diff --git a/source/_images/educator_how_tos/assign_role_button.png b/source/_images/educator_how_tos/assign_role_button.png new file mode 100644 index 000000000..beda5cde0 Binary files /dev/null and b/source/_images/educator_how_tos/assign_role_button.png differ diff --git a/source/_images/educator_how_tos/assign_role_step1_console.png b/source/_images/educator_how_tos/assign_role_step1_console.png new file mode 100644 index 000000000..0e36cf75e Binary files /dev/null and b/source/_images/educator_how_tos/assign_role_step1_console.png differ diff --git a/source/_images/educator_how_tos/assign_role_step1_manage_roles.png b/source/_images/educator_how_tos/assign_role_step1_manage_roles.png new file mode 100644 index 000000000..0ded0b8be Binary files /dev/null and b/source/_images/educator_how_tos/assign_role_step1_manage_roles.png differ diff --git a/source/_images/educator_how_tos/assign_role_step2_console.png b/source/_images/educator_how_tos/assign_role_step2_console.png new file mode 100644 index 000000000..ec0091574 Binary files /dev/null and b/source/_images/educator_how_tos/assign_role_step2_console.png differ diff --git a/source/_images/educator_how_tos/assign_role_step2_manage_roles.png b/source/_images/educator_how_tos/assign_role_step2_manage_roles.png new file mode 100644 index 000000000..443b2b182 Binary files /dev/null and b/source/_images/educator_how_tos/assign_role_step2_manage_roles.png differ diff --git a/source/_images/educator_how_tos/console_course_team_members.png b/source/_images/educator_how_tos/console_course_team_members.png new file mode 100644 index 000000000..2f57fffe4 Binary files /dev/null and b/source/_images/educator_how_tos/console_course_team_members.png differ diff --git a/source/_images/educator_how_tos/course_settings_roles_and_perms.png b/source/_images/educator_how_tos/course_settings_roles_and_perms.png new file mode 100644 index 000000000..531e91a24 Binary files /dev/null and b/source/_images/educator_how_tos/course_settings_roles_and_perms.png differ diff --git a/source/_images/educator_how_tos/library_add_team_member_button.png b/source/_images/educator_how_tos/library_add_team_member_button.png deleted file mode 100644 index 5f9f52003..000000000 Binary files a/source/_images/educator_how_tos/library_add_team_member_button.png and /dev/null differ diff --git a/source/_images/educator_how_tos/library_permissions_tab.png b/source/_images/educator_how_tos/library_permissions_tab.png deleted file mode 100644 index 79f780e20..000000000 Binary files a/source/_images/educator_how_tos/library_permissions_tab.png and /dev/null differ diff --git a/source/_images/educator_how_tos/library_team_add_new_role.png b/source/_images/educator_how_tos/library_team_add_new_role.png deleted file mode 100644 index 3537acafe..000000000 Binary files a/source/_images/educator_how_tos/library_team_add_new_role.png and /dev/null differ diff --git a/source/_images/educator_how_tos/library_team_roles_assign copy.png b/source/_images/educator_how_tos/library_team_roles_assign copy.png new file mode 100644 index 000000000..0e36cf75e Binary files /dev/null and b/source/_images/educator_how_tos/library_team_roles_assign copy.png differ diff --git a/source/_images/educator_how_tos/library_team_roles_assign_save copy.png b/source/_images/educator_how_tos/library_team_roles_assign_save copy.png new file mode 100644 index 000000000..ec0091574 Binary files /dev/null and b/source/_images/educator_how_tos/library_team_roles_assign_save copy.png differ diff --git a/source/_images/educator_how_tos/library_team_roles_delete copy.png b/source/_images/educator_how_tos/library_team_roles_delete copy.png new file mode 100644 index 000000000..1fdf42007 Binary files /dev/null and b/source/_images/educator_how_tos/library_team_roles_delete copy.png differ diff --git a/source/_images/educator_how_tos/library_team_roles_edit.png b/source/_images/educator_how_tos/library_team_roles_edit.png deleted file mode 100644 index 850fb580c..000000000 Binary files a/source/_images/educator_how_tos/library_team_roles_edit.png and /dev/null differ diff --git a/source/_images/educator_how_tos/library_team_roles_edit_user_screen copy.png b/source/_images/educator_how_tos/library_team_roles_edit_user_screen copy.png new file mode 100644 index 000000000..543490299 Binary files /dev/null and b/source/_images/educator_how_tos/library_team_roles_edit_user_screen copy.png differ diff --git a/source/_images/educator_how_tos/library_team_roles_new_role_popup.png b/source/_images/educator_how_tos/library_team_roles_new_role_popup.png deleted file mode 100644 index 387392db7..000000000 Binary files a/source/_images/educator_how_tos/library_team_roles_new_role_popup.png and /dev/null differ diff --git a/source/_images/educator_how_tos/library_team_roles_tab.png b/source/_images/educator_how_tos/library_team_roles_tab.png deleted file mode 100644 index d938a74e0..000000000 Binary files a/source/_images/educator_how_tos/library_team_roles_tab.png and /dev/null differ diff --git a/source/_images/educator_how_tos/remove_role_icon.png b/source/_images/educator_how_tos/remove_role_icon.png new file mode 100644 index 000000000..1fdf42007 Binary files /dev/null and b/source/_images/educator_how_tos/remove_role_icon.png differ diff --git a/source/_images/educator_how_tos/roles_and_permissions_tab.png b/source/_images/educator_how_tos/roles_and_permissions_tab.png new file mode 100644 index 000000000..97c2a4250 Binary files /dev/null and b/source/_images/educator_how_tos/roles_and_permissions_tab.png differ diff --git a/source/_images/educator_how_tos/studio_home_roles_and_permissions_button.png b/source/_images/educator_how_tos/studio_home_roles_and_permissions_button.png new file mode 100644 index 000000000..a7436280f Binary files /dev/null and b/source/_images/educator_how_tos/studio_home_roles_and_permissions_button.png differ diff --git a/source/_images/educator_how_tos/team_members_action_icon.png b/source/_images/educator_how_tos/team_members_action_icon.png new file mode 100644 index 000000000..f8411ee97 Binary files /dev/null and b/source/_images/educator_how_tos/team_members_action_icon.png differ diff --git a/source/_images/educator_how_tos/team_members_filters.png b/source/_images/educator_how_tos/team_members_filters.png new file mode 100644 index 000000000..80224ef3f Binary files /dev/null and b/source/_images/educator_how_tos/team_members_filters.png differ diff --git a/source/_images/educator_how_tos/team_members_tab.png b/source/_images/educator_how_tos/team_members_tab.png new file mode 100644 index 000000000..2ba20d410 Binary files /dev/null and b/source/_images/educator_how_tos/team_members_tab.png differ diff --git a/source/_images/educator_how_tos/user_audit_view.png b/source/_images/educator_how_tos/user_audit_view.png new file mode 100644 index 000000000..543490299 Binary files /dev/null and b/source/_images/educator_how_tos/user_audit_view.png differ diff --git a/source/_images/release_notes/verawood/rp_console_roles.png b/source/_images/release_notes/verawood/rp_console_roles.png new file mode 100644 index 000000000..08db6fb54 Binary files /dev/null and b/source/_images/release_notes/verawood/rp_console_roles.png differ diff --git a/source/community/release_notes/verawood/dev_op_release_notes.rst b/source/community/release_notes/verawood/dev_op_release_notes.rst index 356da0e10..3ce4c22ae 100644 --- a/source/community/release_notes/verawood/dev_op_release_notes.rst +++ b/source/community/release_notes/verawood/dev_op_release_notes.rst @@ -409,155 +409,162 @@ Administrators & Operators slot to render the content. See the instructor dashboard MFE README for more details. -* **RBAC AuthZ for Course Authoring (opt-in).** Verawood introduces a new, - opt-in, RBAC-based authorization system for course authoring in Studio, - powered by `openedx-authz `_. - This replaces the legacy ``CourseAccessRole``-based permission model with a - more granular, role-based system. See `ADR: AuthZ for Course Authoring - Implementation Plan - `_. - - This flag will be turned on by default in the next release, Willow, and - the legacy permission system will be removed in Xylon (June 2027). To set up an - individual course, a specific organization, or your whole site to use the - new system, you need to both enable the appropriate feature flag(s) and - run migrations. - - * **Enabling the feature flag.