TrainGrid User Guide

Functions: Users, Roles & Permissions

This area covers everyone who signs in to run TrainGrid — inviting staff users, deciding what each role is allowed to do, tailoring permissions with — step-by-step function reference.


This area covers everyone who signs in to run TrainGrid — inviting staff users, deciding what each role is allowed to do, tailoring permissions with toggles and custom roles, and the two administrative records that prove what happened: the Audit log and the Email log. Use it when you onboard a teammate, restrict or expand what a role can do, or need an immutable trail for an auditor. All of it lives in the sidebar under Organization → Administration, spread across the Users, Permissions, Audit log and Email log pills of the admin navigation.

In this section: Invite a user · The five built-in roles · Turn a capability off for a built-in role · Create a custom role · Edit a user (role, locations, name, sign-in email) · Manage pending invitations (copy link, resend, revoke) · Deactivate or reactivate a user's login · Remove a user · Transfer ownership · Send a password reset · Employee portal access roster · View and export the audit log · View the email log

Invite a user

Creates a personal invite link that lets a teammate create an account (or sign in) and join your organization with a chosen role and, optionally, a limited set of locations they can see.

Where: Sidebar → Administration → Users → "Invite user" button (top right of the page header)  ·  Before you start: Administrator or Manager (the Users page requires the manage-members permission). The Administrator role itself cannot be granted at invite time — invite the person at a lower role, then promote them via Edit user.

OptionWhat it does
EmailThe address the invitation is for; required. The account they create or sign in with must use this address.
RoleThe role they will join as: Manager, Training Coordinator (default), Supervisor, or Viewer (auditor). Administrator is deliberately not offered at invite time.
Location scope (optional)Checkboxes, one per active location. Leave all unchecked (default) for access to all locations; check some to restrict the user to only those locations' employees, assignments and reports.
  1. In the sidebar, open "Administration", then click the "Users" pill.
  2. Click "Invite user". A dialog titled "Invite a user" opens; it explains: "Creates an invite link you can send them. It expires in 7 days."
  3. Type the person's address in "Email".
  4. Open the "Role" dropdown and pick one of: Manager, Training Coordinator, Supervisor, Viewer (auditor). The default is Training Coordinator, and a one-line description of the selected role appears under the dropdown.
  5. Optionally, under "Location scope (optional)", tick the locations they should be limited to. The helper text confirms your choice: "No locations checked — they'll see all locations." or "They'll only see N location(s)."
  6. Click "Create invite".
  7. The dialog switches to "Invitation ready" and shows the personal link. Click the copy button ("Copy invite link") and send the link to the person yourself — the invitation email is also sent automatically where email is configured.
  8. Click "Done" (or "Invite another" to send more). Success: the invitation now appears in the "Pending invitations" section of the Users page, showing its role, location scope and "Expires" date.
Good to know:
  • Every invite link expires in 7 days. After that the "Pending invitations" row shows an "Expired" badge and the link stops working — use "Resend" to issue a fresh one.
  • The person sets their own name and password on the invite-accept page; no password is ever assigned or emailed.
  • Invitations count toward the plan's seat limit alongside active users.
  • Invitation creation and acceptance are recorded in the Audit log (actions "Invite" and "Invite accepted").

The five built-in roles

TrainGrid ships five fixed role tiers that act as the security floor — every permission decision starts from one of them, and the tiers are enforced in the database, not just the interface.

Where: Sidebar → Administration → Permissions (page title "Roles & permissions") — the "Built-in roles" grid shows exactly what each role holds

OptionWhat it does
Administrator"Full control, including billing and organization ownership." Holds every capability, including the three Administrator-only deletes (employees, courses, records) and Billing. Cannot be restricted.
Manager"Manages the whole workspace — everything except billing." Manages users, organization settings, employees, courses, assignments, completions, competency, email, exports, audit log and email log. Cannot permanently delete employees, courses or records.
Training Coordinator"Manage employees, courses, assignments, completions and reports." Also imports/archives employees, imports courses, assesses competency, emails employees, exports data and views the audit log. No user management, no email log, no deletes.
Supervisor"View and record training completions for their assigned location(s)." Records completions, assesses competency and exports data — typically combined with a location scope.
Viewer (auditor)"Read-only access for audits and inspections." Can export data and view the audit log; changes nothing.
  1. In the sidebar, open "Administration" and click the "Permissions" pill.
  2. Scroll to the "Built-in roles" grid. Columns are: Capability, Administrator (with a lock icon — always full, never editable), Manager, Training Coordinator, Supervisor, Viewer (auditor).
  3. Read a row: a switch means the role holds that capability (and you may turn it off); a dash means the role never has it. Success: you can see, per role, exactly which of the 15 capabilities it carries.
Good to know:
  • Governance permissions are fixed and never configurable, to prevent lockout: managing the organization and users = Administrator + Manager; billing = Administrator only; reports are visible to every role.
  • Permanent deletes (employees, courses, records) are Administrator-only by design — the grid shows them as dashes for every other role, so no toggle can grant them.
  • An organization can have multiple Administrators, but it can never lose its last active one — the database blocks removing, demoting or deactivating the only remaining Administrator.
  • In this product, "Administrator" is the ownership tier and "Manager" is the admin tier — the words on screen are always Administrator and Manager.

