diff --git a/source/_images/educator_how_tos/assign_role_button.png b/source/_images/educator_how_tos/assign_role_button.png new file mode 100644 index 000000000..333a5d44b Binary files /dev/null and b/source/_images/educator_how_tos/assign_role_button.png differ diff --git a/source/_images/educator_how_tos/assign_role_step1_console.png b/source/_images/educator_how_tos/assign_role_step1_console.png new file mode 100644 index 000000000..0e36cf75e Binary files /dev/null and b/source/_images/educator_how_tos/assign_role_step1_console.png differ diff --git a/source/_images/educator_how_tos/assign_role_step1_manage_roles.png b/source/_images/educator_how_tos/assign_role_step1_manage_roles.png new file mode 100644 index 000000000..0ded0b8be Binary files /dev/null and b/source/_images/educator_how_tos/assign_role_step1_manage_roles.png differ diff --git a/source/_images/educator_how_tos/assign_role_step2_console.png b/source/_images/educator_how_tos/assign_role_step2_console.png new file mode 100644 index 000000000..ec0091574 Binary files /dev/null and b/source/_images/educator_how_tos/assign_role_step2_console.png differ diff --git a/source/_images/educator_how_tos/assign_role_step2_manage_roles.png b/source/_images/educator_how_tos/assign_role_step2_manage_roles.png new file mode 100644 index 000000000..443b2b182 Binary files /dev/null and b/source/_images/educator_how_tos/assign_role_step2_manage_roles.png differ diff --git a/source/_images/educator_how_tos/console_course_team_members.png b/source/_images/educator_how_tos/console_course_team_members.png new file mode 100644 index 000000000..991f27245 Binary files /dev/null and b/source/_images/educator_how_tos/console_course_team_members.png differ diff --git a/source/_images/educator_how_tos/course_settings_roles_and_perms.png b/source/_images/educator_how_tos/course_settings_roles_and_perms.png new file mode 100644 index 000000000..531e91a24 Binary files /dev/null and b/source/_images/educator_how_tos/course_settings_roles_and_perms.png differ diff --git a/source/_images/educator_how_tos/library_team_roles_assign copy.png b/source/_images/educator_how_tos/library_team_roles_assign copy.png new file mode 100644 index 000000000..0e36cf75e Binary files /dev/null and b/source/_images/educator_how_tos/library_team_roles_assign copy.png differ diff --git a/source/_images/educator_how_tos/library_team_roles_assign_save copy.png b/source/_images/educator_how_tos/library_team_roles_assign_save copy.png new file mode 100644 index 000000000..ec0091574 Binary files /dev/null and b/source/_images/educator_how_tos/library_team_roles_assign_save copy.png differ diff --git a/source/_images/educator_how_tos/library_team_roles_delete copy.png b/source/_images/educator_how_tos/library_team_roles_delete copy.png new file mode 100644 index 000000000..1fdf42007 Binary files /dev/null and b/source/_images/educator_how_tos/library_team_roles_delete copy.png differ diff --git a/source/_images/educator_how_tos/library_team_roles_edit_user_screen copy.png b/source/_images/educator_how_tos/library_team_roles_edit_user_screen copy.png new file mode 100644 index 000000000..543490299 Binary files /dev/null and b/source/_images/educator_how_tos/library_team_roles_edit_user_screen copy.png differ diff --git a/source/_images/educator_how_tos/remove_role_icon.png b/source/_images/educator_how_tos/remove_role_icon.png new file mode 100644 index 000000000..1fdf42007 Binary files /dev/null and b/source/_images/educator_how_tos/remove_role_icon.png differ diff --git a/source/_images/educator_how_tos/roles_and_permissions_tab.png b/source/_images/educator_how_tos/roles_and_permissions_tab.png new file mode 100644 index 000000000..97c2a4250 Binary files /dev/null and b/source/_images/educator_how_tos/roles_and_permissions_tab.png differ diff --git a/source/_images/educator_how_tos/studio_home_roles_and_permissions_button.png b/source/_images/educator_how_tos/studio_home_roles_and_permissions_button.png new file mode 100644 index 000000000..a7436280f Binary files /dev/null and b/source/_images/educator_how_tos/studio_home_roles_and_permissions_button.png differ diff --git a/source/_images/educator_how_tos/team_members_action_icon.png b/source/_images/educator_how_tos/team_members_action_icon.png new file mode 100644 index 000000000..a6a6383e8 Binary files /dev/null and b/source/_images/educator_how_tos/team_members_action_icon.png differ diff --git a/source/_images/educator_how_tos/team_members_filters.png b/source/_images/educator_how_tos/team_members_filters.png new file mode 100644 index 000000000..d97b69457 Binary files /dev/null and b/source/_images/educator_how_tos/team_members_filters.png differ diff --git a/source/_images/educator_how_tos/team_members_tab.png b/source/_images/educator_how_tos/team_members_tab.png new file mode 100644 index 000000000..2b379c830 Binary files /dev/null and b/source/_images/educator_how_tos/team_members_tab.png differ diff --git a/source/_images/educator_how_tos/user_audit_view.png b/source/_images/educator_how_tos/user_audit_view.png new file mode 100644 index 000000000..543490299 Binary files /dev/null and b/source/_images/educator_how_tos/user_audit_view.png differ diff --git a/source/community/release_notes/verawood/feature_release_notes.rst b/source/community/release_notes/verawood/feature_release_notes.rst index 1e2cdab06..519667389 100644 --- a/source/community/release_notes/verawood/feature_release_notes.rst +++ b/source/community/release_notes/verawood/feature_release_notes.rst @@ -10,6 +10,8 @@ Open edX Verawood Release - Product Release Notes stay_up_to_date verawood_lti_cert + verawood_console + verawood_rp Information for site operators and developers, including information on how to enable and/or configure new features that require additional work, can be found diff --git a/source/community/release_notes/verawood/verawood_console.rst b/source/community/release_notes/verawood/verawood_console.rst new file mode 100644 index 000000000..f2de10bb4 --- /dev/null +++ b/source/community/release_notes/verawood/verawood_console.rst @@ -0,0 +1,78 @@ +.. _Verawood Roles and Permissions Console: + +Roles and Permissions Console +############################################ + + .. image:: /_images/educator_how_tos/console_course_team_members.png + :alt: The Team Members tab of the Roles and