** The feature is controlled by the waffle - flag ``authz.enable_course_authoring``, which can be enabled at three - levels of granularity (course, organization, global). When disabled (the - default), the legacy permission system remains in effect and no behavior - changes. - - * Course-level: add a "Waffle flag course override" at - ``/admin/waffle_utils/waffleflagcourseoverridemodel/`` for - ``authz.enable_course_authoring``, with the course key, "Force - On"/"Force Off", marked "Enabled". - * Org-level: add a "Waffle flag org override" at - ``/admin/waffle_utils/waffleflagorgoverridemodel/`` the same way, - using the org short name. - * Global: add a Flag named ``authz.enable_course_authoring`` at - ``/admin/waffle/flag/`` with "Everyone" set to "Yes". - * Course and org overrides work as overrides over the global flag, not - independent switches. If the override is "Disabled", the effective - state follows the global flag. If the global flag is off, an override - "Enabled" + "Force On" turns the flag on for that scope; if the global - flag is on, "Enabled" + "Force Off" turns it off for that scope. - * Global enablement affects all courses on the instance. If automatic - migrations are not enabled (see below), you must run the migration - management commands manually before or after toggling the global flag. - - See `ADR: Feature Flag Implementation Details - `_. - - * **Migrating permission data.** Existing legacy role assignments - (``CourseAccessRole``) must be migrated to ``openedx-authz`` when - enabling the new system. Two management commands are provided, scoped by - either ``--course-id-list`` or ``--org-id`` (mutually exclusive; one is - required): - - * Forward migration (legacy to openedx-authz): ``./manage.py cms - authz_migrate_course_authoring --delete --course-id-list - [course_key2 ...]`` or ``--org-id `` - * Rollback migration (openedx-authz to legacy): ``./manage.py cms - authz_rollback_course_authoring --delete --course-id-list - [course_key2 ...]`` or ``--org-id `` - * Both accept ``--delete``, which removes the successfully migrated role - assignments from the source system after migration (prompts for - confirmation). Without ``--delete``, the migration copies but does not - move, and source records are preserved. - * Using ``--delete`` is strongly recommended. The system expects - permission data to exist in only one system at a time for a given - resource. If assignments remain in both systems they can diverge over - time: for example, a course may keep appearing in a user's Studio - course list after their permissions were removed in one system, - because the assignment still exists in the other. Running without - ``--delete`` should only be used for development/testing before the - definitive migration. - * Both operations run within a database transaction. During rollback, - roles that exist only in the new system (no legacy equivalent) remain - in ``openedx-authz`` and are not migrated back; warnings are logged. - - See `ADR: Migration Process Details - `_. - - * **Automatic migrations (opt-in).** Set - ``ENABLE_AUTOMATIC_AUTHZ_COURSE_AUTHORING_MIGRATION = True`` (default - ``False``) to have course/org-level flag toggles in Django Admin - automatically trigger the corresponding data migration (forward on - enable, rollback on disable). Migration status and errors are recorded - in the ``AuthzCourseAuthoringMigrationRun`` model, viewable in Django - Admin. A runtime constraint prevents concurrent migrations on the same - scope. - - * Automatic migration only applies to course-level and org-level flag - changes. Global (instance-wide) flag changes do not trigger it, due to - performance risk on large instances, and must be migrated manually - with the management commands above. - * This setting is disabled by default. Only enable it if you understand - that the migration then runs synchronously within the Django Admin - request. - - See `ADR: Automatic Migration Details - `_. - - * **Audit trail.** Role assignment and removal operations in - ``openedx-authz`` are now recorded in a ``RoleAssignmentAudit`` table - (operation type, affected user, role, scope, actor), registered in - Django Admin for inspection. An ``OpenedxPublicSignal`` is also emitted - on every role lifecycle event for downstream consumers. See `ADR: - Auditability - `_. - - * **Known caveat: Admin Console and courses without the flag enabled.** - The Admin Console displays all courses in scope selectors when assigning - roles, regardless of whether ``authz.enable_course_authoring`` is - enabled for those courses. Roles can be assigned to any course through - the admin, but those assignments won't take effect unless the flag is - enabled for that course, its org, or globally. This can look like roles - were assigned but permissions aren't enforced. This limitation does not - affect content libraries, which don't use the legacy permission system. - - As of `frontend-app-admin-console PR #176 - `_, the - Admin Console's filters and role assignment wizard all read flag state directly - from ``GET /api/authz/v1/waffle-flag-states/`` and hide course content the flag - doesn't cover yet, independently of whether the underlying Casbin - migration has run. The Team Members table and Audit User view display all - course assignments; however, course or organization assignments that are - not enabled via the ``authz.enable_course_authoring`` flag can only be viewed, - but not deleted. Observed behavior: - - .. list-table:: - :header-rows: 1 - - * - Scenario - - Expected behaviour - * - Flag OFF globally, no overrides - - Role filter hides course groups; scope filter hides all courses; - org filter hides all orgs for course-only users; wizard has no - course roles - * - Flag OFF globally, org A forced ON - - Courses in org A appear in scope/org filters and wizard; all - other orgs/courses hidden - * - Flag ON globally, course X forced OFF - - Course X hidden in scope filter and wizard scope list; all other - courses visible - * - Flag ON globally, org B forced OFF - - Org B and its courses hidden for course-only users - * - User has only library roles - - Libraries appear in all filters regardless of flag state - * - User has both library and course roles, flag OFF - - Library content visible everywhere; course content hidden - * - ``waffle-flag-states`` endpoint unreachable - - Error toast appears with retry button; all course content hidden - * - Loading state (slow network) - - Course content hidden until flag state resolves; library content - unaffected - - Flag-state resolution here is intentionally separate from permission - validation, since Casbin state can lag behind the flag when automatic - migration is disabled or the global flag changes. + + +.. _Enabling RBAC in Verawood: + +Enabling RBAC in Verawood +************************* + +**RBAC AuthZ for Course Authoring (opt-in).** Verawood introduces a new, +opt-in, RBAC-based authorization system for course authoring in Studio, +powered by `openedx-authz `_. +This replaces the legacy ``CourseAccessRole``-based permission model with a +more granular, role-based system. See `ADR: AuthZ for Course Authoring +Implementation Plan +`_. + +This flag will be turned on by default in the next release, Willow, and +the legacy permission system will be removed in Xylon (June 2027). To set up an +individual course, a specific organization, or your whole site to use the +new system, you need to both enable the appropriate feature flag(s) and +run migrations. + +* **Enabling the feature flag.** The feature is controlled by the waffle + flag ``authz.enable_course_authoring``, which can be enabled at three + levels of granularity (course, organization, global). When disabled (the + default), the legacy permission system remains in effect and no behavior + changes. + + * Course-level: add a "Waffle flag course override" at + ``/admin/waffle_utils/waffleflagcourseoverridemodel/`` for + ``authz.enable_course_authoring``, with the course key, "Force + On"/"Force Off", marked "Enabled". + * Org-level: add a "Waffle flag org override" at + ``/admin/waffle_utils/waffleflagorgoverridemodel/`` the same way, + using the org short name. + * Global: add a Flag named ``authz.enable_course_authoring`` at + ``/admin/waffle/flag/`` with "Everyone" set to "Yes". + * Course and org overrides work as overrides over the global flag, not + independent switches. If the override is "Disabled", the effective + state follows the global flag. If the global flag is off, an override + "Enabled" + "Force On" turns the flag on for that scope; if the global + flag is on, "Enabled" + "Force Off" turns it off for that scope. + * Global enablement affects all courses on the instance. If automatic + migrations are not enabled (see below), you must run the migration + management commands manually before or after toggling the global flag. + + See `ADR: Feature Flag Implementation Details + `_. + +* **Migrating permission data.