Permissions
Who can do what on Aladia, the role names used everywhere, how roles are inherited and what people without the permission see.
Tested on 28/09/2026 · version 5d7d821a1e
On Aladia every piece of data has an owner and every action needs a permission. These guides explain, area by area, what the Owner and the Admins of a workspace can do, what people who teach and people who study can do, and what someone without the permission sees: a message on the page, or an error from the server (403 when the resource exists but is not yours, 404 when, for you, it does not exist).
One rule applies everywhere: belonging to the same workspace does not give access to other people's personal data. Attendance and grades are for whoever manages the course, availability for whoever shares a calendar, payments for whoever pays and whoever gets paid.
The same names on every resource
Since 28/09/2026 every resource uses the same levels. Each level includes everything the level below can do, and adds something.
| Where | Levels, from highest to lowest | Also |
|---|---|---|
| Workspace (academy) | Owner ⊃ Admin ⊃ Member ⊃ Viewer | Student: whoever follows a course of the workspace. Add-on roles Billing, Developer, Social |
| Space, calendar | Manager ⊃ Editor ⊃ Member ⊃ Viewer | |
| Course | Manager ⊃ Teacher ⊃ Editor ⊃ Viewer | Student ⊃ Viewer: the member of the course who attends it |
| Live event | Manager ⊃ Editor ⊃ Member | host, co-host and guest of the live room follow from these |
| Subject area, book library, exam collection | Manager ⊃ Editor ⊃ Viewer | |
| Subject, level | Teacher | |
| Document | Owner (who created it) and Viewer |
What each level means, on any resource:
- Manager: runs the resource and its members, deletes it, invites everyone except other Managers;
- Editor: changes the content and invites the levels below their own;
- Member: takes part (a calendar's events, a space's courses);
- Viewer: reads, changes nothing;
- on a course, the Teacher is an Editor who also grades, takes attendance, co-hosts live lessons and issues certificates; the Student hands in assignments and sees their own grades and attendance.
"Owner" is never a role you give: a resource created in the workspace belongs to the workspace, one created in your personal context belongs to you. Ownership is transferred, not assigned.
The workspace Admin is Manager everywhere
The Admin of a workspace can do everything in it: it inherits the Manager role on every space, course, calendar, event, subject area, library and exam collection of the workspace, without being added to each one, and it can appoint the Managers of the courses. The Owner has everything the Admin has, plus creating and deleting the workspace.
flowchart TD
O[Workspace Owner] --> A[Workspace Admin]
A --> WM[Workspace Member] --> WV[Workspace Viewer]
A --> F[Billing · Developer · Social]
A --> SM[Space Manager]
A --> CM[Course Manager]
A --> KM[Calendar Manager]
A --> EM[Event Manager]
A --> XM[Area · Library · Exam collection Manager]
SM --> CM
CM --> CT[Course Teacher] --> CE[Course Editor] --> CV[Course Viewer]
CS[Course Student] --> CV
SM --> SE[Space Editor] --> SMe[Space Member] --> SV[Space Viewer]
SE --> CE
KM --> KE[Calendar Editor] --> KMe[Calendar Member] --> KV[Calendar Viewer]
An arrow goes from a role to a role it includes. The Manager of a space is also Manager of the courses in that space, and the Editor of a space is Editor of its courses.
What stays out of reach of the Admin is what is personal: direct messages, documents, whiteboards and calendars created in someone's personal context, their profile. The context where something is created decides, not the type of content.
The invitation rule
You invite only below your own level, and an invitation is checked role by role: if even one of the invited roles is not yours to give, the whole invitation is refused (403), nobody is invited.
| Who invites | On a course they can invite |
|---|---|
| Owner, Admin of the workspace | every role, Manager included |
| Course Manager | Teacher, Editor, Student, Viewer |
| Course Teacher, Course Editor | Student only |
| Student, Viewer | nobody |
So a Teacher who invites a Student and a Manager together gets a 403 and neither invitation leaves. Spaces, calendars, events, areas, libraries and exam collections follow the same rule: the Manager invites up to Editor, the Editor invites Members and Viewers. The Owner role is never invited. Details in Invitations and activity log.
Coming from the previous version
Roles were renamed on 28/09/2026 and people kept what they had, under the new name:
- Observer of a course is now the Manager of the course; Attendant is now Student.
- Supervisor of a space is now Manager of the space; the space owner is a Manager too.
- Coordinator of a space is now Editor of the space. It no longer has Manager powers on the courses of the space created from now on: on those it is Editor.
- Organizer of a calendar is now Manager, Scheduler is Editor, Participant is Member.
- Host, co-host and guest of an event are now Manager, Editor and Member of the event; in the live room they still appear as host, co-host and guest.
- Curator of a subject area, a library or an exam collection is now Manager.
- Creator of a document is now its Owner.
- In the workspace, External member is now Student, Billing manager is Billing, Social manager is Social. The Viewer of the workspace is new.
Invitation links copied before 28/09/2026 carry the old names and no longer work: copy a new link. Email invitations already sent keep working.
Guides
- Roles and custom roles
- Invitations and activity log
- Student data and the Students table
- What a student sees in the academy
- Add people to a course
- API keys and webhooks by context
- Payments: who gets paid and who buys
- Calendars: free/busy and other people's events
- Instant live rooms: who can join
- Social and chat: authorship, send as the academy, direct messages