Role mapper
The role mapper maps roles and permissions from an institution's existing system to Flow. These roles are provided by the configured data importers, allowing Flow to reuse roles from the campus management system.
How roles are assigned
- Roles are imported per organisation from your campus management system.
- Every course belongs to exactly one organisation, and an organisation can have several managers.
- Flow itself treats organisations as flat; there is no organisation hierarchy inside Flow. If your campus management system organises organisations hierarchically, the importer copies a role assigned to a parent organisation to all of its child organisations, so it effectively applies to them as well.
Changes made in the role mapper apply to roles imported from the campus management system and take effect with the next data synchronisation.
Roles
The following roles can be mapped. Each role grants a specific set of permissions in Flow.
Some roles build on others: Admin includes every permission, and the Exemption manager, Exemption commenter, Presence rate course manager and Student lifecycle manager roles each also grant all Organization manager permissions for the organisations they apply to.
| Role | What it allows |
|---|---|
| Admin | Full access to every student, course, organisation and setting. Includes every permission that all other roles provide. |
| Organization manager | Can manage the students of their organisation(s), and has lecturer-level access to every course that belongs to those organisations (in addition to any course where the user is personally a lecturer). |
| Exemption manager | Can review, approve and reject exemption requests from students in their organisation(s). Also has all Organization manager permissions for those organisations. |
| Exemption commenter | Can review exemption requests and add internal notes (not visible to students), but cannot approve or reject them. Also has all Organization manager permissions for their organisation(s). |
| Presence rate course manager | Can change the required attendance rate for courses in their organisation(s). Also has all Organization manager permissions for those organisations. |
| Student lifecycle manager | Can edit the "Attendance List Student Lifecycle" settings and manage (create, edit and delete) semesters. Also has all Organization manager permissions for their organisation(s). |
| Groups manager | Can change a course's maximum group size and its group registration time window. |
| MS Teams course manager | Can change the Microsoft Teams synchronisation settings of a course. This is a system-wide capability; on its own it does not grant access to any course, so it is typically combined with a role that does (Organization manager, or being a lecturer). |
| MS Teams organization manager | Is automatically added as an owner to the Microsoft Teams teams of the courses in their organisation(s) when the Microsoft Teams module is enabled. Does not grant access to students or courses in Flow. |
| Survey analytics manager | Can access survey analytics through the HTML modules API. |
| NFC tag manager | Can add, edit and delete NFC tags. |
| Door manager | Can add, edit and delete doors. |
| Student with reduced minimal presence rate | A student role that grants no administrative permissions, but lowers the student's required attendance rate (by the configured reduction). |
| Student with automatic attendance request approval | A student whose attendance requests are approved automatically, when the course has this option enabled. |
Role hierarchy
The diagram below shows how the administrative roles inherit permissions from each other. An arrow means "inherits the permissions of". The two student roles (Student with reduced minimal presence rate and Student with automatic attendance request approval) are standalone behaviours that are not part of this permission inheritance — see the table above.