** Existing legacy role assignments + (``CourseAccessRole``) must be migrated to ``openedx-authz`` when + enabling the new system. Two management commands are provided, scoped by + either ``--course-id-list`` or ``--org-id`` (mutually exclusive; one is + required): + + * Forward migration (legacy to openedx-authz): ``./manage.py cms + authz_migrate_course_authoring --delete --course-id-list + [course_key2 ...]`` or ``--org-id `` + * Rollback migration (openedx-authz to legacy): ``./manage.py cms + authz_rollback_course_authoring --delete --course-id-list + [course_key2 ...]`` or ``--org-id `` + * Both accept ``--delete``, which removes the successfully migrated role + assignments from the source system after migration (prompts for + confirmation). Without ``--delete``, the migration copies but does not + move, and source records are preserved. + * Using ``--delete`` is strongly recommended. The system expects + permission data to exist in only one system at a time for a given + resource. If assignments remain in both systems they can diverge over + time: for example, a course may keep appearing in a user's Studio + course list after their permissions were removed in one system, + because the assignment still exists in the other. Running without + ``--delete`` should only be used for development/testing before the + definitive migration. + * Both operations run within a database transaction. During rollback, + roles that exist only in the new system (no legacy equivalent) remain + in ``openedx-authz`` and are not migrated back; warnings are logged. + + See `ADR: Migration Process Details + `_. + +* **Automatic migrations (opt-in).** Set + ``ENABLE_AUTOMATIC_AUTHZ_COURSE_AUTHORING_MIGRATION = True`` (default + ``False``) to have course/org-level flag toggles in Django Admin + automatically trigger the corresponding data migration (forward on + enable, rollback on disable). Migration status and errors are recorded + in the ``AuthzCourseAuthoringMigrationRun`` model, viewable in Django + Admin. A runtime constraint prevents concurrent migrations on the same + scope. + + * Automatic migration only applies to course-level and org-level flag + changes. Global (instance-wide) flag changes do not trigger it, due to + performance risk on large instances, and must be migrated manually + with the management commands above. + * This setting is disabled by default. Only enable it if you understand + that the migration then runs synchronously within the Django Admin + request. + + See `ADR: Automatic Migration Details + `_. + +* **Audit trail.** Role assignment and removal operations in + ``openedx-authz`` are now recorded in a ``RoleAssignmentAudit`` table + (operation type, affected user, role, scope, actor), registered in + Django Admin for inspection. An ``OpenedxPublicSignal`` is also emitted + on every role lifecycle event for downstream consumers. See `ADR: + Auditability + `_. + +* **Known caveat: Admin Console and courses without the flag enabled.** + The Admin Console displays all courses in scope selectors when assigning + roles, regardless of whether ``authz.enable_course_authoring`` is + enabled for those courses. Roles can be assigned to any course through + the admin, but those assignments won't take effect unless the flag is + enabled for that course, its org, or globally. This can look like roles + were assigned but permissions aren't enforced. This limitation does not + affect content libraries, which don't use the legacy permission system. + + As of `frontend-app-admin-console PR #176 + `_, the + Admin Console's filters and role assignment wizard all read flag state directly + from ``GET /api/authz/v1/waffle-flag-states/`` and hide course content the flag + doesn't cover yet, independently of whether the underlying Casbin + migration has run. The Team Members table and Audit User view display all + course assignments; however, course or organization assignments that are + not enabled via the ``authz.enable_course_authoring`` flag can only be viewed, + but not deleted. Observed behavior: + + .. list-table:: + :header-rows: 1 + + * - Scenario + - Expected behaviour + * - Flag OFF globally, no overrides + - Role filter hides course groups; scope filter hides all courses; + org filter hides all orgs for course-only users; wizard has no + course roles + * - Flag OFF globally, org A forced ON + - Courses in org A appear in scope/org filters and wizard; all + other orgs/courses hidden + * - Flag ON globally, course X forced OFF + - Course X hidden in scope filter and wizard scope list; all other + courses visible + * - Flag ON globally, org B forced OFF + - Org B and its courses hidden for course-only users + * - User has only library roles + - Libraries appear in all filters regardless of flag state + * - User has both library and course roles, flag OFF + - Library content visible everywhere; course content hidden + * - ``waffle-flag-states`` endpoint unreachable + - Error toast appears with retry button; all course content hidden + * - Loading state (slow network) + - Course content hidden until flag state resolves; library content + unaffected + + Flag-state resolution here is intentionally separate from permission + validation, since Casbin state can lag behind the flag when automatic + migration is disabled or the global flag changes. Frontend-base ************* diff --git a/source/community/release_notes/verawood/feature_release_notes.rst b/source/community/release_notes/verawood/feature_release_notes.rst index d210a9ea6..7b425197a 100644 --- a/source/community/release_notes/verawood/feature_release_notes.rst +++ b/source/community/release_notes/verawood/feature_release_notes.rst @@ -8,6 +8,7 @@ Open edX Verawood Release - Product Release Notes .. toctree:: :maxdepth: 1 + verawood_rp ai_extension_framework new_instructor_dashboard verawood_lti_cert @@ -23,5 +24,5 @@ in the :ref:`Verawood Dev Notes`. +--------------+-------------------------------+----------------+--------------------------------+ | Review Date | Working Group Reviewer | Release |Test situation | +--------------+-------------------------------+----------------+--------------------------------+ -| | | | | +| 2025-07-30 | Product WG | Verawood | Pass | +--------------+-------------------------------+----------------+--------------------------------+ diff --git a/source/community/release_notes/verawood/verawood_lti_cert.rst b/source/community/release_notes/verawood/verawood_lti_cert.rst index 90888e9e3..f294e700e 100644 --- a/source/community/release_notes/verawood/verawood_lti_cert.rst +++ b/source/community/release_notes/verawood/verawood_lti_cert.rst @@ -48,4 +48,4 @@ View the `1EdTech listing for the Open edX platform here | Review Date | Working Group Reviewer | Release |Test situation | +--------------+-------------------------------+----------------+--------------------------------+ | 2026-07-03 | Aamir Ayub | Verawood | Pass | -+--------------+-------------------------------+----------------+--------------------------------+ ++--------------+-------------------------------+----------------+--------------------------------+ \ No newline at end of file diff --git a/source/community/release_notes/verawood/verawood_rp.rst b/source/community/release_notes/verawood/verawood_rp.rst new file mode 100644 index 000000000..ca43b930e --- /dev/null +++ b/source/community/release_notes/verawood/verawood_rp.rst @@ -0,0 +1,144 @@ +.. _Introducing More Granular Team Management: + +Introducing More Granular Team Management +########################################## + +Easily manage user access across multiple parts of the platform from a single +view. The Verawood release extends the :ref:`administrative console `, introduced in the previous release for managing permissions over +:ref:`Content Libraries `. Now renamed to the "Roles and +Permissions Console", it adds new roles that can be applied across Studio. + +.. figure:: /_images/educator_how_tos/console_course_team_members.png + :alt: The Team Members tab of the Roles and Permissions console, showing course team members + + The Team Members tab of the Roles and Permissions console. This