Permissions in the eLLM Admin Console

By Paul Flanders ·

The article explains how administrators can manage user permissions in the eLLM Admin Console, detailing how to grant or revoke capabilities for groups. It covers features like document uploads, access tags, and personal tool connections.

What this product is for

Not everyone should be able to do everything. Some staff should upload documents; others should only ask questions. The permissions page lets you grant specific capabilities to groups, so people get exactly the access they need, no more, no less.

Main features

  • Grant or revoke capabilities per group.
  • A small, clear set of capabilities covering uploads, context, tags, and personal tools.
  • Changes that apply the next time affected users sign in.

How to use it

Granting a capability

  • Open the Permissions page in the admin console.
  • Find the group you want to change.
  • Turn on the capabilities that group should have, and turn off any it should not.

The available capabilities

Capability What it allows
Upload documents Add documents to the library so the assistant can answer from them.
Set system context  Edit the company context that shapes how answers are written.
Manage access tags Create, rename, and apply the tags that control which groups can see a document.
Ingest web URLs Add sources to the library from a web link, in the Web sources tab on the documents page. This is separate from the organisation-wide internet search, so a group can add web sources without web search being on for everyone.
Manage personal MCP Let users connect their own private tool services in their settings.

Common tasks

  • Let a team add documents: grant upload documents to their group.
  • Allow a team to tag documents for access control: grant manage access tags.
  • Let a team add web pages as sources: grant ingest web URLs.
  • Let power users connect their own tools: grant manage personal MCP.
  • Tighten access: revoke a capability a group no longer needs.

Things to know

  • Capabilities are granted to groups, not to individuals. A user gets a capability through the groups they belong to.
  • Changes take effect the next time an affected user signs in, so a user may need to log out and back in.
  • These capabilities are separate from group membership itself, which is managed in your identity system. Membership decides who is in a group; permissions decide what that group can do.
  • Reaching the admin console is controlled by the admin group, which is separate from these fine-grained capabilities.

Troubleshooting

  • A user still can't do something after I granted it: ask them to sign out and back in, since changes apply at next login.
  • I granted it to the wrong place: capabilities attach to groups, so make sure the user is actually in the group you changed.
  • A user needs admin console access: that is controlled by membership of the admin group in your identity system, not by these capabilities.

Frequently asked questions

Can I give a capability to one person only?

Not directly. Capabilities are granted to groups. Put the person in a group that has the capability.

Why hasn't a change taken effect?

Capability changes apply at the user's next sign-in. Ask them to log out and back in.

What is the difference between a capability and being in the admin group?

The admin group grants access to the admin console. Capabilities are finer-grained abilities within the main app, like uploading documents.

Where do I create the groups themselves?

Groups and membership live in your identity system. See the Permissions, users and groups article.

Summary

The permissions page is where administrators decide what each group can do: upload documents, set company context, manage access tags, and connect personal tools. Capabilities attach to groups and take effect at next login, giving you clear, group-based control over who can do what in eLLM.

Need assistance navigating the complexities of eLLM? EssingtonITS offers expert guidance and tailored IT solutions to help you succeed. Visit EssingtonITS.co.uk for comprehensive support.

person people found this useful.

Related

Knowledge base 10 Jun 2026

Personal Notebook in eLLM

The personal notebook in eLLM allows users to organise and store notes, images, and files in a private, searchable timeline. It ensures privacy by keeping contents visible only to the user, and it can be integrated with the assistant for personalised answers.

Knowledge base 9 Jun 2026

Git Commands Quick Reference Guide

This quick reference guide covers essential Git commands for repository setup, staging, branching, merging, and working with remote repositories, making it a handy tool for developers to streamline their workflow.

Knowledge base 9 Jun 2026

Organisation Skills in the eLLM Admin Console

The article explains how the eLLM Admin Console allows organisations to create and manage shared instruction sets called "organisation skills" to ensure consistent responses across teams. These skills can be customised, restricted to specific groups, and integrated with extern…

Expand 29 Jul 2026

How AI can support pupils with SEND

Explore how AI tools are aiding pupils with special educational needs and disabilities by simplifying text, breaking down tasks, and enhancing accessibility. Learn about the considerations schools should make before implementation.

Expand 29 Jul 2026

AI policy and practice in further education

Further education colleges need distinct AI policies due to their unique mix of vocational courses, diverse age groups, and specific funding and inspection requirements. This guidance highlights the importance of tailored AI approaches in FE settings.