Turn a capability off for a built-in role

Restricts what a built-in role can do organization-wide — for example, making Training Coordinators read-only or hiding the email log from Managers. Toggles can only restrict within a role's tier, never grant beyond it.

Where: Sidebar → Administration → Permissions → "Built-in roles" grid  ·  Before you start: Administrator or Manager (manage-organization permission).

OptionWhat it does
Manage employeesAdd and edit employee records. Default on for Manager and Training Coordinator.
Import employeesBulk-import employees from a spreadsheet (needs Manage employees). Default on for Manager and Training Coordinator.
Archive employeesArchive and restore employees (needs Manage employees). Default on for Manager and Training Coordinator.
Delete employeesPermanently delete employees with no training records (needs Manage employees). Administrator only — a dash for every other role.
Manage coursesCreate and edit the course catalog. Default on for Manager and Training Coordinator.
Import coursesBulk-import courses from a spreadsheet (needs Manage courses). Default on for Manager and Training Coordinator.
Delete coursesPermanently delete courses (needs Manage courses). Administrator only.
Assign & scheduleAssign training, waive and reschedule. Default on for Manager and Training Coordinator.
Record completionsMark training complete (bulk and per-cell). Default on for Manager, Training Coordinator and Supervisor.
Assess competencyRecord competency assessment outcomes on completed training (needs Record completions). Default on for Manager, Training Coordinator and Supervisor.
Delete recordsPermanently delete assignment records. Administrator only.
Email employeesSend ad-hoc email messages to selected employees. Default on for Manager and Training Coordinator.
Export dataDownload CSVs and printable reports. Default on for every role.
View audit logSee the immutable change history. Default on for Manager, Training Coordinator and Viewer (auditor).
View email logSee the record of every email the organization has sent. Default on for Manager only (plus Administrator).
  1. In the sidebar, open "Administration" and click the "Permissions" pill.
  2. In the "Built-in roles" grid, find the row for the capability (e.g. "Record completions") and the column for the role (e.g. Supervisor).
  3. Click the switch to turn it off. Repeat for any other role/capability pairs — nothing saves yet.
  4. Click "Save changes" (use "Reset" to discard unsaved edits). Success: the toast "Role permissions updated." appears, and every user holding that role immediately loses the capability — the related buttons and pages disappear for them, and the database refuses the underlying writes.
Good to know:
  • Turning off a parent capability also disables its indented children: switching off Manage employees disables Import/Archive/Delete employees; Manage courses gates Import/Delete courses; Record completions gates Assess competency.
  • The Administrator column is always fully on and shows a lock — it cannot be edited.
  • The footer states the contract: "Toggles only restrict within a role — they can't grant access a role doesn't have. Enforced on the server, not just the interface."
  • Restrictions apply to everyone holding the role, and also cap any custom role built on that base tier's users indirectly (a custom role reads its own restriction map, but the base tier remains the enforced ceiling).

Create a custom role

Builds a named, reusable role (e.g. "Shift Lead") based on one of the four non-Administrator tiers, with selected capabilities switched off. Use it when several people need the same tailored permission set without editing the built-in roles for everyone.

Where: Sidebar → Administration → Permissions → "New role" button (top of the page, above "Built-in roles")  ·  Before you start: Administrator or Manager.

