Avada Online Course
Settings
Permissions

What each permission unlocks

When you create an MCP key you tick permissions in two groups: Read access — what the assistant may look at — and Actions — what it may change. This page lists what each one actually gives it.

Untick a permission and the matching ability does not exist for that assistant: it never sees the tool, so it never tries and never asks. Nothing here can be worked around from the assistant's side — the app checks every request on its own.

👀 Read access

Four permissions, one per area of the app.

PermissionThe assistant canTools it gets
DashboardSee course, student and enrollment counts, completion rate, and your top coursesget_dashboard_stats
CourseList courses and open one in full — title, description, visibility, enrollment trigger, thumbnail, certificate — and read its modules, lessons and quizzeslist_courses · get_course · list_modules · list_lessons · get_lesson
Student 👤List students, open one record, and see their enrollments and lesson progresslist_students · get_student
SettingRead your app settings: general, appearance, student access, email notifications, and portal translationsget_settings · get_translations

👤 = gives the assistant access to student names, emails and progress. This carries the Student data badge in the Create key dialog.

✍️ Actions

Twelve permissions, grouped the way the app's own edit screens are — so an assistant allowed to write lessons cannot quietly delete a course.

Course

PermissionThe assistant can changeTools
Create courseCreate a new course with title, description and contentcreate_course
Edit courseTitle, description, auto-enrollment product, access and visibility, featured image, enrollment trigger, publish statusupdate_course
Manage certificateTurn a course certificate on, and set its template, logo and colorsmanage_certificate
Create moduleAdd, rename, delete or reorder a modulecreate_module · update_module · reorder_modules
Create & edit lessonsCreate and edit lessons — title, status, free-preview setting, and content blocks (video, text, quiz)create_lesson · update_lesson · reorder_lessons
Delete module / lessonPermanently remove a module or a lessondelete_module · delete_lesson
Delete coursePermanently remove a coursedelete_course
⚠️

Delete course and Delete module / lesson are permanent — there is no undo and no bin to restore from. Grant them only to an assistant you would trust with the delete button itself.

Student

PermissionThe assistant can changeTool
Add student 👤Enroll a new student into a course, the same as the Students list doesadd_student

Setting

PermissionThe assistant can changeTools
Edit GeneralThe app display nameupdate_settings_general
Edit AppearanceCourse Player logo, primary color, and page labelsupdate_settings_appearance
Edit NotificationsWhich lifecycle events send an email, the template content, and sending a testupdate_settings_notifications · update_notification_template · send_test_email
Edit TranslationStorefront, course and certificate player stringsupdate_translation

Send a test email can only send to the sender address configured in your own Mail Notifications settings. An assistant cannot point it at someone else's inbox, so the permission cannot be turned into a way to mail your customers.

🔒 What no permission unlocks

Some things can never be done by an assistant, whatever you tick:

  • Deleting a student, changing an enrollment, or resetting progress. An assistant can add a student; taking access away stays in your hands.
  • Your plan, quota and storage. Read-only, always.
  • Store timezone and language, and the auto-revoke-on-refund switch. These change how every course behaves, so they are not writable over MCP at all.
  • Anything not listed above. Settings are read then merged field by field: a field the app does not expose is dropped, not written.

If an assistant sends a field it may not write, the app ignores that field and tells the assistant which ones it dropped — so it cannot report a change that never happened.

Choosing well

  • Start from what you actually want to ask. "How many students finished the onboarding course?" needs Dashboard and Course read, nothing else.
  • Grant Actions one row at a time. An assistant that only writes lesson content needs Create & edit lessons, not the whole Course group.
  • Leave the two delete permissions off unless you have a reason. Everything else is recoverable by editing; those two are not.
  • Prefer a separate key per assistant, so revoking one does not disturb the others.
  • You can change permissions later with the pencil icon — it takes effect immediately, with no reconnecting. Assistants that signed in through your admin are the exception: their permissions were fixed on the approval screen, so change them by connecting again.
Products
Avada SEO SuiteAvada AEO OptimizerAvada AI Blog BuilderAvada Product CopyAvada Images & Page Speed UpAvada Shipping LabelsAvada Backups & Restore
Resources
DocumentationSEO Suite DocsBlog DocsSpeed DocsShipping Labels DocsBackups & Restore Docs
Company
Avada GroupPrivacy Policy
© 2026 Avada Group. All rights reserved.