Skip to content

Users and roles

Administrators only.

Users (Użytkownicy) shows each person’s photo (or their drawn initials), name, email, roles as badges and the date the email was verified. Search by name or email, filter by role, sort by name, email or verification date. Created (Utworzono) is hidden until you switch it on.

The Deleted (Usunięte) filter hides deleted accounts by default. Switch it over to see them: a deleted account survives as an anonymous record so that the trail of who was granted which course still points somewhere.

Row actions: Edit, View the site as this person (Zobacz stronę jako ta osoba), Delete account (Usuń konto) and Export data (Eksportuj dane).

  1. Click Create (Utwórz).
  2. Fill in Name (Imię i nazwisko) and Email (Adres e-mail).
  3. Password (Hasło) is optional. Leave it empty and HiLMS emails the person a link to set their own — which is usually what you want, and what the console and the API do too. Type one only if you have a reason to hand it over yourself.
  4. Choose one or more Roles (Role). Only an administrator sees this field; an account somebody else creates is a student, and an administrator gives it a role afterwards.
  5. Where the site speaks more than one language, choose the Language (Język) this person reads in — the language of the site and of the mail they receive. They can change it themselves at any time.
  6. Optionally set Email verified (E-mail potwierdzony); leaving it empty means the person must verify by email.
  7. Fill in the Profile (Profil) section: a photo, and whatever profile fields the roles you ticked bring with them. Tick “instructor” and the instructor’s fields appear as you do it.
  8. Save.

Open a row or click Edit (Edytuj). Change any field; leave the password empty to keep the current one. Roles take effect immediately, including panel access.

Hiding a profile field — by taking a role away for an afternoon — never erases what the person had written in it.

The sidebar of the user editor has a section called Zarządzanie kontem: the things this person could do for themselves at /account, for when they cannot. Each one asks first, tells you what happened, and only appears when it would actually do something.

Control Does
Wyślij link do ustawienia hasła Emails a signed link, valid seven days, with which they set a password. It stops working the moment the password changes
Wyślij ponownie potwierdzenie adresu Sends the verification email again
Zresetuj drugi składnik Turns two-factor authentication off, so they can sign in with the password alone and set up a new device
Usuń wszystkie klucze dostępu Removes every passkey; they add new ones themselves
Odłącz dostawcę Disconnects a Google or Facebook login. Refused while it is their only way in
Eksportuj dane Builds their personal data archive and emails the link to them, not to you
Zobacz stronę jako ta osoba Impersonation — see below

Every one of these is written into the audit trail under its own name.

Zobacz stronę jako ta osoba signs you in as that person until you come back. A banner stays above the header for as long as it lasts, with a link back to your own account.

Two things to know before you use it:

  • It is a way down, never across: only administrators may impersonate, and another administrator cannot be impersonated.
  • Everything you do is recorded as that person. The audit trail cannot tell it apart from something they did themselves. Look; try not to touch.

Usuń konto, on the row or at the bottom of the editor’s sidebar, deletes the account immediately and for good. The person’s name, email, photo, passkeys and connected logins go; what stays is an anonymous record of which courses the account was granted and when, because that is the history behind a purchase.

HiLMS never hard-deletes a user and offers no bulk delete here. The last administrator account is refused, and you cannot delete yourself from the list.

The person receives one email telling them the account was deleted.

Ustawienia → Role i uprawnienia (Settings → Roles and permissions) lists the roles. Open one to tick or untick permissions per entity. Each entity only offers the actions it really has: a course can be restored, an entitlement cannot be deleted at all, a quiz attempt can only be read.

The defaults after installation:

  • Redaktor: everything on categories, courses, sections, lessons, pages, menus and the media library; grant, extend and revoke course access; use the AI assistants.
  • Prowadzący: the view permissions of the catalogue and of the three student tables, every one narrowed to the courses they are named on, and the media library — narrowed to their own uploads and the files their courses use (The media library).
  • Uczestnik: nothing in the panel.
  • Administrator: ignores permissions entirely and always has full access.

API clients, the audit trail and the monitoring tools are given to nobody but the administrator, though the list offers them so you can delegate.

If you give a role the users’ permissions — support staff who reset two-factor or resend a verification email, say — that role still cannot touch an administrator: it can neither open an administrator’s account, nor use the account controls on it, nor delete it, and it is never offered the administrator role to hand out. Only an administrator acts on an administrator, because whoever may change an address and a password could otherwise take over the account that holds every permission.

Only an administrator opens this page or changes anybody’s roles. The four built-in roles can be neither renamed nor deleted, you cannot take the administrator role off your own account, and the last administrator can never lose it — so no ticking or unticking here can leave the site without somebody who holds every permission. Changes apply the next time the person loads a page.

Ustawienia → Pola profilu decides what each role is asked for. See Administration.

HiLMS is MIT-licensed. No replicants were harmed in the writing of these books.