OptionWhat it does
Role nameDisplay name shown on user rows and pickers; up to 60 characters; required.
Base tierThe built-in tier the role is capped by — Manager, Training Coordinator (default), Supervisor or Viewer (auditor). Cannot be changed after creation (it would alter the security of everyone already assigned the role).
CapabilitiesOne switch per capability the base tier holds, all on by default; "n/a" marks capabilities outside the tier. You can only switch OFF — a custom role never exceeds its base tier.
  1. In the sidebar, open "Administration" and click the "Permissions" pill.
  2. Click "New role". A dialog titled "New custom role" opens: "Pick a base tier (its security ceiling) and switch off any capabilities this role shouldn't have."
  3. Type a "Role name" (e.g. "Shift Lead").
  4. Pick the "Base tier": Manager, Training Coordinator (default), Supervisor, or Viewer (auditor). The tier's description appears below the dropdown.
  5. Under "Capabilities", switch off anything this role should not have. Capabilities the base tier never holds show "n/a" instead of a switch — pick a higher tier if you need one of those.
  6. Click "Create role". Success: toast "Role \"<name>\" created." — the role now lists at the top of the Permissions page (showing "Based on <tier> · N capabilities restricted" or "· full tier access") and appears under "Custom roles" in every user's role picker.
Good to know:
  • A custom role is restrictive only: its base tier is the enforced security ceiling, in the database as well as the interface.
  • Administrator cannot be a base tier — it is reserved and always full.
  • Editing a role later (pencil icon) can change its name and capability switches, but never its base tier.
  • Deleting a role (trash icon → "Delete role") reverts everyone assigned to it to the default permissions of its base tier; this cannot be undone.
  • Custom roles can also be selected as alert audiences under Administration → Alerts.

Edit a user (role, locations, name, sign-in email)

One dialog changes everything about a user: their role (built-in or custom), which locations they can see, and — for an Administrator — their display name and sign-in email. Nothing saves until you press Save changes.

Where: Sidebar → Administration → Users → "Edit" button on the user's row (also in the row's ⋯ menu as "Edit user")  ·  Before you start: Administrator or Manager. Only an Administrator can grant/revoke the Administrator role or change a user's name and sign-in email. You cannot edit your own row.

OptionWhat it does
NameThe user's display name (Administrator-only field; up to 120 characters).
Sign-in emailThe address they log in with (Administrator-only). Takes effect immediately; their password is unchanged, and the previous address is notified of the change.
RoleAdministrator, Manager, Training Coordinator, Supervisor, Viewer (auditor), or any custom role. The Administrator option is only grantable by an Administrator.
Location scopePer-location checkboxes; unchecked everywhere = All locations. Scoped users only see employees, assignments and reports for the checked locations.
Quick-select a divisionOne button per division (with its location count) that checks/unchecks all of that division's locations at once; you can still fine-tune individual locations below.
  1. In the sidebar, open "Administration" and click the "Users" pill.
  2. On the user's row, click "Edit". The dialog "Edit user — <name>" opens; everything in it is a draft.
  3. (Administrator only) Change "Name" and/or "Sign-in email". Changing the email shows: "They'll sign in with the new address from now on. Their password stays the same."
  4. Open the "Role" dropdown and pick a built-in role or, under the "Custom roles" group, a custom role.
  5. Under "Location scope", tick the locations they may see, or use the "Quick-select a division" buttons to check a whole division's locations at once. Leave everything unchecked for "All locations"; the line below confirms "Currently: all locations." or "Currently: N of M locations."
  6. Click "Save changes" (Cancel or the X discards the draft).
  7. If you are promoting someone to Administrator, a confirmation appears — "Make <name> an Administrator?" — click "Make Administrator" to proceed. Success: toast "<name>'s settings were saved." (with "— they are now <role>." when the role changed).
Good to know:
  • You cannot change your own role — ask another Administrator or Manager.
  • A Manager cannot edit an Administrator's role, nor grant the Administrator tier.
  • Granting Administrator always shows a confirmation dialog, and the change is recorded in the audit log.
  • A partial failure keeps the dialog open with your draft intact so the failed part can be corrected.

The Pending invitations table tracks every invite that has not been accepted, so you can re-share a link, reissue an expired one, or cancel an invite that should never be used.

Where: Sidebar → Administration → Users → "Pending invitations" section (below the users table)  ·  Before you start: Administrator or Manager.

  1. In the sidebar, open "Administration" and click the "Users" pill, then scroll to "Pending invitations".
  2. Read the row: Email, Role, Location scope, and "Expires" (an "Expired" badge appears once the 7 days have passed).
  3. To re-share a live invite: click "Copy link" — toast "Invite link copied to clipboard."
  4. To reissue an expired invite: click "Resend" — a fresh link is generated and copied; toast "New invite link for <email> copied."
  5. To cancel an invite: click the X on the row, then confirm "Revoke invitation" in the dialog ("The invite link they received will stop working immediately. You can always send a new one."). Success: toast "Invitation for <email> revoked." and the row disappears.
Good to know:
  • "Copy link" shows only on unexpired invitations; "Resend" replaces it once the invite has expired.
  • Accepted invitations leave this table automatically — the person appears in the users table above instead.
  • Revoking is immediate and safe to redo — send a new invitation any time.

