Menu Close
  • References
  • Pricing
Close
  • References
  • Pricing
+49 89 3090 839 30

Contact

Made in Germany · ISO 27001 · GDPR-compliant

SoftDeCC LMS's Flexible Roles and Permissions Model

The granular role- and permission-based model ensures that each user group has access to exactly the functions and information it needs to perform its tasks. This allows you to combine data protection, data segregation, and efficient administration—without rigid permission structures or ongoing IT adjustments.

With configurable role profiles, SoftDeCC flexibly adapts to your organizational structure—from learners and trainers to HR, managers, and external partners.

Standardized Roles

Secure Access Rights

Flexible Customization

Definition

A Secure Roles and Permissions Framework with SoftDeCC LMS

A role- and permission-based model (also known as role-based access control, RBAC) defines which user groups in the LMS are permitted to view, edit, or manage specific data. It serves as the technical and organizational foundation for ensuring that data protection requirements are met and that each user group has access only to the functions relevant to them.

Without a granular permissions model, a common dilemma arises: Either all users have too much access (data protection risk, lack of clarity), or the assignment of permissions is so rigid that every organizational change requires an IT request. SoftDeCC solves this with configurable role profiles that can be adapted to the organizational structure without any programming.

Data Security

Access & Function Rights

Typical Roles in the LMS and Their Permissions

Role profiles can be freely combined in SoftDeCC and expanded to include custom intermediate levels—such as a "Regional Training Coordinator" role with access only to data from their own region.

RoleTypical Permissions
LearnersAccess to assigned courses, tracking their own progress, viewing their own certificates, and booking courses via self-service
InstructorManage your own courses and schedules; view participant progress in your own courses; track attendance
Training AdministratorFull access to the course catalog, resource planning,
ManagerAggregated progress and compliance status of their own team; approval of training requests
HR/Staff DevelopmentCross-Location Reporting, Competency Matrices, Budget Overview
External Partners/CustomersLimited access via a separate learning portal; no access to internal data
System AdministratorFull access to system configuration, role management, and interfaces

An enterprise LMS must be able to scale with the complexity of a large organization. SoftDeCC LMS supports this scalability through automation, integration, and clear process structures.

The Importance of Role and Permission Models

Why Granular Permission Assignment Is More Than Just a Convenience Feature

Privacy and the GDPR

Personal learning data—test results, attendance records, and competency profiles—may only be accessed by authorized individuals. A granular access control policy is part of data protection compliance.

GDPR-compliant training →

Multi-Instance & Data Separation

When there are multiple locations, subsidiaries, or external training partners, the permissions model prevents data from being visible across organizational boundaries—even within the same technical platform.

Multi-Instance LMS →

Auditability

It must be clearly documented who received or modified which authorization and when—this is relevant for audits in regulated industries.

Compliance and Security →

External Audiences

By analyzing each format, the in-person component can be focused on content that benefits from group interaction.

Extended Enterprise →

Example

The Role Concept in Practice

An international company with plants in three countries is implementing SoftDeCC. The roles are assigned as follows:

1

Learners at each location can see only their own courses and certificates.


2

Site managers can view the aggregated compliance status of their facility, but not the individual test results for specific employees.


3

Central Training Administration manages the global course catalog, while local training coordinators are only allowed to create courses for their own location.


4

External supplier training is conducted through a separate learning portal with no access whatsoever to internal employee data.

This model is created in SoftDeCC by combining standard roles with organization-specific access levels—without any custom programming.

Checklist

Establish a Roles and Permissions Framework

Have all relevant user groups been identified (internal, external, management, administration)?

Is it defined for each role which data they can view and which they are allowed to edit?

Are external audiences (partners, customers) separated from internal data via a separate portal?

Can the training administration make role changes on its own without creating an IT ticket?

Is the assignment of rights automatically linked to the HR system when an employee changes locations or departments?

Are changes to permissions logged, and are they auditable?


Get More Information for Free Now

Ready for flexible role and permission models?

Contact us for a free consultation and discover how your learning data, access, and features can be organized securely and efficiently.

Over 25 Years of Expertise

Made in Germany

Frequently Asked Questions

FAQs: Roles and Permissions in the LMS

What is a roles and permissions model in an LMS?

A system of defined user roles that determines who is authorized to view, edit, or manage which data and functions in the LMS—the foundation for data protection compliance and intuitive system use.

What standard roles are available in SoftDeCC?

Learners, trainers, training administrators, managers, HR/talent development staff, external partners, and system administrators—each with their own authorization profile, which can be freely combined and expanded.

How are external partners or customers separated from the internal system?

Through separate, standalone learning portals with their own branding and a limited set of features—without access to internal employee data or organizational structures.

Can rollers be adjusted without programming?

Yes. Role profiles can be customized and combined in SoftDeCC using the configuration interface—including for organization-specific intermediate levels such as regional coordinator roles.

How does the concept of rights relate to the GDPR?

A granular permissions model is a key technical measure for implementing the data protection principle of access minimization: Only those who need the data to perform their tasks are granted access. Details: GDPR-compliant LMS → Link.

What happens to access rights when an employee changes departments?

When the HR system is integrated, role changes are automatically applied as soon as the HR master data changes—without any manual intervention by IT.