is the Admin + view; you only see the role assignments associated with the course(s) and/or + librar(ies) you have access to, not any other roles those users may have + on other organizations, courses, or libraries. + +You can now assign two new roles, Course Admin or Course Staff, to one or +multiple users and apply them at multiple levels (a specific organization, +course, or library) — all in a single action. Granting a role at +the organization level covers both existing courses and any courses created in +that organization afterward. + +This feature is opt-in and disabled by default. It can be enabled across your +whole instance, or for one or more specific organizations or courses, and must be +:ref:`enabled by your site administrator `. + +New User Roles +************** + +**Course Admin** is the new-system equivalent of the legacy Admin role: course +team management through the Roles and Permissions console and full authoring +access in Studio. + +**Course Staff** is the new-system equivalent of the legacy Staff role: full +course lifecycle management in Studio. + +**Course Admin** and **Course Staff** are the new system's equivalents of the +legacy Admin and Staff roles for a course: same responsibilities, new assignment +mechanism. For a full breakdown of what each role can do, see :ref:`Course Authoring Roles +Under the New Roles and Permissions System `. + +What's Available in Verawood +***************************** + +- **Unified interface**: the Roles and Permissions console displays all role + assignments in one place, filterable by role, organization, and scope. +- **Assign Role wizard**: assign a role to multiple users and multiple scopes in + a single action. +- **Organization-level assignment**: grant a role to a user across an entire + organization, including scopes created later. +- **User audit view**: shows a user's roles across every course and library you + have permission to manage. +- **Filtered entry points**: the console opens filtered to the context you came + from, unfiltered from the Studio home page, or filtered to a single course or + library when opened from there. + +Scope and Impact +***************** + +When this feature is enabled, the platform supports both the legacy Instructor +Dashboard roles (Admin, Staff, Limited Staff) and the new Course Admin / Course +Staff roles at the same time. New roles apply according to the scope where the +flag is enabled — platform, organization, or course. + +The Roles and Permissions console is a place where you can examine the users who +have access to your system - their “role”, and also where that applies (which +“organization” it applies to, as well as the “scope” of the role - specific +course(s) or librar(ies)). For example, in the following screenshot, we see two +users - Jhon_Doe, who has the "Course Admin” role - this role applies across one +organization and one course. The next user, “KellyKapoor”, has the “Course +Editor” role applied over a different course in a different organization. + +.. image:: /_images/release_notes/verawood/rp_console_roles.png + :alt: A screenshot illustrating the above paragraph + +Note: if you have a role for a course or library, this view allows you to see +users who have roles related to that same course or library. You only see the +role assignments associated with the course(s) and/or librar(ies) you have +access to, not any other roles those users may have on other organizations, +courses, or libraries. + +The Roles and Permissions console is where you can examine the users who have +access to your system: their role, which organization it applies to, and the scope +of the role (specific course(s) or librar(ies)). The console also lets you change +or add course and library authoring roles for individual users. + +Migration of Existing Course Role Assignments +********************************************** + +Verawood includes migration tools to synchronize existing Admin and Staff course +role assignments between the legacy system and the new Roles and Permissions +framework. Depending on how your site is configured, this can happen automatically +when the Course Authoring feature is enabled for a course or organization — +existing Admin and Staff assignments carry over without manual steps. If automatic +migration isn't enabled on your site, your site operator can run the migration +separately. No role assignments are lost in the process. + +Not Affected by This Release +***************************** + +- Course content and how it is authored. This feature improves how course and + library teams are managed, not what authors create. +- :ref:`Legacy Libraries ` (deprecated in + Verawood) that have not yet been :ref:`migrated to Content Libraries `. +- Permissions that apply to LMS functionality and are managed by the Instructor + Dashboard, such as Discussions Forums Admin or Beta Tester. + +Future Improvements +******************** + +In upcoming releases, the Roles and Permissions work is expected to continue in +several directions: + +- New Studio roles are planned to separate authoring responsibilities from + managing an active course, and to introduce a read-only role for reviewing + course content in Studio. +- Roles and Permissions management will also expand to the LMS, bringing the same + model to learner-facing features and runtime course management. +- Documentation with design patterns, guides, and extension points for the + community to build on top of the new system are also on the roadmap. + + +.. seealso:: + + :ref:`Manage Course Authoring Roles` (how-to) + + :ref:`Guide to Course Team Roles` (reference) + + :ref:`Add Course Team Members` (how-to) + + :ref:`Verawood Product Notes` (reference) + + +**Maintenance chart** + ++--------------+-------------------------------+----------------+--------------------------------+ +| Review Date | Working Group Reviewer | Release |Test situation | ++--------------+-------------------------------+----------------+--------------------------------+ +| 2025-07-30 | eduNEXT | Verawood | Pass | ++--------------+-------------------------------+----------------+--------------------------------+ diff --git a/source/educators/how-tos/course_development/add_users_to_libraries.rst b/source/educators/how-tos/course_development/add_users_to_libraries.rst index b79125284..549eb65d5 100644 --- a/source/educators/how-tos/course_development/add_users_to_libraries.rst +++ b/source/educators/how-tos/course_development/add_users_to_libraries.rst @@ -6,12 +6,12 @@ Manage Library User Access .. tags:: educator, how-to Access to a library team starts from the library home page in Studio and is -managed in the library team manager in the :ref:`Administrative Console `. This article explains the library roles and how to add and manage -members of a library team. +managed in the Roles and Permissions console. This article explains the +library roles and how to add and manage members of a library team. -Any change made in the library team manager applies to this library only. It -does not change what that user can do in other libraries or in courses. +Any change made in the Roles and Permissions console applies to this library +only. It does not change what that user can do in other libraries or in +courses. .. contents:: :local: @@ -28,195 +28,99 @@ Libraries use roles to control what each team member can do. See * Library Author * Library Admin -Library Team Management -*********************** +Access the Roles and Permissions Console +***************************************** -On the Team Management panel, there are three tabs at the top of the page: - -* Team Members -* Roles -* Permissions - -Any user who has any of the above Library Roles can view these tabs. - -Team Members Tab -================ - -On the Team Members tab, users can see who has access to the Library and which -roles they have. The list of team members is searchable by username or email, -and can be filtered by role, making it easy to understand who else can edit, -publish or manage access. - -.. image:: /_images/educator_how_tos/library_team_member_tab.png - :alt: The Team Members tab of the Admin Console, showing two team members in a table with the columns Name, Email, Role, and Actions - :width: 800 - :align: center - -Roles Tab -========= - -The :ref:`authz:Library Roles` tab has a description of each Library role and -the set of permissions each role includes, helping users understand at a glance what -each role covers when granting