Getting started · How-to guide
Organizations
Understand organization roles and resource permissions.
Organizations are the top-level entity that groups users together. Each organization can have multiple members with different roles that determine what actions they can perform. This documentation covers the roles, permissions, and options involved with organizations.
Key Concepts
- Organization: A group or team that contains members and resources like courses, learners, and collections.
- Member: A user who belongs to an organization with an assigned role.
- Role: Defines what actions a member can perform within the organization.
Roles
Kokobi project access defines four roles: Owner, Admin, Support, and Member. Owner and Admin have full project access, Support can impersonate learners for support purposes, and Member has read access to the core organization resources.
1. Member (Default)
The Member role is designed for regular users who need to view organization content but don't require administrative privileges.
Most organization members should have the Member role.
2. Admin
The Admin role has comprehensive permissions to manage all resources within the organization, except for certain owner-only privileges.
Only give the Admin role to trusted individuals who need full control over resources and organization settings.
3. Owner
The Owner role has complete control over the organization with all administrative permissions plus ownership-specific capabilities.
The Owner role is given to the creator of the organization.
4. Support
The Support role is narrowly scoped to learner impersonation for troubleshooting and assistance.
Project Permission Matrix
The live matrix below is derived directly from Kokobi's project access configuration. It covers the Owner, Admin, Support, and Member roles, along with the maximum permissions available to user and organization API keys.
These project permissions protect Kokobi resources and API operations. Centralized Better Auth organization permissions, such as organization membership and role administration, are a separate authorization layer and are not represented in this matrix.
Role grants
| Resource | Action | Owner | Admin | Support | Member |
|---|---|---|---|---|---|
Folderfolder | Readread | Allowed | Allowed | Not allowed | Allowed |
Folderfolder | Createcreate | Allowed | Allowed | Not allowed | Not allowed |
Folderfolder | Updateupdate | Allowed | Allowed | Not allowed | Not allowed |
Folderfolder | Deletedelete | Allowed | Allowed | Not allowed | Not allowed |
Coursecourse | Readread | Allowed | Allowed | Not allowed | Allowed |
Coursecourse | Createcreate | Allowed | Allowed | Not allowed | Not allowed |
Coursecourse | Shareshare | Allowed | Allowed | Not allowed | Not allowed |
Coursecourse | Updateupdate | Allowed | Allowed | Not allowed | Not allowed |
Coursecourse | Archivearchive | Allowed | Allowed | Not allowed | Not allowed |
Coursecourse | Deletedelete | Allowed | Allowed | Not allowed | Not allowed |
Collectioncollection | Readread | Allowed | Allowed | Not allowed | Allowed |
Collectioncollection | Createcreate | Allowed | Allowed | Not allowed | Not allowed |
Collectioncollection | Shareshare | Allowed | Allowed | Not allowed | Not allowed |
Collectioncollection | Updateupdate | Allowed | Allowed | Not allowed | Not allowed |
Collectioncollection | Archivearchive | Allowed | Allowed | Not allowed | Not allowed |
Collectioncollection | Deletedelete | Allowed | Allowed | Not allowed | Not allowed |
Learnerlearner | Readread | Allowed | Allowed | Not allowed | Allowed |
Learnerlearner | Createcreate | Allowed | Allowed | Not allowed | Not allowed |
Learnerlearner | Updateupdate | Allowed | Allowed | Not allowed | Not allowed |
Learnerlearner | Deletedelete | Allowed | Allowed | Not allowed | Not allowed |
Learnerlearner | Impersonateimpersonate | Allowed | Allowed | Allowed | Not allowed |
Webhookwebhook | Readread | Allowed | Allowed | Not allowed | Allowed |
Webhookwebhook | Createcreate | Allowed | Allowed | Not allowed | Not allowed |
Webhookwebhook | Updateupdate | Allowed | Allowed | Not allowed | Not allowed |
Webhookwebhook | Deletedelete | Allowed | Allowed | Not allowed | Not allowed |
Organizationorganization | Readread | Allowed | Allowed | Not allowed | Allowed |
Organizationorganization | Updateupdate | Allowed | Allowed | Not allowed | Not allowed |
Domaindomain | Readread | Allowed | Allowed | Not allowed | Not allowed |
Domaindomain | Createcreate | Allowed | Allowed | Not allowed | Not allowed |
Domaindomain | Deletedelete | Allowed | Allowed | Not allowed | Not allowed |
API-key assignable permissions
| Resource | Action | User key | Organization key |
|---|---|---|---|
Folderfolder | Readread | Not allowed | Allowed |
Folderfolder | Createcreate | Not allowed | Allowed |
Folderfolder | Updateupdate | Not allowed | Allowed |
Folderfolder | Deletedelete | Not allowed | Allowed |
Coursecourse | Readread | Not allowed | Allowed |
Coursecourse | Createcreate | Not allowed | Allowed |
Coursecourse | Shareshare | Not allowed | Allowed |
Coursecourse | Updateupdate | Not allowed | Allowed |
Coursecourse | Archivearchive | Not allowed | Allowed |
Coursecourse | Deletedelete | Not allowed | Allowed |
Collectioncollection | Readread | Not allowed | Allowed |
Collectioncollection | Createcreate | Not allowed | Allowed |
Collectioncollection | Shareshare | Not allowed | Allowed |
Collectioncollection | Updateupdate | Not allowed | Allowed |
Collectioncollection | Archivearchive | Not allowed | Allowed |
Collectioncollection | Deletedelete | Not allowed | Allowed |
Learnerlearner | Readread | Not allowed | Allowed |
Learnerlearner | Createcreate | Not allowed | Allowed |
Learnerlearner | Updateupdate | Not allowed | Allowed |
Learnerlearner | Deletedelete | Not allowed | Allowed |
Learnerlearner | Impersonateimpersonate | Not allowed | Not allowed |
Webhookwebhook | Readread | Not allowed | Allowed |
Webhookwebhook | Createcreate | Not allowed | Allowed |
Webhookwebhook | Updateupdate | Not allowed | Allowed |
Webhookwebhook | Deletedelete | Not allowed | Allowed |
Organizationorganization | Readread | Not allowed | Allowed |
Organizationorganization | Updateupdate | Not allowed | Not allowed |
Domaindomain | Readread | Not allowed | Allowed |
Domaindomain | Createcreate | Not allowed | Allowed |
Domaindomain | Deletedelete | Not allowed | Allowed |