Skip to Content
AdministrationPermissions

Permissions

Lumieos implements a role-based access control (RBAC) approach to security and permissions. All permissions are dependent on the roles and assignments given to a user. This page describes the full permissions model across the platform.


1. Region/Partner Permissions

Lumieos maintains role-based access control with permission levels set per user by region staff. Each user is assigned one of the following roles.

Role NamePermissions
Primary AdministratorFull access to every season and function. Can invite and manage Administrators and Partner Representatives.
AdministratorThe same full access as a Primary Administrator, but cannot alter Primary Administrators, and manages Partner Representatives only when the region has delegated that.
Partner RepresentativeAccess is limited to the permission sets assigned to them (see breakdown below); each set covers chosen regions and programs.

Primary Administrators and Administrators are functionally the same — both see every season and every function. They differ only in who they may assign. Partner Representatives can have reduced permissions and reduced visibility: they only see the seasons covered by a permission set.

Permission Breakdown

Permissions are inherited — a user with “Manage” permission also has “View” and “Contact” for the same area.

Warning: The PII option is separate from general access permissions. Enabling PII allows the user to see personally identifiable information from Lumieos. Without it, only first name and last initial are shown.

NameOptionsPII Restriction?
TeamsNo Permissions / Can View / Can Contact / Can Manage (team status, Tableau reports, etc.)Yes
VolunteersNo Permissions / Can View / Can Contact / Can Manage (volunteer status, screening, etc.)Yes
EventsNo Permissions / Can View / Can Contact / Can Manage (events, edit details, full event host and event day access)N/A

Note: Users with “View” permissions can be separately added host management permissions for an event on a per-event basis.

Managing Users (Users & Permissions tab)

Regions manage their own administrator accounts from Configuration → Users & Permissions. The rule is simple: you can only invite and manage roles below your own.

Your roleYou can invite/manage
Innovalda staffPrimary Administrators (and below, though this is normally left to the region)
Primary AdministratorAdministrators and Partner Representatives
AdministratorPartner Representatives — only when the region has enabled “Administrators may manage representatives”
Partner RepresentativeNobody — the Configuration area is closed to representatives entirely, so they do not see the user list at all

Additional safeguards:

  • New users are added by email and must already have a Lumieos account.
  • You cannot change or remove your own access.
  • A region always keeps at least one Primary Administrator — the last one cannot be demoted or removed.
  • The “Administrators may manage representatives” setting can only be changed by a Primary Administrator.
  • Every change is recorded in the region’s audit trail.
  • All changes require a verified (two-factor) session.

Setting a Partner Representative’s permissions

Administrators need no setup — they have everything. When you add a user as a Partner Representative, or change an existing user’s role to it, the same dialog expands to show the representative’s permissions:

  • Account grants — four switches that apply across the whole region: Impersonate user payments (open a user’s commerce pages as them; exposes any PII in the commerce module), Manage commerce (process invoices and payments), Manage learning (edit learning modules), and Manage sponsorship codes (create, deactivate and download batches of single-use sponsorship codes). Administrators always hold all four. Manage commerce, Manage learning and Manage sponsorship codes work on their own — an accountant, a training coordinator or a sponsorship contact needs no permission set at all — and the list shows a Commerce, Learning or Sponsorship codes marker for such grant-only representatives. Impersonate user payments starts from the team list, so it has no effect until a permission set grants at least Can View on Teams.

    Note: Manage sponsorship codes is deliberately not implied by Manage commerce. Someone who runs your sponsorship programme can be given the codes and nothing else; give them both if they also handle invoices.

  • Permission sets — each set names the regions and programs it covers, then the Teams / Volunteers / Events levels from the breakdown above, the two PII checkboxes, and Manage season. Add as many sets as the representative needs. Each region and program combination can only be covered by one set; the dialog tells you which pair is already covered if two sets overlap.

A representative with no permission sets and neither manage grant cannot see anything in Region Management. The list shows a No access marker next to any representative in that state, and the dialog warns before you save.

Changing a representative to Administrator leaves their permission sets in place but stops using them; they apply again if the user is later changed back to a representative.


2. Event Host Permissions

Permissions are inherited. Each user is assigned per event, so permissions can change between events.

NameOptions
View TeamsCheckbox — view team list and simple roster info (first name, last initial — PII safe)
VolunteersNo Permissions / Can View / Can Contact / Can Manage
CommunicationsNo Permissions / Can View / Can Contact / Can Manage (broadcasts, chat rooms). Checkbox: Attachments — allow uploads

Event Day Access for Hosts

Event hosts are not automatically granted event day access. Access must be manually granted per event, and Event Day must be enabled with specific interfaces activated.

Inherited Permissions

  • Region/Partner staff with “Manage” Event permission automatically gain all event host and event day permissions (if event day is enabled).
  • Users with other permission levels can be granted additional permissions per event.
  • Permissions are additive — granting lower permissions at the event host level has no impact if the region/partner level is higher.

3. Event Day Permissions

Event Day must first be enabled per event, and the appropriate interfaces must be turned on.

Important: Granting permission to an interface on an event where that interface is not enabled will have no effect.

Interfaces

Each interface is toggled independently via checkboxes:

  • Pit Admin — Team check-in, volunteer check-in, practice tables
  • Score Display — Faster score updates than the public website
  • Queuing — Team check-in for scheduled activities
  • Referee — Pick a table and submit match scores
  • Head Referee — All Referee abilities plus edit past scores, publish/unpublish, mark replays, and HR notes
  • Score Entry — Scorekeeper interface with match timer, scoresheets, and edit past scores
  • Game Announcer — Follows upcoming matches with team demographics and profiles
  • Judge — Enter rubrics and scripts once enabled by Judge Advisor
  • Judge Advisor — Judging plus judge advisor interface (awards, scripts, advancement, GP notes)

Permission Sources

  • Partner/Region Staff with “Manage” Event: Full access to all enabled interfaces.
  • Event Hosts: Can be granted any interface as part of their assignment.
  • Volunteers: If using Lumieos for volunteer management, each role can be configured with Event Day access.

Access Timeframe

  • Users (except Region/Partner staff with “Manage”) can only access Event Day the day before and the day of an event.
  • Region/Partner staff with “Manage” can access Event Day at any point until the end of the season.

Ephemeral/Tokenized Logins

Users can create tokenized logins for temporary access to event day interfaces. Tokens are assigned individual permissions, limited by number of uses, and sessions are revocable. Tokens are only active during normal access times.

  • Partner/Region Staff with “Manage” can create tokens for any interface.
  • Event Hosts can only create tokens for permissions they currently hold.
  • Volunteers can only create tokens for permissions granted via roles that have “Create Ephemeral Logins” enabled.

4. Volunteer Permissions

To be determined.


5. Team Permissions

Team access is all-or-nothing in the current version. If a user is granted access by any method, they receive full team access.

Permission Sources

  • Partner/Region Staff with “Manage” Team: Can impersonate teams via the Team List.
  • Team Contacts: Invited via automated Tableau invites. Removal requires manual action.
  • For regions using the Invited Coaches feature, invited coaches receive the same access as Tableau coaches.

Note: Lumieos ties the roster list to permissions — if a user is on the roster, they have access.

Warning: By design, Lumieos does not automatically remove coaches who are no longer listed on Tableau reports. Manual removal is required.

Last updated on