Permissions console, listing role assignments across libraries and courses + :width: 800 + +The Verawood release upgrades the Roles and Permissions console, +letting you manage user access across multiple parts of the platform +from a single view. + +You can now assign a role to one or multiple users, and apply it to +one or multiple spaces, all in a single action. Verawood also adds +organization-level assignment. Granting a role to a user at the +organization level covers not only what exists today, but everything +created in that organization afterward. + +This is the same console already used for libraries. With Verawood, +course authoring also lives here too, if enabled — see +:ref:`Verawood Course Authoring Roles`. + +.. _Verawood Console Available: + +What's Available in Verawood +***************************** + +* **Unified interface**: shows all role assignments in one place, + filterable by role, organization, and scope. + +* **Assign Role wizard**: assign a role to multiple users and multiple + scopes in a single action. + +* **Organization-level assignment**: grant a role to a user across an + entire organization, including scopes created later. + +* **User audit view**: shows a user's roles across every course and + library you have permission to manage. + +* **Filtered entry points**: the console opens filtered to the context + you came from, unfiltered from the Studio home page, or filtered to + a single course or library when opened from there. + +Not Affected by This Release +***************************** + +* Course content and how it is authored. The console changes how course + teams and library teams are managed, not what authors create. + +* :ref:`Legacy Libraries ` that have + not yet been migrated to Content Libraries. + +* LMS features outside of role assignment, such as grading, cohorts, + groups, and discussion forums. + +* Whether course authoring roles are available for a given course, + which depends on the Course Authoring waffle flag; see + :ref:`Verawood Course Authoring Roles`. + +.. seealso:: + + :ref:`Verawood Course Authoring Roles` (release notes) + + :ref:`Manage Course Authoring Roles` (how-to) + + :ref:`Add users to Libraries` (how-to) + + :ref:`Guide to Course Team Roles` (reference) + + +**Maintenance chart** + ++--------------+-------------------------------+----------------+--------------------------------+ +| Review Date | Working Group Reviewer | Release |Test situation | ++--------------+-------------------------------+----------------+--------------------------------+ +| [DATE] | [REVIEWER] | Verawood | [PASS/FAIL] | ++--------------+-------------------------------+----------------+--------------------------------+ diff --git a/source/community/release_notes/verawood/verawood_rp.rst b/source/community/release_notes/verawood/verawood_rp.rst new file mode 100644 index 000000000..e600743ab --- /dev/null +++ b/source/community/release_notes/verawood/verawood_rp.rst @@ -0,0 +1,117 @@ +.. _Verawood Course Authoring Roles: + +Course Authoring Roles and Permissions +############################################ + + .. image:: /_images/educator_how_tos/console_course_team_members.png + :alt: The Team Members tab of the Roles and Permissions console, showing course team members + :width: 800 + +With Verawood, course authoring joins the Roles and Permissions console +already used for content libraries. Course team management now also +uses the same assignment and permission patterns as libraries, +available through the same console (see +:ref:`Verawood Roles and Permissions Console`). + +Course Admin and Course Staff are the new system's equivalents of the +legacy Admin and Staff roles for a course: same responsibilities, new +assignment mechanism. + +This feature is opt-in: the Course Authoring waffle flag is disabled by +default and can be enabled per platform, organization, or course. See +`Enabling the Feature`_ below for setup instructions. + +.. _Verawood Authoring Roles Available: + +Roles +***** + +* **Course Admin** — the new-system equivalent of the legacy Admin + role: course team management through the Roles and Permissions + console and full authoring access in Studio. + +* **Course Staff** — the new-system equivalent of the legacy Staff + role: full course lifecycle management in Studio. + +For a full breakdown of what each role can do, see +:ref:`Course Authoring Roles Under the New Roles and Permissions System `. + +Scope and Impact +**************** + +While this feature is enabled, the platform supports both the legacy +Instructor Dashboard roles (Admin, Staff, Limited Staff) and the new +Course Admin / Course Staff roles at the same time. New roles apply +according to the scope where the flag is enabled — platform, +organization, or course. + +The Roles and Permissions console shows and lets you act on +course-authoring roles only for the specific courses and organizations +where the Course Authoring flag is actually enabled — not simply +because it's enabled somewhere else in your access. Turning the flag +on or off also triggers a migration of role assignments behind the +scenes: for a single course or organization this can happen +automatically, depending on your site's configuration, but a +platform-wide change always requires your site operator to run the +migration manually. Until that migration finishes, there can be a +brief window where a role assignment does not yet reflect the current +flag state. This is expected during a flag transition — if it doesn't +resolve on its own, check with your site operator. + +Enabling the Feature +********************* + +Disabled by default. Can be enabled at the platform, organization, or +course level. See the operator release notes: +https://openedx.atlassian.net/wiki/spaces/OEPM/pages/6331662350/RBAC+AuthZ+for+Course+Authoring+-+Operator+Release+Notes#Enabling-the-Feature-Flag + +Migration of Existing Course Role Assignments +********************************************** + +Verawood includes migration tools to synchronize existing Admin and +Staff course role assignments between the legacy system and Roles and +Permissions. Depending on how your site is configured, this can happen +automatically when the Course Authoring flag is turned on for a course +or organization — existing Admin and Staff assignments carry over to +the new system