Skip to main content

Role mapper

The role mapper is a Studo Flow feature that allows you to map roles and permissions from your existing system to Studo Flow. This can be LDAP roles, SAML roles, or any other role that is provided by the configured login provider. Roles can be also imported by the data importers, to reuse existing roles from your campus management system.

How roles are assigned

  • Roles are imported per organization from your campus management system.
  • Every course belongs to exactly one organization, and an organization can have several managers.
  • Studo Flow itself treats organizations as flat (there is no organization hierarchy inside Flow). If your campus management system organizes organizations hierarchically, the importer copies a role assigned on a parent organization down to all of its child organizations, so it effectively applies to them as well.

Changes you make in the role mapper apply to roles imported from your campus management system, and take effect at its next data synchronization.

Roles

The following roles can be mapped. Each role grants a specific set of permissions in Studo Flow.

Some roles build on others: Admin includes every permission, and the Exemption manager, Exemption commenter, Presence rate course manager and Student lifecycle manager roles each also grant all Organization manager permissions for the organizations they apply to.

RoleWhat it allows
AdminFull access to every student, course, organization and setting. Includes every permission that all other roles provide.
Organization managerCan manage the students of their organization(s), and has lecturer-level access to every course that belongs to those organizations (in addition to any course where the user is personally a lecturer).
Exemption managerCan review, approve and reject exemption requests from students in their organization(s). Also has all Organization manager permissions for those organizations.
Exemption commenterCan review exemption requests and add internal notes (not visible to students), but cannot approve or reject them. Also has all Organization manager permissions for their organization(s).
Presence rate course managerCan change the required attendance rate for courses in their organization(s). Also has all Organization manager permissions for those organizations.
Student lifecycle managerCan edit the "Attendance List Student Lifecycle" settings and manage (create, edit and delete) semesters. Also has all Organization manager permissions for their organization(s).
Groups managerCan change a course's maximum group size and its group registration time window.
MS Teams course managerCan change the Microsoft Teams synchronization settings of a course. This is a system-wide capability; on its own it does not grant access to any course, so it is typically combined with a role that does (Organization manager, or being a lecturer).
MS Teams organization managerIs automatically added as an owner to the Microsoft Teams teams of the courses in their organization(s) (when the Microsoft Teams module is enabled). Does not grant access to students or courses in Studo Flow.
Survey analytics managerCan access survey analytics through the HTML modules API.
NFC tag managerCan add, edit and delete NFC tags.
Door managerCan add, edit and delete doors.
Student with reduced minimal presence rateA student role that grants no administrative permissions, but lowers the student's required attendance rate (by the configured reduction).
Student with automatic attendance request approvalA student whose attendance requests are approved automatically, when the course has this option enabled.

Role hierarchy

The diagram below shows how the administrative roles inherit permissions from each other. An arrow means "inherits the permissions of". The two student roles (Student with reduced minimal presence rate and Student with automatic attendance request approval) are standalone behaviors that are not part of this permission inheritance — see the table above.