Deactivate or reactivate a user's login

Temporarily blocks a user from signing in — for a leave of absence or a departure under review — without deleting their role, location scope or history. Reactivation restores access instantly, with no re-invite.

Where: Sidebar → Administration → Users → ⋯ menu on the user's row → "Deactivate login" / "Reactivate login"  ·  Before you start: Administrator or Manager. Only an Administrator can deactivate another Administrator; the last active Administrator can never be deactivated.

  1. In the sidebar, open "Administration" and click the "Users" pill.
  2. Click the ⋯ button on the user's row ("More actions for <name>").
  3. Choose "Deactivate login".
  4. In the dialog "Deactivate <name>'s login?" — "They will be signed out and can no longer access this organization, but their role, location scope and history are kept. You can reactivate them at any time — no re-invite needed." — click "Deactivate login".
  5. Success: toast "<name>'s login was deactivated." and a red "Deactivated" badge appears beside their name. To restore access later, open the same ⋯ menu and choose "Reactivate login" — toast "<name>'s login was reactivated."
Good to know:
  • Deactivation signs the user out immediately; nothing about their record is lost.
  • Reactivation is one click — no new invitation is required.

Remove a user

Permanently removes a user's membership from the organization. Their access ends immediately, but the training records they created are kept, and they can be invited again later.

Where: Sidebar → Administration → Users → ⋯ menu on the user's row → "Remove from organization"  ·  Before you start: Administrator or Manager. Only an Administrator can remove another Administrator; the organization's only Administrator cannot be removed.

  1. In the sidebar, open "Administration" and click the "Users" pill.
  2. Click the ⋯ button on the user's row and choose "Remove from organization".
  3. In the dialog "Remove <name>?" — "They will immediately lose access to this organization. Training records they created are kept. You can invite them again later." — click "Remove user".
  4. Success: toast "<name> was removed from the organization." and the row disappears from the users table.
Good to know:
  • This removes membership, not history — audit entries and training records created by the user remain, attributed to them.
  • If they hold the only Administrator seat, promote someone else to Administrator first (the system refuses otherwise: "This member is the organization's only Administrator. Promote another member to Administrator first.").
  • You cannot remove yourself — the ⋯ menu is hidden on your own row.

Transfer ownership

Hands your Administrator seat to another user in one step: they become an Administrator with full control (including billing) and you are demoted to Manager. Use when the primary account owner changes.

Where: Sidebar → Administration → Users → ⋯ menu on the target user's row → "Transfer ownership"  ·  Before you start: Administrator only, on an active non-Administrator user.

  1. In the sidebar, open "Administration" and click the "Users" pill.
  2. Click the ⋯ button on the row of the person receiving ownership and choose "Transfer ownership".
  3. In the dialog "Transfer ownership to <name>?" — "<name> will become an Administrator with full control, and you will be demoted to Manager. Only an Administrator can transfer ownership back. This is recorded in the audit log." — click "Transfer ownership".
  4. Success: toast "<name> is now an Administrator. You are now a Manager." — your own row now shows Manager, theirs Administrator.
Good to know:
  • The alternative to a full transfer is simply granting the Administrator role via Edit user — an organization can have several Administrators; Transfer ownership is the swap that also demotes you.
  • The transfer is recorded in the audit log.
  • The option is hidden for deactivated users and users who are already Administrators.

Send a password reset

Emails a user a password-reset link so they can regain access without you ever seeing or setting a password.

Where: Sidebar → Administration → Users → ⋯ menu on the user's row → "Send password reset"  ·  Before you start: Administrator or Manager; the user must have a sign-in email on file.

  1. In the sidebar, open "Administration" and click the "Users" pill.
  2. Click the ⋯ button on the user's row and choose "Send password reset".
  3. Success: toast "Password reset email sent to <email>." — the user follows the emailed link to choose a new password.
Good to know:
  • Passwords are never visible or assignable by an admin — reset links are the only recovery path.

Employee portal access roster

Shows every employee who has been invited to, or has activated, the read-only employee portal — a login that shows only their own training record. Portal users are not staff users, so this roster is the only place that answers "who has registered?" at a glance.

Where: Sidebar → Administration → Users → "Employee portal access" section (below Pending invitations)  ·  Before you start: Administrator or Manager to open the Users page; the Manage employees permission is additionally required to see pending/expired portal invitations (without it, only activated users are listed and a note explains why).