without manual steps. If automatic migration isn't +enabled on your site, your site operator can run the migration +separately. Either way, no role assignments are lost in the process. + +Future Improvements +******************* + +The Course Authoring waffle flag is expected to default to enabled at +the platform level in a future release (timeline not yet committed). + +After Verawood, the Roles and Permissions work is expected to continue +in several directions: + +New Studio roles are planned to separate authoring responsibilities +from managing an active course, and to introduce a read-only role for +reviewing course content in Studio without edit access. + +Roles and Permissions will also expand to the LMS, bringing the same +model to learner-facing features and runtime course management. + +Documentation with design patterns, guides, and extension points for +the community to build on top of the new system are also on the +roadmap. + +.. seealso:: + + :ref:`Verawood Roles and Permissions Console` (release notes) + + :ref:`Manage Course Authoring Roles` (how-to) + + :ref:`Guide to Course Team Roles` (reference) + + :ref:`Add Course Team Members` (how-to) + + +**Maintenance chart** + ++--------------+-------------------------------+----------------+--------------------------------+ +| Review Date | Working Group Reviewer | Release |Test situation | ++--------------+-------------------------------+----------------+--------------------------------+ +| [DATE] | [REVIEWER] | Verawood | [PASS/FAIL] | ++--------------+-------------------------------+----------------+--------------------------------+ diff --git a/source/educators/how-tos/course_development/add_users_to_libraries.rst b/source/educators/how-tos/course_development/add_users_to_libraries.rst index b79125284..80fb7c3aa 100644 --- a/source/educators/how-tos/course_development/add_users_to_libraries.rst +++ b/source/educators/how-tos/course_development/add_users_to_libraries.rst @@ -6,12 +6,12 @@ Manage Library User Access .. tags:: educator, how-to Access to a library team starts from the library home page in Studio and is -managed in the library team manager in the :ref:`Administrative Console `. This article explains the library roles and how to add and manage -members of a library team. +managed in the Roles and Permissions console. This article explains the +library roles and how to add and manage members of a library team. -Any change made in the library team manager applies to this library only. It -does not change what that user can do in other libraries or in courses. +Any change made in the Roles and Permissions console applies to this library +only. It does not change what that user can do in other libraries or in +courses. .. contents:: :local: @@ -28,195 +28,99 @@ Libraries use roles to control what each team member can do. See * Library Author * Library Admin -Library Team Management -*********************** +Access the Roles and Permissions Console +***************************************** -On the Team Management panel, there are three tabs at the top of the page: - -* Team Members -* Roles -* Permissions - -Any user who has any of the above Library Roles can view these tabs. - -Team Members Tab -================ - -On the Team Members tab, users can see who has access to the Library and which -roles they have. The list of team members is searchable by username or email, -and can be filtered by role, making it easy to understand who else can edit, -publish or manage access. - -.. image:: /_images/educator_how_tos/library_team_member_tab.png - :alt: The Team Members tab of the Admin Console, showing two team members in a table with the columns Name, Email, Role, and Actions - :width: 800 - :align: center - -Roles Tab -========= - -The :ref:`authz:Library Roles` tab has a description of each Library role and -the set of permissions each role includes, helping users understand at a glance what -each role covers when granting permissions. - -.. image:: /_images/educator_how_tos/library_team_roles_tab.png - :alt: The Roles tab shows all 4 Library roles and what permissions each role grants - :align: center - -Permissions Tab -=============== - -The Permissions tab has a :ref:`authz:Library RP Summary Table` that describes -which permissions are assigned to each role. Every permission in the table -includes a short explanation, enabling users to see what role allows which -actions, and compare roles side by side before they change a user's access. - -.. image:: /_images/educator_how_tos/library_permissions_tab.png - :alt: The Permissions tab shows a table of permissions, with a ✅ for permissions a given role allows and a ❌ for permissions not available for that role. - :align: center - - -Manage Access for Library Team Members -************************************** - -Only Library Admins and global site admins can add or remove team members or change -their roles. All actions in this section affect access to one library only. - -To begin, follow these steps to open the Team Management panel: - -#. From the home page of the library in Studio, click the :guilabel:`ⓘ Library Info` button on +#. From the home page of the library in Studio, select the :guilabel:`ⓘ Library Info` button on the top right of the page to open the right sidebar. .. image:: /_images/educator_how_tos/library_info_button.png :alt: The Library Info button appears below the header, on the top-right of the page. -#. In the right sidebar, click the :guilabel:`Manage Access` button. This opens the team - management panel in a new browser tab in the Administrative Console, on the - Team Members tab. +#. In the right sidebar, select :guilabel:`Manage Access`. This opens the Roles and + Permissions console in a new browser tab, filtered to this library's team. .. image:: /_images/educator_how_tos/library_manage_access_button.png :alt: The "Manage Access" button appears in the right sidebar, below the Published status and Organization information. :scale: 40 :align: center -View Team Members -================= - -Library administrators can audit a user's access to that library via the Team Management panel: - -#. Use search or filters to find a user to update and select Edit in the Action - column to open the user detail view. +For a full description of the console's tabs, filters, and audit view, see +:ref:`Use Roles and Permissions Console`. - .. image:: /_images/educator_how_tos/library_team_roles_edit.png - :alt: The "Edit" link appears in the rightmost column of the User table for each row that contains a user. +Find and Audit Team Members +**************************** -#. Once "Edit" has been clicked, a new screen is shown that allows admins to - view what roles a user holds and edit their access to the library. +Use search or filters to find a team member. Select the option in the +**Actions** column to open their audit view, which shows their current +role and the permissions it grants for this library. .. image:: /_images/educator_how_tos/library_team_roles_edit_user_screen.png - :alt: The screen for one single user, showing their role (Library Admin) and a table of which permissions that role grants them. + :alt: The audit view for one team member, showing their role (Library Admin) and a table of which permissions that role grants them. +Assign a Role +************** -Add a New Team Member -======================== +Only Library Admins and global site admins can assign roles. -Library administrators can add a new team member via the Team Management panel: +#. In the Roles and Permissions console, select **Assign Role**. -#. In the team management panel, click the :guilabel:`+ Add New Team Member` button in the - upper right corner to open the Add User pop-up. + This opens the Assign Role wizard. Use it both to add a new team member + and to give an existing team member an additional role. - .. image:: /_images/educator_how_tos/library_add_team_member_button.png - :alt: The Add New Team Member button appears at the top-right of the Library Team Management page - -#. In the pop-up window, enter one or more email addresses or usernames of the - people you want to grant access to, separated by commas. Select the desired - role to assign, for example Library Admin, Library Author, Library - Contributor, or Library User. +#. In **Step 1: Who and Role**, enter one or more usernames or email + addresses, separated by commas, and select the role to assign: Library + Admin, Library Author, Library Contributor, or Library User. .. image:: /_images/educator_how_tos/library_team_roles_assign.png - :alt: The pop-up modal has a text box for entering users by username or email, and a dropdown menu that shows the available roles to be assigned. - -#. Save the changes. After saving, the new user(s) are listed in the team table with their new role. - - .. image:: /_images/educator_how_tos/library_team_roles_assign_save.png - :alt: The "Save" button appears in the bottom right of the pop-up modal. - -Edit User Roles -=============== + :alt: The Assign Role wizard's first step, with a text box for entering users by username or email and a dropdown for the role to assign. -Library Admins and global site admins can update roles for users who are already -on the library team. To begin, follow these steps to open the Team Management -panel: + Users must have an existing account. If any entry does not match a user, + the input shows an error for that entry and blocks the flow until + corrected. -#. From the home page of the library in Studio, click the :guilabel:`ⓘ Library Info` button on - the top right of the page to open the right sidebar. - - .. image:: /_images/educator_how_tos/library_info_button.png - :alt: The Library Info button appears below the header, on the top-right of the page. - -#. In the right sidebar, click the :guilabel:`Manage Access` button. This opens the team - management panel in a new browser tab in the Administrative Console, on the - Team Members tab. - - .. image:: /_images/educator_how_tos/library_manage_access_button.png - :alt: The "Manage Access" button appears in the right sidebar, below the Published status and Organization information. - :scale: 40 - :align: center - -Add a Role to a Team Member ----------------------------- - -#. Navigate to the "Team Members" tab of the Team Management panel. Use search - or filters to find the user to update and select "Edit" in the Action column - to open the user detail view for the user. +#. Select **Next**. - .. image:: /_images/educator_how_tos/library_team_roles_edit.png - :alt: The "Edit" link appears in the rightmost column of the User table for each row that contains a user. +#. In **Step 2: Where It Applies**, select this library to apply the role to. -#. In the user detail view, select :guilabel:`Add New Role` in the upper right corner. +#. Select **Save**. After saving, the new role assignments appear in the team + table. - .. image:: /_images/educator_how_tos/library_team_add_new_role.png - :alt: The "Add New Role" button appears in the top right corner. - - -#. In the Add New Role pop-up, open the Roles dropdown and select the new role to add. - - .. image:: /_images/educator_how_tos/library_team_roles_new_role_popup.png - :alt: The pop-up dialog has a dropdown for selecting a role, and both a Cancel and a Save button in the bottom right. - -#. Select Save. - -The new role is added for this user in this library and appears in their list of roles. + .. image:: /_images/educator_how_tos/library_team_roles_assign_save.png + :alt: The "Save" button in the Assign Role wizard. -Remove a Role from a Team Member --------------------------------- +Remove a Role +************** -#. Navigate to the "Team Members" tab of the Team Management panel. Use search - or filters to find the user to update and select "Edit" in the Action column - to open the user detail view for the user. +Library Admins and global site admins can remove role assignments. - .. image:: /_images/educator_how_tos/library_team_roles_edit.png - :alt: The "Edit" link appears in the rightmost column of the User table for each row that contains a user. +#. In the team members list, find the user whose role you want to remove and + select the option to open their audit view. -#. In the user detail view, find the role to remove and select the delete icon for that role. +#. In the audit view, find the role to remove and select the option to + remove that role. .. image:: /_images/educator_how_tos/library_team_roles_delete.png - :alt: The delete (trash can) icon appears on the top right of each "card", where a card represents one role a user holds. + :alt: The remove-role control on a role card in the audit view. - -#. In