---
title: Permissions
url: 'https://manuals.remository.com/userpoints/permissions'
markdown: 'https://manuals.remository.com/userpoints/permissions.md'
date: '2026-10-06'
description: "UserPoints uses Joomla's standard Access Control List (ACL) system. Permissions are configured in Components → UserPoints → Configuration → Permissions. Each permission can be set to Inherited, Allowed, or Denied for any Joomla user group. Permissions set at the component level override the global …"
taxonomy:
  category:
    - docs
---

[](#) [ edit this page](https://github.com/getgrav/grav-skeleton-rtfm-site/blob/develop/pages/12.permissions/docs.md) 

# Permissions

UserPoints uses Joomla's standard Access Control List (ACL) system. Permissions are configured in **Components → UserPoints → Configuration → Permissions**.

Each permission can be set to **Inherited**, **Allowed**, or **Denied** for any Joomla user group. Permissions set at the component level override the global Joomla defaults, and a **Denied** setting always wins over an **Allowed** setting from a parent group.

---

## Standard Joomla Permissions

These two permissions are shared across all Joomla extensions:

| Permission | What it controls |
|---|---|
| Configure (core.admin) | Full access to all UserPoints backend functions, including configuration. Grant only to trusted administrators. |
| Access Administration Interface (core.manage) | Access to the UserPoints administrator backend. Users with this permission can see the component in the backend but are further restricted by the permissions below. |

---

## UserPoints-Specific Permissions

### Content Management

| Permission | What it controls |
|---|---|
| Rules (core.rules) | Create, edit, publish, and delete point rules. |
| Users (core.users) | View and edit user point balances, run sync and recalculate. |
| Activity (core.activity) | View, approve, combine, and archive activity records. |
| Invitation Templates (core.templatesinvite) | Create and edit invitation email templates. |
| Categories (core.categories) | Manage rule categories. |
| Plugins (core.plugins) | View the installed plugins list. |

### Bulk Operations

| Permission | What it controls |
|---|---|
| User Sync (core.usersynch) | Run the user synchronisation tool. |
| Recalculate (core.recalculate) | Recalculate all user point balances from the activity log. |
| Set Max Points (core.setmaxpoints) | Set per-user maximum point ceilings. |
| Reset All Points (core.resetallpoints) | Reset every user's balance to zero. Grant with care — this is irreversible. |
| Purge Expired Points (core.purgeexpiredpoints) | Delete activity records past their expiry date. |
| Combine Activities (core.combineactivities) | Merge multiple activity records into summary records. |
| Auto-Detect Plugins (core.autodetectplugins) | Scan installed plugins and create missing rule definitions. |

### Monetisation

| Permission | What it controls |
|---|---|
| Coupon Codes (core.couponcodes) | Create, edit, and delete coupon codes. |
| Raffles (core.raffles) | Create and manage raffles, draw winners. |

### Reporting and Export

| Permission | What it controls |
|---|---|
| View Statistics (core.viewstats) | Access the Statistics admin pages. |
| Export Active Users (core.exportactiveusers) | Download the active users CSV export. |
| Export Emails (core.exportemails) | Download the email address CSV export. |
| Report System (core.reportsystem) | Run the system diagnostics report. |

### Recognition

| Permission | What it controls |
|---|---|
| Level Rank (core.levelrank) | Create and manage ranks, medals, and levels. |

---

## Recommended Permission Setups

### Typical site with a single administrator group

Grant **core.admin** to the Super Users group and **core.manage** plus all specific permissions to the Administrator group. Leave all other groups at **Inherited** (which defaults to Denied for component-level permissions).

### Site with a community manager role

Create a custom Joomla user group (e.g. "Points Manager") and grant:

- `core.manage` — backend access
- `core.users` — view and adjust balances
- `core.activity` — view and approve activities
- `core.couponcodes` — create promotions
- `core.viewstats` — view reports

Do not grant `core.admin`, `core.resetallpoints`, or `core.exportemails` to this group.

### Read-only reporting role

Grant only `core.manage` and `core.viewstats`. The user can log in to the backend and view statistics but cannot modify any data.

---

## Applying Changes

After saving permission changes, Joomla rebuilds the ACL immediately. Affected users will see the updated permissions on their next page load or after logging out and back in.

 [ ](https://manuals.remository.com/userpoints/modules) [](https://manuals.remository.com/userpoints/taking-payments-for-user-points)

---

## Navigation

- Previous: [Modules](https://manuals.remository.com/userpoints/modules.md)
- Next: [Taking Payments for User Points](https://manuals.remository.com/userpoints/taking-payments-for-user-points.md)
