removing a role from a permission removes access immediately for every user with that role. Review the impact before making changes.
Creating a Custom Role
If the four built-in roles do not meet your needs, you can create a custom role.
Go to Settings → Platform Settings → Roles & Permissions
Click + Create New Role
Name the role
Assign it to the relevant permission groups using the same process as above
Assign the custom role to users via their profile
📝 Note: Custom roles follow the same permission structure as built-in roles. They appear alongside Admin and Talent in the permission group dropdowns.
User Permission vs. Role
It is important to understand the distinction between two fields in Lumofy:
Field | What it means |
Role (on the Talent profile) | The talent's job title or position in the organisation (e.g. Marketing Specialist) |
User Permission (on the Talent profile) | The platform access level — Admin or Talent |
A user's job Role does not affect what they can do in the platform. Their User Permission (and any additional platform roles like Manager) determines their access.
FAQs
Can a user have more than one role?
Can a user have more than one role?
Yes. A user can hold Admin and Manager simultaneously. This lets them manage their direct team while also having platform configuration access.
Can I restrict an Admin to specific modules only?
Can I restrict an Admin to specific modules only?
Yes. Remove the permissions for modules you want to restrict. The Admin will lose access to those areas immediately.
What happens if I accidentally remove a critical permission?
What happens if I accidentally remove a critical permission?
Re-add the role to the permission dropdown. The change takes effect instantly.
Can a Talent access admin features if I give them Admin permission?
Can a Talent access admin features if I give them Admin permission?
Yes. Changing a user's User Permission to Admin gives them access to everything the Admin role allows, based on your current permission configuration.