the Remove role confirmation pop-up, review the message and select Remove - to confirm, or Cancel to retain the user's current level of access. +#. Review the confirmation message and select **Remove** to confirm, or + **Cancel** to keep the current assignment. .. image:: /_images/educator_how_tos/library_team_roles_remove_role_popup.png - :alt: The pop-up dialog, in this example, explains that removing the role for the user will also remove all their Library access as it is the only role the user has. + :alt: The confirmation dialog, explaining that removing the role also removes all library access if it is the user's only role. .. note:: - After "Remove" is selected, that role is removed for this user in this library. If the - user has no roles left for this library, they will no longer have access and - will stop appearing in the team list. Their roles in other libraries or courses - are not affected. + After a role is removed, if the user has no roles left for this library, + they will no longer have access and will stop appearing in the team list. + Their roles in other libraries or courses are not affected. +.. note:: + With Verawood, this same Roles and Permissions console can also manage + course team roles, if your site has enabled Course Authoring. See + :ref:`Manage Course Authoring Roles` for the equivalent course workflow. This + doesn't change how library access works — everything above applies the + same way whether or not Course Authoring is enabled. .. seealso:: @@ -242,6 +146,10 @@ Remove a Role from a Team Member :ref:`Add a Problem Bank to your course for randomization` + :ref:`Use Roles and Permissions Console` (how-to) + + :ref:`Manage Course Authoring Roles` (how-to) + **Maintenance chart** +--------------+-------------------------------+----------------+--------------------------------+ @@ -251,3 +159,5 @@ Remove a Role from a Team Member +--------------+-------------------------------+----------------+--------------------------------+ | 07/02/2025 | Leira (Curricu.me) | Sumac | Pass | +--------------+-------------------------------+----------------+--------------------------------+ +| [DATE] | [REVIEWER] | Verawood | [PASS/FAIL] | ++--------------+-------------------------------+----------------+--------------------------------+ diff --git a/source/educators/how-tos/course_development/create_new_library.rst b/source/educators/how-tos/course_development/create_new_library.rst index c190050e8..5ac49b6aa 100644 --- a/source/educators/how-tos/course_development/create_new_library.rst +++ b/source/educators/how-tos/course_development/create_new_library.rst @@ -9,9 +9,13 @@ Create a New Library To create a new library, follow these steps. +.. note:: To create a library, your account must have the ``course_creator`` + role, or global admin or global staff access on your platform. If you do + not have this access, contact your platform administrator. + #. Log in to Studio. -#. Select **Libraries** from the Studio home page. +#. Select **Libraries** from the Studio home page. #. Select **New Library**. @@ -24,7 +28,7 @@ To create a new library, follow these steps. - For **Library Name**, enter the public display name for your library. Choose a meaningful name that will help you and other course team members - to identify the library. For example, "Level 200 Math Problems". + to identify the library. For example, "Level 200 Math Problems". - For **Organization**, enter the identifier for your university. For example, enter HarvardX or MITx. Do not include spaces or special @@ -37,15 +41,16 @@ To create a new library, follow these steps. #. Select **Create**. You see the new library, to which you can now add components. For information -about adding components to a library, see :ref:`Build a Collection in a Library` and :ref:`Create and edit content in a Library`. +about adding components to a library, see :ref:`Build a Collection in a Library` +and :ref:`Create and edit content in a Library`. -After you create a library, you are automatically assigned an **Admin** role -for the library. For information about adding other users to a library after -you create it, see :ref:`Add users to Libraries`. +After you create a library, you are automatically assigned a **Library Admin** +role for the library. For information about adding other users to a library +after you create it, see :ref:`Add users to Libraries`. .. seealso:: - + :ref:`Navigate the Library Homepage` :ref:`Create and edit content in a Library` @@ -78,5 +83,5 @@ you create it, see :ref:`Add users to Libraries`. +--------------+-------------------------------+----------------+--------------------------------+ | Review Date | Working Group Reviewer | Release |Test situation | +--------------+-------------------------------+----------------+--------------------------------+ -| | | | | +| [DATE] | [REVIEWER] | Verawood | [PASS/FAIL] | +--------------+-------------------------------+----------------+--------------------------------+ diff --git a/source/educators/how-tos/course_development/manage_course_authoring_roles.rst b/source/educators/how-tos/course_development/manage_course_authoring_roles.rst new file mode 100644 index 000000000..7f467764a --- /dev/null +++ b/source/educators/how-tos/course_development/manage_course_authoring_roles.rst @@ -0,0 +1,153 @@ +.. _Manage Course Authoring Roles: + +Manage Course Authoring Roles +############################################################## + +.. tags:: educator, how-to + +This article covers the course authoring roles introduced in the Verawood +release. Whether these roles or the ones described in +:ref:`Add Course Team Members` apply to your course team depends on whether +Course Authoring is enabled for your site. + +.. note:: + This feature is not enabled by default. See the operator release notes: + https://openedx.atlassian.net/wiki/spaces/OEPM/pages/6331662350/RBAC+AuthZ+for+Course+Authoring+-+Operator+Release+Notes#Enabling-the-Feature-Flag + for instructions on how to enable it. For more on what's included in this + release, see :ref:`Verawood Course Authoring Roles`. + +.. contents:: + :local: + :depth: 2 + +Course Roles +************* + +Courses use roles to control what each team member can do. See +:ref:`Course Authoring Roles Under the New Roles and Permissions System ` +for more detail on the following