Skip to content

Capabilities

Three capabilities, all defined at system level, all given to managers when the plugin is installed.

CapabilityAllows
local/loop:manageCreate, edit and delete certifications and editions; import and export the configuration; edit the notices; import the notification texts; activate the licence; reach the settings page
local/loop:viewreportsThe Home dashboard, certification history, message logs, mail queue and reports sent
local/loop:viewuserstatusThe user status pages, which name individual people and their compliance state

Grant them from Site administration → Users → Permissions → Define roles.

What each one opens

A link to a page the current user cannot open is not rendered at all, rather than shown and refused. Somebody holding only local/loop:viewuserstatus sees the user status page without the menu around it.

The per-certification tab strip follows the same rule: Details, Editions and Messages need manage; User status needs viewuserstatus; History needs viewreports.

A useful split

A compliance officer who must read everything but change nothing gets viewreports and viewuserstatus, and not manage. They keep every dashboard, log and export, and cannot alter a setting or a notice.

What the capabilities do not gate

Two things are governed by the licence rather than by capabilities: creating and editing certifications and editions, and the sending of notices. Somebody with manage on a site whose licence has lapsed can still read and export everything, but not change the configuration. See What the licence covers.

Reading compliance data raises no event: what reaches the site log is a decision somebody took — creating a certification, rewriting a notice, activating a licence — and not a page somebody opened.