ExamNovaDocumentation
Offline readyChangelog
Least privilege

Roles and permissions

Give each person the smallest role, institute membership, and action permissions needed for a real responsibility.

Platform ownerInstitute administrator
Who does thisPlatform or institute administrator
Before you startJob responsibilities and institute boundaries are understood
Successful outcomeUsers can complete assigned work without receiving unrelated sensitive access
Role and permission handoffWork moves from platform owner to assessment staff, students, reviewers, and result consumers.OwnerAdminAuthorStudentMarkerModeratorPublisher
Role and permission handoff. Work moves from platform owner to assessment staff, students, reviewers, and result consumers.

What this means in plain language

A role is a convenient set of permissions. The server still checks the active institute, specific action permission, record ownership, and current state before allowing sensitive work.

Step-by-step

  1. List the real responsibilities for the job before choosing a role.
  2. Start with the nearest standard role and add only justified action permissions.
  3. Confirm institute membership and scope separately from the role name.
  4. Test with a non-administrator account, including direct URLs and downloads.
  5. Document temporary access and remove it after the exam cycle.
  6. Review administrator, evidence, export, billing, update, and integration permissions regularly.
ExamNova role index
Live seeded-demo screen. Administrators review available job-based roles.
ExamNova role editor
Live seeded-demo screen. Permissions are selected for a defined responsibility.
ExamNova permission glossary
Live seeded-demo screen. Action permissions explain the server-side boundary.

How to know it worked

Common mistakes

  • Using Super Admin to solve every missing permission.
  • Treating sidebar visibility as authorization.
  • Giving students, guardians, or teaching staff billing and update access.

If something goes wrong

  • Compare the route’s required permission with the user’s effective permission set.
  • Confirm the active institute and pivot membership.
  • Check record ownership and state when the permission alone appears correct.
Privacy and security: Permissions controlling results, evidence, exports, documents, integrations, and user administration require especially careful review.

What to do next

Apply the same least-privilege approach while configuring global and institute settings.