course roles: + +* Course Admin +* Course Staff + +Access the Roles and Permissions Console +***************************************** + +The Roles and Permissions console can be opened from the Studio home page. +A filtered view, scoped to a specific course, can be accessed from the +course Settings menu. + +To open the console for a specific course: + +#. In Studio, open the **Settings** menu for your course. + +#. Select **Roles and Permissions**. The console opens in a new browser tab, + filtered to show only this course's team. + + .. image:: /_images/educator_how_tos/course_settings_roles_and_perms.png + :alt: The Settings menu in Studio, showing the Roles and Permissions option + +Find and Audit Team Members +**************************** + +Once you open the console, your course team is shown in the **Team Members** +tab. The tab lists all users with a role assignment on this course. Use the +search bar and filters to find a specific user. + +Select the option in the **Actions** column to open a user's audit view, +which lists all of their role assignments. + +For a detailed description of the console and its filters, see +:ref:`Use Roles and Permissions Console`. + +Assign a Role +************** + +Only Course Admins and global site admins can assign roles. + +#. In the Roles and Permissions console, select **Assign Role**. + + .. image:: /_images/educator_how_tos/assign_role_button.png + :alt: The Assign Role button in the Roles and Permissions console + + This opens the Assign Role wizard. + +#. In **Step 1: Who and Role**, enter one or more usernames or email addresses, + separated by commas. Select the role to assign. + + .. image:: /_images/educator_how_tos/assign_role_step1_manage_roles.png + :alt: Step 1 of the Assign Role wizard, showing a text input for users and a role selector + + Users must have an existing account. If any entry does not match a user, + the input shows an error for that entry and blocks the flow until corrected. + +#. Select **Next**. If all users are valid, the wizard moves to Step 2. + +#. In **Step 2: Where It Applies**, select one or more courses to apply the + role to. Use the search bar or Organization filter to find a specific course. + + .. image:: /_images/educator_how_tos/assign_role_step2_manage_roles.png + :alt: Step 2 of the Assign Role wizard, showing a list of courses with checkboxes + + .. note:: + The courses and organizations available here reflect where the Course + Authoring feature is actually enabled. If a role assignment doesn't + seem to take effect right away, check with your site operator — this + can happen briefly during a flag change. + +#. Select **Save**. After saving, the new role assignments appear in the Team + Members table and a confirmation message is shown. + +Remove a Role +************** + +Course Admins and global site admins can remove role assignments. + +#. In the Team Members tab, find the user whose role you want to remove and + select the option to open their audit view. + +#. In the user audit view, find the role assignment to remove and select + the option to remove the role assignment in the **Actions** column. + + .. image:: /_images/educator_how_tos/remove_role_icon.png + :alt: The remove-role control in the Actions column of the user audit view + +#. Review the confirmation message and select **Remove** to confirm, or + **Cancel** to keep the current assignment. + +.. note:: + A role assignment tied to a course where the Course Authoring flag is + disabled still appears in the Team Members table and the user audit + view. The option to remove it is unavailable, with a message explaining + why. + +.. note:: + + You cannot remove your own admin role. If you need to revoke your own + access, another user with the required permissions must do it. + + Super Admin and Global Staff roles are managed at the platform level and + cannot be removed from the Roles and Permissions console. + +.. seealso:: + + :ref:`Use Roles and Permissions Console` (how-to) + + :ref:`Guide to Course Team Roles` (reference) + + :ref:`Add Course Team Members` (how-to) + + :ref:`Add users to Libraries` (how-to) + + :ref:`Manage Course Beta Testing` (how-to) + + :ref:`Assign discussion roles ` (how-to) + + +**Maintenance chart** + ++--------------+-------------------------------+----------------+--------------------------------+ +| Review Date | Working Group Reviewer | Release |Test situation | ++--------------+-------------------------------+----------------+--------------------------------+ +| [DATE] | [REVIEWER] | Verawood | [PASS/FAIL] | ++--------------+-------------------------------+----------------+--------------------------------+ diff --git a/source/educators/how-tos/set_up_course/add_course_team_members.rst b/source/educators/how-tos/set_up_course/add_course_team_members.rst index 3fcf68aed..e4d78c6dd 100644 --- a/source/educators/how-tos/set_up_course/add_course_team_members.rst +++ b/source/educators/how-tos/set_up_course/add_course_team_members.rst @@ -84,11 +84,25 @@ To assign a privileged role to a course team member, follow these steps. To remove an assigned role, view the list of users and then select **Revoke access**. +.. note:: + For installations using the Roles and Permissions console: course team + management is available from :guilabel:`Settings` > :guilabel:`Roles and + Permissions` in Studio. See :ref:`Manage Course Authoring Roles` for the + Course Admin and Course Staff roles available there. + + The Roles and Permissions console (called the Administrative Console in + earlier releases) is not enabled by default. See the operator release + notes: + https://openedx.atlassian.net/wiki/spaces/OEPM/pages/6331662350/RBAC+AuthZ+for+Course+Authoring+-+Operator+Release+Notes#Enabling-the-Feature-Flag + for instructions on how to enable it. + .. seealso:: - + :ref:`Guide to Course Team Roles` (reference) - :ref:`Manage Course Beta Testing` (how-to) + :ref:`Manage Course Beta Testing` (how-to) + + :ref:`Manage Course Authoring Roles` (how-to) **Maintenance chart** @@ -100,3 +114,5 @@ access**. +--------------+-------------------------------+----------------+---------------------------------------------------------------+ | 03/07/2025 | Leira (Curricu.me) | Sumac | Fail (https://github.com/openedx/docs.openedx.org/issues/881) | +--------------+-------------------------------+----------------+---------------------------------------------------------------+ +| [DATE] | [REVIEWER] | Verawood | [PASS/FAIL] | ++--------------+-------------------------------+----------------+---------------------------------------------------------------+ diff --git a/source/educators/how-tos/use_roles_and_permissions_console.rst b/source/educators/how-tos/use_roles_and_permissions_console.rst new file mode 100644 index 000000000..d31602aa9 --- /dev/null +++ b/source/educators/how-tos/use_roles_and_permissions_console.rst @@ -0,0 +1,203 @@ +.. _Use Roles and Permissions Console: + +Use Roles and Permissions Console +###################################### + +.. tags:: educator, how-to + +The Roles and Permissions console is where you manage team access for courses +and libraries in Studio. This article describes the main areas of the console: +the Team Members tab, the Roles and Permissions tab, and the user audit view. + +.. note:: + This feature is not enabled by default. See the operator release notes: + https://openedx.atlassian.net/wiki/spaces/OEPM/pages/6331662350/RBAC+AuthZ+for+Course+Authoring+-+Operator+Release+Notes#Enabling-the-Feature-Flag + for instructions on how to enable it. For more on what's included in this + release, see :ref:`Verawood Course Authoring Roles`. + +.. contents:: + :local: + :depth: 2 + +Access the Console +****************** + +#. From the Studio home page, select **Roles and Permissions** in the top + right corner. This opens the Roles and Permissions console in a new + browser tab. + + .. image:: /_images/educator_how_tos/studio_home_roles_and_permissions_button.png + :alt: The Roles and Permissions button in the top right of the Studio home page + +When you open it from the Studio home page, all courses and libraries you +have access to are shown. When you open it from within a specific course or +library, the view is prefiltered to show only that course or library's team. +The console is always the same interface. + +Team Members Tab +***************** + +On the Team Members tab, you can see all users with a role assignment on the +courses and libraries you have access to. + + .. image:: /_images/educator_how_tos/team_members_tab.png + :alt: The Team Members tab showing a table with Name, Email, Organization, Scope, Role, and Actions columns + :width: 800 + :align: center + +The table has six columns: **Name**, **Email**, **Organization**, **Scope**, +**Role**, and **Actions**. Each row represents one role assignment. A user with +multiple assignments appears once per assignment. + +Your own account is identified with a "(me)" label next to your username. + +Rows for Super Admin or Global Staff users are visually highlighted. + +The table shows 10 rows per page. Use the previous and next arrows or the page +selector to navigate through results. + +.. note:: + The table only shows users with a role on the courses and libraries you + have access to. You may not see all users on your platform. + +.. note:: + For a role assignment tied to a course where the Course Authoring flag + is disabled, the option to open the audit view is unavailable, with a + message explaining why. + +Search and Filters +================== + +You can search for users and narrow the list using three filters. + + .. image:: /_images/educator_how_tos/team_members_filters.png + :alt: The search bar and filter row above the team members table + +* The **search bar** filters by user name and email. + +* The **Organization** filter shows a list of organizations. You can search + within the filter to find a specific organization. Select one or more to + narrow results. + +* The **Role** filter lists all available roles, grouped by global, course, and + library. Select one or more roles to narrow results. + +* The **Scope** filter shows a list of courses and libraries. You can search + within the filter to find a specific course or library. Select one or more + to narrow results. + +Active filters show a count badge and appear as tags below the filter row. Select +the **X** on a tag to remove it, or use **Clear all filters** to reset the view. + +The Scope filter only lists courses and libraries you have access to. + +User Audit View +*************** + +You can view all role assignments for a specific user across the courses and +libraries you have access to. + +#. In the Team Members tab, select the option to view their role assignments + in the **Actions** column for the user you want to review. + + .. image:: /_images/educator_how_tos/team_members_action_icon.png + :alt: The action to open a user's role assignments, in the Actions column of the team members table + +The user audit view shows all role assignments for that user. The table has +the following columns: **Role**, **Organization**, **Scope**, and **Actions**. + +Each row represents one role assignment. Use the **Organization** and **Role** +filters to narrow the view. + +Select the **View All Permissions** control in any row to expand a list of all +permissions associated with that role, grouped by functional area. + + .. image:: /_images/educator_how_tos/user_audit_view.png + :alt: The user audit view showing role assignments for a single user + +.. note:: + The role assignments shown are limited to the courses and libraries you + have access to. If your access is limited to one course, you will only + see assignments related to that course. + +.. note:: + A role assignment tied to a course where the Course Authoring flag is + disabled still appears here. The option to remove it, if you have the + permissions, is unavailable, with a message explaining why. + +Roles and Permissions Tab +************************** + +The Roles and Permissions tab shows a permission matrix for course and library +roles. Use it to understand what each role allows before assigning it to a team +member. + + .. image:: /_images/educator_how_tos/roles_and_permissions_tab.png + :alt: The Roles and Permissions tab showing the permission matrix for course roles + :align: center + +Select **Course Roles** or **Library Roles** at the top of the tab to switch +between the two views. + +For course roles, the matrix columns are: **Course Admin** and **Course Staff**. +Each row represents a permission. A checkmark (✓) means the role has that +permission. An X means it does