permissions. - -.. image:: /_images/educator_how_tos/library_team_roles_tab.png - :alt: The Roles tab shows all 4 Library roles and what permissions each role grants - :align: center - -Permissions Tab -=============== - -The Permissions tab has a :ref:`authz:Library RP Summary Table` that describes -which permissions are assigned to each role. Every permission in the table -includes a short explanation, enabling users to see what role allows which -actions, and compare roles side by side before they change a user's access. - -.. image:: /_images/educator_how_tos/library_permissions_tab.png - :alt: The Permissions tab shows a table of permissions, with a ✅ for permissions a given role allows and a ❌ for permissions not available for that role. - :align: center - - -Manage Access for Library Team Members -************************************** - -Only Library Admins and global site admins can add or remove team members or change -their roles. All actions in this section affect access to one library only. - -To begin, follow these steps to open the Team Management panel: - -#. From the home page of the library in Studio, click the :guilabel:`ⓘ Library Info` button on +#. From the home page of the library in Studio, select the :guilabel:`ⓘ Library Info` button on the top right of the page to open the right sidebar. .. image:: /_images/educator_how_tos/library_info_button.png :alt: The Library Info button appears below the header, on the top-right of the page. -#. In the right sidebar, click the :guilabel:`Manage Access` button. This opens the team - management panel in a new browser tab in the Administrative Console, on the - Team Members tab. +#. In the right sidebar, select :guilabel:`Manage Access`. This opens the Roles and + Permissions console in a new browser tab, filtered to this library's team. .. image:: /_images/educator_how_tos/library_manage_access_button.png :alt: The "Manage Access" button appears in the right sidebar, below the Published status and Organization information. :scale: 40 :align: center -View Team Members -================= - -Library administrators can audit a user's access to that library via the Team Management panel: - -#. Use search or filters to find a user to update and select Edit in the Action - column to open the user detail view. +For a full description of the console's tabs, filters, and audit view, see +:ref:`Use Roles and Permissions Console`. - .. image:: /_images/educator_how_tos/library_team_roles_edit.png - :alt: The "Edit" link appears in the rightmost column of the User table for each row that contains a user. +Find and Audit Team Members +**************************** -#. Once "Edit" has been clicked, a new screen is shown that allows admins to - view what roles a user holds and edit their access to the library. +Use search or filters to find a team member. Select the option in the +**Actions** column to open their audit view, which shows their current +role and the permissions it grants for this library. .. image:: /_images/educator_how_tos/library_team_roles_edit_user_screen.png - :alt: The screen for one single user, showing their role (Library Admin) and a table of which permissions that role grants them. + :alt: The audit view for one team member, showing their role (Library Admin) and a table of which permissions that role grants them. +Assign a Role +************** -Add a New Team Member -======================== +Only Library Admins and global site admins can assign roles. -Library administrators can add a new team member via the Team Management panel: +#. In the Roles and Permissions console, select **Assign Role**. -#. In the team management panel, click the :guilabel:`+ Add New Team Member` button in the - upper right corner to open the Add User pop-up. + This opens the Assign Role wizard. Use it both to add a new team member + and to give an existing team member an additional role. - .. image:: /_images/educator_how_tos/library_add_team_member_button.png - :alt: The Add New Team Member button appears at the top-right of the Library Team Management page - -#. In the pop-up window, enter one or more email addresses or usernames of the - people you want to grant access to, separated by commas. Select the desired - role to assign, for example Library Admin, Library Author, Library - Contributor, or Library User. +#. In **Step 1: Who and Role**, enter one or more usernames or email + addresses, separated by commas, and select the role to assign: Library + Admin, Library Author, Library Contributor, or Library User. .. image:: /_images/educator_how_tos/library_team_roles_assign.png - :alt: The pop-up modal has a text box for entering users by username or email, and a dropdown menu that shows the available roles to be assigned. - -#. Save the changes. After saving, the new user(s) are listed in the team table with their new role. - - .. image:: /_images/educator_how_tos/library_team_roles_assign_save.png - :alt: The "Save" button appears in the bottom right of the pop-up modal. - -Edit User Roles -=============== + :alt: The Assign Role wizard's first step, with a text box for entering users by username or email and a dropdown for the role to assign. -Library Admins and global site admins can update roles for users who are already -on the library team. To begin, follow these steps to open the Team Management -panel: + Users must have an existing account. If any entry does not match a user, + the input shows an error for that entry and blocks the flow until + corrected. -#. From the home page of the library in Studio, click the :guilabel:`ⓘ Library Info` button on - the top right of the page to open the right sidebar. - - .. image:: /_images/educator_how_tos/library_info_button.png - :alt: The Library Info button appears below the header, on the top-right of the page. - -#. In the right sidebar, click the :guilabel:`Manage Access` button. This opens the team - management panel in a new browser tab in the Administrative Console, on the - Team Members tab. - - .. image:: /_images/educator_how_tos/library_manage_access_button.png - :alt: The "Manage Access" button appears in the right sidebar, below the Published status and Organization information. - :scale: 40 - :align: center - -Add a Role to a Team Member ----------------------------- - -#. Navigate to the "Team Members" tab of the Team Management panel. Use search - or filters to find the user to update and select "Edit" in the Action column - to open the user detail view for the user. +#. Select **Next**. - .. image:: /_images/educator_how_tos/library_team_roles_edit.png - :alt: The "Edit" link appears in the rightmost column of the User table for each row that contains a user. +#. In **Step 2: Where It Applies**, select this library to apply the role to. -#. In the user detail view, select :guilabel:`Add New Role` in the upper right corner. +#. Select **Save**. After saving, the new role assignments appear in the team + table. - .. image:: /_images/educator_how_tos/library_team_add_new_role.png - :alt: The "Add New Role" button appears in the top right corner. - - -#. In the Add New Role pop-up, open the Roles dropdown and select the new role to add. - - .. image:: /_images/educator_how_tos/library_team_roles_new_role_popup.png - :alt: The pop-up dialog has a dropdown for selecting a role, and both a Cancel and a Save button in the bottom right. - -#. Select Save. - -The new role is added for this user in this library and appears in their list of roles. + .. image:: /_images/educator_how_tos/library_team_roles_assign_save.png + :alt: The "Save" button in the Assign Role wizard. -Remove a Role from a Team Member --------------------------------- +Remove a Role +************** -#. Navigate to the "Team Members" tab of the Team Management panel. Use search - or filters to find the user to update and select "Edit" in the Action column - to open the user detail view for the user. +Library Admins and global site admins can remove role assignments. - .. image:: /_images/educator_how_tos/library_team_roles_edit.png - :alt: The "Edit" link appears in the rightmost column of the User table for each row that contains a user. +#. In the team members list, find the user whose role you want to remove and + select the option to open their audit view. -#. In the user detail view, find the role to remove and select the delete icon for that role. +#. In the audit view, find the role to remove and select the option to + remove that role. .. image:: /_images/educator_how_tos/library_team_roles_delete.png - :alt: The delete (trash can) icon appears on the top right of each "card", where a card represents one role a user holds. + :alt: The remove-role control on a role card in the audit view. - -#. In the Remove role confirmation pop-up, review the message and select Remove - to confirm, or Cancel to retain the user's current level of access. +#. Review the confirmation message and select **Remove** to confirm, or + **Cancel** to keep the current assignment. .. image:: /_images/educator_how_tos/library_team_roles_remove_role_popup.png - :alt: The pop-up dialog, in this example, explains that removing the role for the user will also remove all their Library access as it is the only role the user has. + :alt: The confirmation dialog, explaining that removing the role also removes all library access if it is the user's only role. .. note:: - After "Remove" is selected, that role is removed for this user in this library. If the - user has no roles left for this library, they will no longer have access and - will stop appearing in the team list. Their roles in other libraries or courses - are not affected. + After a role is removed, if the user has no roles left for this library, + they will no longer have access and will stop appearing in the team list. + Their roles in other libraries or courses are not affected. +.. note:: + With Verawood, this same Roles and Permissions console can also manage + course team roles, if your site has enabled Course Authoring. See + :ref:`Manage Course Authoring Roles` for the equivalent course workflow. This + doesn't change how library access works — everything above applies the + same way whether or not Course Authoring is enabled. .. seealso:: @@ -242,11 +146,17 @@ Remove a Role from a Team Member :ref:`Add a Problem Bank to your course for randomization` + :ref:`Use Roles and Permissions Console` (how-to) + + :ref:`Manage Course Authoring Roles` (how-to) + **Maintenance chart** +--------------+-------------------------------+----------------+--------------------------------+ | Review Date | Working Group Reviewer | Release |Test situation | +--------------+-------------------------------+----------------+--------------------------------+ +| 2025-07-30 | eduNEXT | Verawood | Pass | ++--------------+-------------------------------+----------------+--------------------------------+ | 2025-12-11 | Product WG | Ulmo | Pass | +--------------+-------------------------------+----------------+--------------------------------+ | 07/02/2025 | Leira (Curricu.me) | Sumac | Pass | diff --git a/source/educators/how-tos/course_development/create_new_library.rst b/source/educators/how-tos/course_development/create_new_library.rst index c190050e8..e61d8e747 100644 --- a/source/educators/how-tos/course_development/create_new_library.rst +++ b/source/educators/how-tos/course_development/create_new_library.rst @@ -9,9 +9,13 @@ Create a New Library To create a new library, follow these steps. +.. note:: To create a library, your account must have the ``course_creator`` + role, or global admin or global staff access on your platform. If you do + not have this access, contact your platform administrator. + #. Log in to Studio. -#. Select **Libraries** from the Studio home page. +#. Select **Libraries** from the Studio home page. #. Select **New Library**. @@ -24,7 +28,7 @@ To create a new library, follow these steps. - For **Library Name**, enter the public display name for your library. Choose a meaningful name that will help you and other course team members - to identify the library. For example, "Level 200 Math Problems". + to identify the library. For example, "Level 200 Math Problems". - For **Organization**, enter the identifier for your university. For example, enter HarvardX or MITx. Do not include spaces or special @@ -37,15 +41,16 @@ To create a new library, follow these steps. #. Select **Create**. You see the new library, to which you can now add components. For information -about adding components to a library, see :ref:`Build a Collection in a Library` and :ref:`Create and edit content in a Library`. +about adding components to a library, see :ref:`Build a Collection in a Library` +and :ref:`Create and edit content in a Library`. -After you create a library, you are automatically assigned an **Admin** role -for the library. For information about adding other users to a library after -you create it, see :ref:`Add users to Libraries`. +After you create a library, you are automatically assigned a **Library Admin** +role for the library. For information about adding other users to a library +after you create it, see :ref:`Add users to Libraries`. .. seealso:: - + :ref:`Navigate the Library Homepage` :ref:`Create and edit content in a Library` @@ -78,5 +83,5 @@ you create it, see :ref:`Add users to Libraries`. +--------------+-------------------------------+----------------+--------------------------------+ | Review Date | Working Group Reviewer | Release |Test situation | +--------------+-------------------------------+----------------+--------------------------------+ -| | | | | +| 2025-07-30 | eduNEXT | Verawood | Pass | +--------------+-------------------------------+----------------+--------------------------------+ diff --git a/source/educators/how-tos/course_development/manage_course_authoring_roles.rst b/source/educators/how-tos/course_development/manage_course_authoring_roles.rst new file mode 100644 index 000000000..03192f41c --- /dev/null +++ b/source/educators/how-tos/course_development/manage_course_authoring_roles.rst @@ -0,0 +1,150 @@ +.. _Manage Course Authoring Roles: + +Manage Course Authoring Roles +############################################################## + +.. tags:: educator, how-to + +This article covers the course authoring roles introduced in the Verawood +release. Whether these roles or the ones described in +:ref:`Add Course Team Members` apply to your course team depends on whether +Course Authoring is enabled for your site. + +.. note:: + This feature is not enabled by default, and must be enabled by your site administrator. See: + :ref:`Enabling RBAC in Verawood` + for instructions on how to enable it. For more on what's included in this + release, see :ref:`Introducing More Granular Team Management`. + +.. contents:: + :local: + :depth: 2 + +Course Roles +************* + +Courses use roles to control what each team member can do. See +:ref:`Course Authoring Roles Under the New Roles and Permissions System ` +for more detail on the following course roles: + +* Course Admin +* Course Staff + +Access the Roles and Permissions Console +***************************************** + +The Roles and Permissions console can be opened from the Studio home page. +A filtered view, scoped to a specific course, can be accessed from the +course Settings menu. + +To open the console for a specific course: + +#. In Studio, open the **Settings** menu for your course. + +#. Select **Roles and Permissions**. The console opens in a new browser tab, + filtered to show only this course's team. + + .. image:: /_images/educator_how_tos/course_settings_roles_and_perms.png + :alt: The Settings menu in Studio, showing the Roles and Permissions option + +Find and Audit Team Members +**************************** + +Once you open the console, your course team is shown in the **Team Members** +tab. The tab lists all users with a role assignment on this course. Use the +search bar and filters to find a specific user. + +Select the option in the **Actions** column to open a user's audit view, +which lists all of their role assignments. + +For a detailed description of the console and its filters, see +:ref:`Use Roles and Permissions Console`. + +Assign a Role +************** + +Only :ref:`Course Admins ` and global site admins can assign roles. + +#. In the Roles and Permissions console, select **Assign Role**. + + .. image:: /_images/educator_how_tos/assign_role_button.png + :alt: The Assign Role button in the Roles and Permissions console + + This opens the Assign Role wizard. + +#. In **Step 1: Who and Role**, enter one or more usernames or email addresses, + separated by commas. Select the role to assign. + + .. image:: /_images/educator_how_tos/assign_role_step1_manage_roles.png + :alt: Step 1 of the Assign Role wizard, showing a text input for users and a role selector + + Users must have an existing account. If any entry does not match a user, + the input shows an error for that entry and blocks