Skip to content

Popular

↑ ↓ to move · Enter to open Browse all modules
intermediate ⏱️ 13 min read

User Management & Role-Based Access Control

Manage platform users, send invitations, and configure roles and the permissions matrix (RBAC) across skillSYMS tenants.

For: Administrators
On this page(12 sections)

Summary

This guide explains how platform administrators manage users and access control on skillSYMS. You’ll learn how to invite and manage users, control sessions and account security, and configure roles and capabilities using the role-based access control (RBAC) matrix.

Who This Guide Is For

  • Platform administrators managing user accounts across tenants
  • Security administrators defining roles and permissions
  • Support staff resolving login and access issues

Prerequisites

Before you begin, ensure you have:

  • Platform administrator credentials with user and security permissions
  • The email addresses and intended roles of users to invite
  • A clear understanding of which capabilities each role should hold

Step 1: Review the User Directory

Navigate to Admin → Users.

This screen lists all platform users with search and filtering. For each user you can open a detail view to inspect their roles, sessions, and account status.

Tip: Use the search and role filters to quickly locate a user reported in a support ticket.

Step 2: Invite a New User

Navigate to Admin → Users → Invite.

Complete the invitation form:

  1. Email address of the new user
  2. Tenant the user belongs to (or Platform for staff)
  3. Role(s) to grant on acceptance

The user receives an email invitation to set their password and activate their account.

Tip: You can send login reminders in bulk from the Users screen for invited users who haven’t yet activated.

Step 3: Manage an Existing User

From Admin → Users, open a user to reach their detail page. From here you can:

  • Edit profile details
  • Suspend / Unsuspend the account
  • Unlock an account locked by failed logins
  • Reset password and trigger a new credential
  • Delete the user

Step 4: Assign Roles to a User

On the user detail page, open the Roles section.

  1. Review the user’s current roles
  2. Add or remove roles as needed
  3. Save to apply

Roles determine which capabilities the user has across the platform. Changes apply on the user’s next request.

Step 5: Manage Active Sessions

On the user detail page, open the Sessions section to see active sign-ins.

  • Revoke an individual session to sign the user out of one device
  • Revoke all sessions to force a full re-authentication

Use this when a user reports a lost device or suspected account compromise.

Step 6: Configure Roles & the Permissions Matrix

Navigate to Admin → Security → Roles.

This is the RBAC control centre. From the roles list you can:

  • Create a new role
  • Open a role to edit its capability grants
  • Grant or revoke individual capabilities
  • Remove capability overrides

Open a role detail page to see the full capability matrix and toggle each permission the role should hold.

Tip: Start from the principle of least privilege — grant only the capabilities a role genuinely needs, then add more if users hit access limits.

Common Mistakes to Avoid

  1. Over-granting roles: Assigning broad roles “to be safe” weakens your audit posture
  2. Editing the wrong tenant’s user: Confirm the tenant column before changing roles
  3. Deleting instead of suspending: Suspend preserves the audit trail; deletion does not
  4. Forgetting to revoke sessions: Resetting a password does not automatically end existing sessions — revoke them for compromised accounts

Verification Checklist

Before finishing, verify:

  • Invited users received and accepted their invitations
  • Each user holds the correct role(s)
  • The permissions matrix reflects least-privilege intent
  • No orphaned active sessions remain for offboarded users
  • Locked or compromised accounts have been resolved

Next Steps

What's new in skillSYMS

  1. MicroQuests in the browser, in the app and by email
    • skillsyms.com/learn: take LearnChat MicroQuests in any browser with buttons instead of chat replies. You get the same quests, wallet, progress and certificates as on WhatsApp
    • Learn by email: anyone can ask for a personal learning link on skillsyms.com/learn. There's no account and no password, and the link keeps you signed in on that device for 30 days
    + 6 more
  2. Schools & Early Learning (alpha): grades, registers, marks, promotion and SA-SAMS import
    • Learners → Schools & ECD: set up a school or ECD centre under its provincial department, with grades, classes and subjects for each academic year
    • Choose your institution type (primary, secondary, combined, independent, ECD centre and more) to switch on the matching pack
    + 12 more
  3. Schools & Early Learning: learner support, behaviour, governance, ECD development and a guardian portal
    • My classes: a teacher's registers still to take today, open assessment tasks and which learners need accommodations
    • Teaching assignments and teaching scope: start by observing captures outside a teacher's classes, then limit teachers to their own classes and subjects
    + 10 more
Full changelog