  1. In the sidebar, open "Administration" and click the "Users" pill.
  2. Scroll past "Pending invitations" to the "Employee portal access" heading. The note under it answers the password question: "Employees who have registered to view their own training record. Portal users set their own password when they activate their invitation — passwords are never stored in a viewable form."
  3. Read the table — columns Employee, Employee #, Email, Status, Invited. Status badges: "Active" (with "Activated <date>"), "Invited" (with "Expires <date>"), "Expired" (with "Expired <date>"). Rows sort active-first, most recent activity first.
  4. For a lapsed or pending invite, click "Re-invite" (expired) or "Manage invite" (invited) — either opens the employee's profile, where the "Invite to portal" action lives.
  5. Success: you can tell for any employee whether they are active on the portal, still invited, or need re-inviting — and jump straight to the profile to act.
Good to know:
  • The roster is deliberately read-only: sending or re-sending a portal invitation happens on the employee's profile ("Invite to portal"), not here.
  • Portal users never appear in the staff users table — they hold a read-only view of their own record only.
  • No password is ever assigned: the invitation link takes the employee to a page where they choose their own password.
  • Clicking an employee's name opens their profile.

View and export the audit log

The audit log is the immutable, append-only record of every change in the organization — who did what, to which record, when, with the before and after values. It is your evidence trail for audits and for answering "who changed this?".

Where: Sidebar → Administration → Audit log  ·  Before you start: View audit log capability — by default Administrator, Manager, Training Coordinator and Viewer (auditor).

OptionWhat it does
ActionFilter to one action: Create, Update, Delete, Archive, Unarchive, Complete, Supersede, Waive, Import, Invite, Invite accepted. Default "Any action".
EntityFilter to one record type: API key, Assignment, Course, Course category, Course group, Custom field, Department, Division, Employee, HR connection, Invitation, Location, User, Organization, Position, Task type, Webhook. Default "Any entity".
From / ToCalendar-date bounds on when the change happened; either side optional.
  1. In the sidebar, open "Administration" and click the "Audit log" pill. The header reads "Immutable record of every change in <organization>" with the total entry count.
  2. Narrow the list with the filter bar: pick an "Action", an "Entity", and/or a "From"/"To" date. The table updates immediately; "Clear filters" resets everything.
  3. Read the columns: Timestamp (org timezone), Actor, Action (colour-coded badge), Entity, Record (hover a record name to see its ID).
  4. Click any row (or its eye button, "View change detail") to open the detail dialog — it names the actor, exact timestamp and record, and shows the before/after values of the change.
  5. To export, click the export button above the filters; a CSV named audit-log downloads with columns Timestamp, Actor, Action, Entity, Record, Record ID, Before, After. Success: the file matches the on-screen filters exactly; if more than 5,000 entries match, a warning notes only the most recent 5,000 were exported — narrow the date range for earlier slices.
Good to know:
  • The log is append-only — entries can never be edited or deleted, by anyone.
  • Entries record automatically: "Every create, update, delete, completion and waive will be recorded here automatically." User-management events (invites, role changes, ownership transfers) are included.
  • Pages show 50 entries; the pager appears above and below the table.
  • Timestamps display and export in the organization's timezone.
  • CSV export caps at the most recent 5,000 matching entries per download.

View the email log

A per-organization record of every email TrainGrid has sent on your behalf — invitations, alert digests, reports and more — with delivery status, so you can prove a notification went out or diagnose one that failed.

Where: Sidebar → Administration → Email log  ·  Before you start: View email log capability — by default Administrator and Manager only (toggleable for Manager in the Permissions grid).

Set up (one time):

  1. Optionally set how long entries are kept: Sidebar → Administration → Settings → "Keep email log for" — choose 30, 60, 90 or 180 days (default 90). The change saves immediately; older entries are then removed automatically. Delivery itself is unaffected — this only controls how long the record is retained.
OptionWhat it does
TypeFilter to one email kind: Alert, Scheduled report, Member invite, Portal invite, Sign-in change, Email employees, Contact form, Signup notice, Trial onboarding, Test send. Default "Any type".
StatusSent or Failed. Default "Any status".
From / ToCalendar-date bounds, interpreted in the organization's timezone.
Keep email log for (Settings)Retention window: 30, 60, 90 (default) or 180 days; older entries purge automatically.
  1. In the sidebar, open "Administration" and click the "Email log" pill. The header reads "Every email <organization> has sent — invitations, alerts, reports and more" with the recorded count.
  2. Narrow the list with the filter bar: "Type", "Status", and "From"/"To" dates.
  3. Read the columns: Sent (org-timezone timestamp), Type, Recipient, Subject, Status. Success: you can see per-recipient whether each email was Sent or Failed (failed rows carry the error).
Good to know:
  • Access is capability-gated: without View email log the page redirects away rather than rendering empty.
  • Pages show 50 entries with a pager top and bottom.
  • The log records the send attempt and outcome — it does not store the email body.