the flow until corrected. + +#. Select **Next**. If all users are valid, the wizard moves to Step 2. + +#. In **Step 2: Where It Applies**, select one or more courses to apply the + role to. Use the search bar or Organization filter to find a specific course. + + .. image:: /_images/educator_how_tos/assign_role_step2_manage_roles.png + :alt: Step 2 of the Assign Role wizard, showing a list of courses with checkboxes + + .. note:: + The courses and organizations available in this view reflect where the Course + Authoring feature is enabled by your site administrator. If a role assignment doesn't + seem to take effect, check with your site administrator. + +#. Select **Save**. After saving, the new role assignments appear in the Team + Members table and a confirmation message is shown. + +Remove a Role +************** + +Course Admins and global site admins can remove role assignments. + +#. In the Team Members tab, find the user whose role you want to remove and + select the option to open their audit view. + +#. In the user audit view, find the role assignment to remove and select + the option to remove the role assignment in the **Actions** column. + + .. image:: /_images/educator_how_tos/remove_role_icon.png + :alt: The remove-role control in the Actions column of the user audit view + +#. Review the confirmation message and select **Remove** to confirm, or + **Cancel** to keep the current assignment. + +.. note:: + A role assignment tied to a course where the Course Authoring flag is + disabled still appears in the Team Members table and the user audit + view. The option to remove it is unavailable, with a message explaining + why. + +.. note:: + + You cannot remove your own admin role. If you need to revoke your own + access, another user with the required permissions must do it. + + +.. seealso:: + + :ref:`Use Roles and Permissions Console` (how-to) + + :ref:`Guide to Course Team Roles` (reference) + + :ref:`Add Course Team Members` (how-to) + + :ref:`Add users to Libraries` (how-to) + + :ref:`Manage Course Beta Testing` (how-to) + + :ref:`Assign discussion roles ` (how-to) + + +**Maintenance chart** + ++--------------+-------------------------------+----------------+--------------------------------+ +| Review Date | Working Group Reviewer | Release |Test situation | ++--------------+-------------------------------+----------------+--------------------------------+ +| 2025-07-30 | eduNEXT | Verawood | Pass | ++--------------+-------------------------------+----------------+--------------------------------+ diff --git a/source/educators/how-tos/set_up_course/add_course_team_members.rst b/source/educators/how-tos/set_up_course/add_course_team_members.rst index 3fcf68aed..debc4b37d 100644 --- a/source/educators/how-tos/set_up_course/add_course_team_members.rst +++ b/source/educators/how-tos/set_up_course/add_course_team_members.rst @@ -84,11 +84,23 @@ To assign a privileged role to a course team member, follow these steps. To remove an assigned role, view the list of users and then select **Revoke access**. +.. note:: + For installations using the Roles and Permissions console: course team + management is available from :guilabel:`Settings` > :guilabel:`Roles and + Permissions` in Studio. See :ref:`Manage Course Authoring Roles` for the + Course Admin and Course Staff roles available there. + + The Roles and Permissions console (called the Administrative Console in + earlier releases) is not enabled by default and must be enabled by your site administrator. See + :ref:`Enabling RBAC in Verawood` for instructions on how to enable it. + .. seealso:: - + :ref:`Guide to Course Team Roles` (reference) - :ref:`Manage Course Beta Testing` (how-to) + :ref:`Manage Course Beta Testing` (how-to) + + :ref:`Manage Course Authoring Roles` (how-to) **Maintenance chart** @@ -96,6 +108,8 @@ access**. +--------------+-------------------------------+----------------+---------------------------------------------------------------+ | Review Date | Working Group Reviewer | Release |Test situation | +--------------+-------------------------------+----------------+---------------------------------------------------------------+ +| 2025-07-30 | eduNEXT | Verawood | Pass | ++--------------+-------------------------------+----------------+---------------------------------------------------------------+ | 03/19/2025 | John (Curricu.me) | Sumac | Pass | +--------------+-------------------------------+----------------+---------------------------------------------------------------+ | 03/07/2025 | Leira (Curricu.me) | Sumac | Fail (https://github.com/openedx/docs.openedx.org/issues/881) | diff --git a/source/educators/how-tos/use_roles_and_permissions_console.rst b/source/educators/how-tos/use_roles_and_permissions_console.rst new file mode 100644 index 000000000..91a8f1aa3 --- /dev/null +++ b/source/educators/how-tos/use_roles_and_permissions_console.rst @@ -0,0 +1,199 @@ +.. _Use Roles and Permissions Console: + +Use Roles and Permissions Console +###################################### + +.. tags:: educator, how-to + +The Roles and Permissions console is where you manage team access for courses +and libraries in Studio. This article describes the main areas of the console: +the Team Members tab, the Roles and Permissions tab, and the user audit view. + +.. note:: + This feature is not enabled by default, and must be enabled by your site administrator. See + :ref:`Enabling RBAC in Verawood` + for instructions on how to enable it. For more on what's included in this + release, see :ref:`Introducing More Granular Team Management`. + +.. contents:: + :local: + :depth: 2 + +Access the Console +****************** + +#. From the Studio home page, select **Roles and Permissions** in the top + right corner. This opens the Roles and Permissions console in a new + browser tab. + + .. image:: /_images/educator_how_tos/studio_home_roles_and_permissions_button.png + :alt: The Roles and Permissions button in the top right of the Studio home page + +When you open it from the Studio home page, all courses and libraries you +have access to are shown. When you open it from within a specific course or +library, the view is prefiltered to show only that course or library's team. +The console is always the same interface. + +Team Members Tab +***************** + +On the Team Members tab, you can see all users with a role assignment on the +courses and libraries you have access to. + + .. image:: /_images/educator_how_tos/team_members_tab.png + :alt: The Team Members tab showing a table with Name, Email, Organization, Scope, Role, and Actions columns + :width: 800 + :align: center + +The table has six columns: **Name**, **Email**, **Organization**, **Scope**, +**Role**, and **Actions**. Each row represents one role assignment. A user with +multiple assignments appears once per assignment. + +Your own account is identified with a "(me)" label next to your username. + +The table shows 10 rows per page. Use the previous and next arrows or the page +selector to navigate through results. + +.. note:: + The table only shows users with a role on the courses and libraries you + have access to. You may not see all users on your platform. + + Additionally, if the feature is not enabled for a specific course, the option to open the audit view is unavailable. + A message explains why. Please contact your site administrator to :ref:`enable the feature `. + +Search and Filters +================== + +You can search for users and narrow the list using three filters. + + .. image:: /_images/educator_how_tos/team_members_filters.png + :alt: The search bar and filter row above the team members table + +* The **search bar** filters by user name and email. + +* The **Organization** filter shows a list of organizations. You can search + within the filter to find a specific organization. Select one or more to + narrow results. + +* The **Role** filter lists all available roles, grouped by course and + library names. Select one or more roles to narrow results. + +* The **Scope** filter shows a list of courses and libraries. You can search + within the filter to find a specific course or library. Select one or more + to narrow results. + +Active filters show a count badge and appear as tags below the filter row. Select +the **X** on a tag to remove it, or use **Clear all filters** to reset the view. + +The Scope filter only lists courses and libraries you have access to. + +User Audit View +*************** + +You can view all role