Tutor AI plugin permissions
The following table summarises the main permissions used by the Tutor AI plugin and their default role assignments.
| Name | Description | Default roles |
|---|---|---|
local/dttutor:use | Use Tutor AI inside a course (open the chat and interact with it). | Manager, Editing teacher, Teacher, Student |
moodle/course:update (Moodle core) | Open the course manager (More → AI Tutor Management) and enable or pause the tutor in a course. | Manager, Editing teacher (Moodle default) |
local/dttutor:use
Allows users to use Tutor AI inside a course.
- Context: course (
CONTEXT_COURSE) - Capability type: read
- Archetypes with the capability by default: manager, editingteacher, teacher, student
With this permission, a user can:
- See the Tutor AI floating avatar button (when Tutor AI is enabled and available in that context).
- Open the chat drawer.
- Send messages and receive responses.
Note: If Tutor AI is enabled but a user does not see the chat in a course, the first permission to verify is
local/dttutor:usefor that user’s role in that course.
moodle/course:update
Tutor AI does not define its own management capability. The course manager page (local/dttutor/manage.php), its entry in the course More menu and the web service local_dttutor_save_course_config all require the Moodle core capability moodle/course:update in the course context. By default this is granted to managers and editing teachers.
No service account
Since version 2.0.9, Tutor AI does not use a service account and does not call Moodle web services. It answers only from the course knowledge pre-loaded for the user who is chatting, filtered to what that user can see. Every chat request is checked on the server: the user must be enrolled in the course, hold local/dttutor:use there, and the tutor must be enabled for the site and for the course.
If you upgraded from an earlier version:
- The old service account
tutoriabot_datacursowas unenrolled from every course and suspended. It is kept so old logs still resolve; you can delete it. - The
moodle/course:viewgrant that version 2.0.6 gave to the Teacher and Editing teacher archetypes at system level was removed. local/dttutor:useis no longer given to the Authenticated user role. If your site relied on it, assign the capability to the roles that need it in the course.