not. + +.. note:: + This list shows the permissions currently available in Authoring Studio. + Some roles may grant additional permissions managed outside this interface. + See :ref:`Guide to Course Team Roles` for full documentation. + +Assign a Role +************** + +The **Assign Role** button is available from any tab in the console. Selecting +it opens the Assign Role wizard. + + .. image:: /_images/educator_how_tos/assign_role_button.png + :alt: The Assign Role button in the Roles and Permissions console + +#. In **Step 1: Who and Role**, enter one or more usernames or email addresses, + separated by commas, and select the role to assign. Users must have an + existing account. If any entry does not match a user, the input shows an + error and blocks the flow until corrected. + + .. image:: /_images/educator_how_tos/assign_role_step1_console.png + :alt: Step 1 of the Assign Role wizard, showing user input and role selector + +#. Select **Next**. + +#. In **Step 2: Where It Applies**, select the courses or libraries to apply + the role to. + + .. image:: /_images/educator_how_tos/assign_role_step2_console.png + :alt: Step 2 of the Assign Role wizard, showing scope selection with org-level options + + If you have management permissions at the organization level, you also see + an **All courses in this organization** or **All libraries in this + organization** option. Selecting this assigns the role to every course or + library in that organization, including ones created in the future. + + .. note:: + The courses and organizations available here reflect where the Course + Authoring feature is actually enabled. If a role assignment doesn't + seem to take effect right away, check with your site operator — this + can happen briefly during a flag change. + +#. Select **Save**. The new role assignments appear in the Team Members table. + +.. seealso:: + + :ref:`Manage Course Authoring Roles` (how-to) + + :ref:`Add users to Libraries` (how-to) + + :ref:`Guide to Course Team Roles` (reference) + +**Maintenance chart** + ++--------------+-------------------------------+----------------+--------------------------------+ +| Review Date | Working Group Reviewer | Release |Test situation | ++--------------+-------------------------------+----------------+--------------------------------+ +| [DATE] | [REVIEWER] | Verawood | [PASS/FAIL] | ++--------------+-------------------------------+----------------+--------------------------------+ diff --git a/source/educators/navigation/creating_course.rst b/source/educators/navigation/creating_course.rst index bfb0650a5..c22e9627a 100644 --- a/source/educators/navigation/creating_course.rst +++ b/source/educators/navigation/creating_course.rst @@ -86,11 +86,13 @@ Add Course Team Members .. toctree:: :maxdepth: 1 - :glob: + :glob: ../references/course_development/course_team_roles.rst ../how-tos/set_up_course/add_course_team_members.rst ../how-tos/releasing-course/manage_beta_testing.rst + ../how-tos/course_development/manage_course_authoring_roles.rst + ../how-tos/use_roles_and_permissions_console.rst Configure Grades ******************************************************* diff --git a/source/educators/references/course_development/course_team_roles.rst b/source/educators/references/course_development/course_team_roles.rst index 318115057..c439fe69b 100644 --- a/source/educators/references/course_development/course_team_roles.rst +++ b/source/educators/references/course_development/course_team_roles.rst @@ -118,17 +118,58 @@ Course data researchers can access the Data Download tab on the instructor dashb Course data researchers can: -* :ref:`View and dowload learner data ` +* :ref:`View and download learner data ` * :ref:`View Anonymized Learner IDs` * :ref:`View Certificate Data` * :ref:`View Learners Not Yet Enrolled` +.. _New System Course Authoring Roles: -.. seealso:: +*********************************************************************** +Course Authoring Roles Under the New Roles and Permissions System +*********************************************************************** + +.. note:: + These roles are available when your platform has enabled Course + Authoring — an opt-in feature disabled by default. See the operator + release notes: + https://openedx.atlassian.net/wiki/spaces/OEPM/pages/6331662350/RBAC+AuthZ+for+Course+Authoring+-+Operator+Release+Notes#Enabling-the-Feature-Flag + for instructions on how to enable it. The legacy Staff and Admin roles + remain available on platforms that have not yet enabled this feature. + +Course Admin and Course Staff are the new system's equivalents of the legacy +Admin and Staff roles for Studio authoring: same responsibilities, new +assignment mechanism. The day-to-day experience in Studio is unchanged — +these roles carry the same capabilities, just under new names and managed +through the Roles and Permissions console. + +Existing role assignments require migration to take effect in the new system. +New role assignments share the behavior of their legacy counterparts across the +full platform, not only in Studio. + +============= +Course Admin +============= + +Course Admins have full authoring access and can manage the course team. +They can do everything a Course Staff member can do, and can also add, +remove, and change roles for team members in the Roles and Permissions console. + +============= +Course Staff +============= + +Course Staff members can operate the full course lifecycle in Studio, including +publishing content, editing schedules, managing advanced settings, and importing +and exporting course content. + +.. seealso:: :ref:`Add Course Team Members` (how-to) - :ref:`Manage Course Beta Testing` (how-to) + :ref:`Manage Course Beta Testing` (how-to) + + :ref:`Manage Course Authoring Roles` (how-to) **Maintenance chart** @@ -139,3 +180,5 @@ Course data researchers can: +--------------+-------------------------------+----------------+------------------------------------------------------------------+ | 2025-03-07 | Docs WG | Sumac | `Fail `_ | +--------------+-------------------------------+----------------+------------------------------------------------------------------+ +| [DATE] | [REVIEWER] | Verawood | [PASS/FAIL] | ++--------------+-------------------------------+----------------+------------------------------------------------------------------+