assignments for a specific user across the courses and +libraries you have access to. + +#. In the Team Members tab, select the option to view their role assignments + in the **Actions** column for the user you want to review. + + .. image:: /_images/educator_how_tos/team_members_action_icon.png + :alt: The action to open a user's role assignments, in the Actions column of the team members table + +The user audit view shows all role assignments for that user. The table has +the following columns: **Role**, **Organization**, **Scope**, and **Actions**. + +Each row represents one role assignment. Use the **Organization** and **Role** +filters to narrow the view. + +Select the **View All Permissions** control in any row to expand a list of all +permissions associated with that role, grouped by functional area. + + .. image:: /_images/educator_how_tos/user_audit_view.png + :alt: The user audit view showing role assignments for a single user + +.. note:: + The role assignments shown are limited to the courses and libraries you + have access to. If your access is limited to one course, you will only + see assignments related to that course. + +.. note:: + A role assignment tied to a course where the Course Authoring flag is + disabled still appears here. The option to remove it, if you have the + permissions, is unavailable, with a message explaining why. + +Roles and Permissions Tab +************************** + +The Roles and Permissions tab shows a permission matrix for course and library +roles. Use it to understand what each role allows before assigning it to a team +member. + + .. image:: /_images/educator_how_tos/roles_and_permissions_tab.png + :alt: The Roles and Permissions tab showing the permission matrix for course roles + :align: center + +Select **Course Roles** or **Library Roles** at the top of the tab to switch +between the two views. + +For course roles, the matrix columns are: **Course Admin** and **Course Staff**. +Each row represents a permission. A checkmark (✓) means the role has that +permission. An X means it does not. + +.. note:: + This list shows the permissions currently available in Authoring Studio. + Some roles may grant additional permissions managed outside this interface. + See :ref:`Guide to Course Team Roles` for full documentation. + +Assign a Role +************** + +The **Assign Role** button is available from any tab in the console. Selecting +it opens the Assign Role wizard. + + .. image:: /_images/educator_how_tos/assign_role_button.png + :alt: The Assign Role button in the Roles and Permissions console + +#. In **Step 1: Who and Role**, enter one or more usernames or email addresses, + separated by commas, and select the role to assign. Users must have an + existing account. If any entry does not match a user, the input shows an + error and blocks the flow until corrected. + + .. image:: /_images/educator_how_tos/assign_role_step1_console.png + :alt: Step 1 of the Assign Role wizard, showing user input and role selector + +#. Select **Next**. + +#. In **Step 2: Where It Applies**, select the courses or libraries to apply + the role to. + + .. image:: /_images/educator_how_tos/assign_role_step2_console.png + :alt: Step 2 of the Assign Role wizard, showing scope selection with org-level options + + If you have management permissions at the organization level, you also see + an **All courses in this organization** or **All libraries in this + organization** option. Selecting this assigns the role to every course or + library in that organization, including ones created in the future. + + .. note:: + The courses and organizations available here reflect where the Course + Authoring feature is actually enabled. If a role assignment doesn't + seem to take effect right away, check with your site operator — this + can happen briefly during a flag change. + +#. Select **Save**. The new role assignments appear in the Team Members table. + +.. seealso:: + + :ref:`Manage Course Authoring Roles` (how-to) + + :ref:`Add users to Libraries` (how-to) + + :ref:`Guide to Course Team Roles` (reference) + +**Maintenance chart** + ++--------------+-------------------------------+----------------+--------------------------------+ +| Review Date | Working Group Reviewer | Release |Test situation | ++--------------+-------------------------------+----------------+--------------------------------+ +| 2025-07-30 | eduNEXT | Verawood | Pass | ++--------------+-------------------------------+----------------+--------------------------------+ diff --git a/source/educators/navigation/creating_course.rst b/source/educators/navigation/creating_course.rst index bfb0650a5..c22e9627a 100644 --- a/source/educators/navigation/creating_course.rst +++ b/source/educators/navigation/creating_course.rst @@ -86,11 +86,13 @@ Add Course Team Members .. toctree:: :maxdepth: 1 - :glob: + :glob: ../references/course_development/course_team_roles.rst ../how-tos/set_up_course/add_course_team_members.rst ../how-tos/releasing-course/manage_beta_testing.rst + ../how-tos/course_development/manage_course_authoring_roles.rst + ../how-tos/use_roles_and_permissions_console.rst Configure Grades ******************************************************* diff --git a/source/educators/references/course_development/course_team_roles.rst b/source/educators/references/course_development/course_team_roles.rst index 318115057..6058be38c 100644 --- a/source/educators/references/course_development/course_team_roles.rst +++ b/source/educators/references/course_development/course_team_roles.rst @@ -118,23 +118,65 @@ Course data researchers can access the Data Download tab on the instructor dashb Course data researchers can: -* :ref:`View and dowload learner data ` +* :ref:`View and download learner data ` * :ref:`View Anonymized Learner IDs` * :ref:`View Certificate Data` * :ref:`View Learners Not Yet Enrolled` +.. _New System Course Authoring Roles: -.. seealso:: +*********************************************************************** +Course Authoring Roles Under the New Roles and Permissions System +*********************************************************************** + +.. note:: + These roles are available when your platform has enabled Course + Authoring — an opt-in feature disabled by default. + This must be enabled by your site administrator. See :ref:`Enabling RBAC in Verawood` + for instructions on how to enable it. The legacy Staff and Admin roles + remain available on platforms that have not yet enabled this feature. + +Course Admin and Course Staff are the new system's equivalents of the legacy +Admin and Staff roles for Studio authoring: same responsibilities, new +assignment mechanism. The day-to-day experience in Studio is unchanged — +these roles carry the same capabilities, just under new names and managed +through the Roles and Permissions console. + +Existing role assignments require migration to take effect in the new system. +New role assignments share the behavior of their legacy counterparts across the +full platform, not only in Studio. + +============= +Course Admin +============= + +Course Admins have full authoring access and can manage the course team. +They can do everything a Course Staff member can do, and can also add, +remove, and change roles for team members in the Roles and Permissions console. + +============= +Course Staff +============= + +Course Staff members can operate the full course lifecycle in Studio, including +publishing content, editing schedules, managing advanced settings, and importing +and exporting course content. + +.. seealso:: :ref:`Add Course Team Members` (how-to) - :ref:`Manage Course Beta Testing` (how-to) + :ref:`Manage Course Beta Testing` (how-to) + + :ref:`Manage Course Authoring Roles` (how-to) **Maintenance chart** +--------------+-------------------------------+----------------+------------------------------------------------------------------+ | Review Date | Working Group Reviewer | Release |Test situation | +--------------+-------------------------------+----------------+------------------------------------------------------------------+ +| 2025-07-30 | eduNEXT | Verawood | Pass | ++--------------+-------------------------------+----------------+------------------------------------------------------------------+ | 2025-04-13 | sarina | Sumac | Pass | +--------------+-------------------------------+----------------+------------------------------------------------------------------+ | 2025-03-07 | Docs WG | Sumac | `Fail `_ |