Skip to main content

Roles & Access Control

Understand how roles and permissions work in Lumofy and how to control access across every module.

Written by Mohamed Shantory

Before You Start

  • Only Super Admins can configure Roles & Permissions

  • Access permissions under Settings → Platform Settings → Roles & Permissions


Overview

Lumofy uses a role-based access model. Every user is assigned at least one role, and each role defines what that user can see and do in the platform. The Super Admin controls which permissions are active for each role, and those assignments apply immediately across the entire organisation.

There are four built-in roles: Super Admin, Admin, Manager, and Talent. Custom roles can also be created if the built-in roles do not fit your needs.


The Four Built-in Roles

Super Admin

The Super Admin has complete, unrestricted access to every area of Lumofy including all modules, all settings, and all user data. Super Admin permissions cannot be removed or scoped.

The Super Admin is responsible for:

  • Assigning and adjusting permissions for every other role

  • Managing platform-wide configuration and settings

  • Creating, editing, and removing any user account

💡 Tip: Assign Super Admin only to users who need complete ownership of the platform. It cannot be limited to specific modules or actions.


Admin

The Admin role is the operational management role. Admins can perform whatever actions their permissions allow — nothing more. By default, Admins have broad platform access, but the Super Admin can tighten or expand this at any time.

Typical Admin responsibilities include:

  • Configuring and running performance cycles

  • Building and managing competency frameworks

  • Creating learning content and pathways

  • Managing Talents and their assignments

📝 Note: A user can hold both the Admin and Manager roles simultaneously. This is useful when someone manages a direct team and also needs platform configuration access.


Manager

The Manager role is activated when a user has direct reports. Managers can only see and act on data for their own team — they have no visibility into other Talents.

Manager access covers:

  • Viewing and contributing to direct reports' Performance Sheets

  • Conducting Check-Ins on team goals

  • Submitting approvals for their direct reports

Managers do not have access to Develop or Engage areas by default. To give a Manager broader access, also assign them the Admin role.


Talent

Talent is the end-user role. Talents cannot configure anything — their access is focused on their own development and performance.

Talents can:

  • Access assigned learning content in the Develop area

  • View and complete their Performance Sheet during active cycles

  • Set and track Smart Goals

  • Acknowledge performance results and submit Appeals if allowed

  • View the Leaderboard and XP scores


How Permissions Work

Permissions are grouped by feature area. Each group contains one or more permission types such as Can Create, Can Edit, or Can Manage. For each permission type, the Super Admin selects which roles are allowed.

Super Admin is always included in every permission and cannot be removed.

Permission groups:

Group

Permission Types

Competencies

Can Create, Can Edit

Performance Management

Can Manage

Content Creation

Can Create, Can Edit

💡 Tip: Permission changes take effect immediately. A role that loses a permission loses access to that feature instantly, with no restart or re-login needed.


Configuring Permissions

  1. Go to Settings from your user menu (bottom left)

  2. Click the Platform Settings tab

  3. Select Roles & Permissions from the left menu

  4. Find the permission group you want to configure

  5. Expand the group to see the permission types inside

  6. Click the dropdown next to a permission type

  7. Add or remove roles by selecting them from the dropdown or clicking the × on an existing role tag

  8. Changes save automatically

⚠️ Warning: Removing a role from a permission removes access immediately for every user with that role. Review the impact before making changes.


Creating a Custom Role

If the four built-in roles do not meet your needs, you can create a custom role.

  1. Go to Settings → Platform Settings → Roles & Permissions

  2. Click + Create New Role

  3. Name the role

  4. Assign it to the relevant permission groups using the same process as above

  5. Assign the custom role to users via their profile

📝 Note: Custom roles follow the same permission structure as built-in roles. They appear alongside Admin and Talent in the permission group dropdowns.


User Permission vs. Role

It is important to understand the distinction between two fields in Lumofy:

Field

What it means

Role (on the Talent profile)

The talent's job title or position in the organisation (e.g. Marketing Specialist)

User Permission (on the Talent profile)

The platform access level — Admin or Talent

A user's job Role does not affect what they can do in the platform. Their User Permission (and any additional platform roles like Manager) determines their access.


FAQs

Can a user have more than one role?

Yes. A user can hold Admin and Manager simultaneously. This lets them manage their direct team while also having platform configuration access.

Can I restrict an Admin to specific modules only?

Yes. Remove the permissions for modules you want to restrict. The Admin will lose access to those areas immediately.

What happens if I accidentally remove a critical permission?

Re-add the role to the permission dropdown. The change takes effect instantly.

Can a Talent access admin features if I give them Admin permission?

Yes. Changing a user's User Permission to Admin gives them access to everything the Admin role allows, based on your current permission configuration.

Did this answer your question?