# Prevent staff to create courses for different organizations

**URL:** <https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447>\
**Category:** Authoring\
**Created:** [June 16, 2023, 1:34pm UTC](https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447 "2023-06-16T13:34:07Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![mcan](https://avatars.discourse-cdn.com/v4/letter/m/b38774/32.png) [@mcan](https://discuss.openedx.org/u/mcan)\
**Post date:** [June 16, 2023, 1:34pm UTC](https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447/1 "2023-06-16T13:34:07Z")

</div>

I want to assign staff users to one or more organizations. Thanks to [this](https://discuss.openedx.org/t/staff-admin-member-by-organization/7345/8) thread, I can access to courses which belongs to specific organization(s) as staff. But, when I want to create a course, those staffs still can create courses for any organization. Is there a way to prevent this and allow course creation for only selected organization(s). Thanks in advance!

---

<div class="post-metadata">

**Author:** ![jill](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.openedx.org/jill/32/3188_2.png) [@jill](https://discuss.openedx.org/u/jill)\
**Post date:** [June 18, 2023, 11:44pm UTC](https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447/2 "2023-06-18T23:44:52Z")

</div>

Hi @mcan 🙂

You need to enable the `FEATURES['ENABLE_CREATOR_GROUP']` flag (instructions for how to enable feature flags in Tutor are here: [How to set ENABLE\_COURSEWARE\_SEARCH flag in configuration - #2 by regis - Tutor - Overhang.IO](https://discuss.overhang.io/t/how-to-set-enable-courseware-search-flag-in-configuration/413/2)).

Once that’s done, you’ll be able to log in to the Studio Django Admin ([https://your-studio-url.org/admin](https://your-studio-url.org/admin)) and add Course Creator users linked to specific Organizations. ref [Maple release Notes: Instructor Experiences](https://docs.openedx.org/en/latest/community/release_notes/maple.html#instructor-experiences)

**EDIT** : Originally had the LMS Django Admin links above, but the Course Creators must be accessed from Studio.

---

<div class="post-metadata">

**Author:** ![mcan](https://avatars.discourse-cdn.com/v4/letter/m/b38774/32.png) [@mcan](https://discuss.openedx.org/u/mcan)\
**Post date:** [June 19, 2023, 8:35am UTC](https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447/3 "2023-06-19T08:35:10Z")

</div>

Thank you for your answer @jill , but I have an issue. I am using tutor 15.3.5 on development mode and I guess the forum link you shared seems a bit old since documentation links are not available anymore. Therefore, I created a tutor plugin myself

```auto
from tutor import hooks

hooks.Filters.ENV_PATCHES.add_item(
    (
        "openedx-cms-common-settings",
        "FEATURES['ENABLE_CREATOR_GROUP'] = True"
    )
)

```

I enabled this plugin and tried to go \<tutor\_page\>/admin/course\_creators/coursecreator/ but I got **Page not found** error. I looked cor course creation in admin page but could not found anything related. I tried with changing cms with lms and removing it but did not work. I am missing anything else?

---

<div class="post-metadata">

**Author:** ![jill](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.openedx.org/jill/32/3188_2.png) [@jill](https://discuss.openedx.org/u/jill)\
**Post date:** [June 20, 2023, 12:35am UTC](https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447/4 "2023-06-20T00:35:28Z")

</div>

@mcan Ahh… Apologies for those broken links, but also: I misled you on the URL for accessing the Course Creators! It’s available in the Studio Django Admin, not the LMS:

[http://studio.local.overhang.io:8001/admin/course\_creators/coursecreator/](http://studio.local.overhang.io:8001/admin/course_creators/coursecreator/)

(That is my tutor dev URL, yours may have a different hostname/port. I’ll fix it on my original post too.)

If the above still isn’t working, then you might need to modify your plugin. According to the [examples in the latest Tutor docs](https://docs.tutor.overhang.io/plugins/examples.html#skip-email-validation-for-new-users), you can add to the `FEATURES` like this:

```python
from tutor import hooks

hooks.Filters.ENV_PATCHES.add_item(
    (
        "common-env-features",
        """
"ENABLE_CREATOR_GROUP": true
"""
    )
)

```

Or with the modern way of patching plugins, by creating a file at `<tutoryour_plugin>/patches/common-env-features` which contains:

```plaintext
ENABLE_CREATOR_GROUP: true

```

To check whether your plugin worked and the setting has actually been applied, you can use the shell:

```python
(tutor) $ tutor dev dc exec cms ./manage.py cms shell

from django.conf import settings
settings.FEATURES.get("ENABLE_CREATOR_GROUP")
# True

```

---

<div class="post-metadata">

**Author:** ![mcan](https://avatars.discourse-cdn.com/v4/letter/m/b38774/32.png) [@mcan](https://discuss.openedx.org/u/mcan)\
**Post date:** [June 20, 2023, 11:10am UTC](https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447/5 "2023-06-20T11:10:56Z")

</div>

@jill Okay, I can see course\_creator page even without any plugin, but it seems I cannot add anything to it. I am pasting my plugin below

```auto
from tutor import hooks

hooks.Filters.ENV_PATCHES.add_item(
    (
      "common-env-features",
      """
        'ENABLE_CREATOR_GROUP': true
      """
    )
)

```

When I enable this plugin I start to get error.

lms\_1 | raise ParserError(“while parsing a block mapping”, self.marks[-1],  
lms\_1 | yaml.parser.ParserError: while parsing a block mapping  
lms\_1 | in “/openedx/config/lms.env.yml”, line 1, column 1  
lms\_1 | expected , but found ‘’  
lms\_1 | in “/openedx/config/lms.env.yml”, line 12, column 3  
tutor\_dev\_lms\_1 exited with code 1

Same error also happens for dev\_cms, dev\_lms\_worker and dev\_cms\_worker containers as well. I guess there is a sytnax error. maybe @regis knows if there is a problem with plugin? I also could not found any setting named **ENABLE\_CREATOR\_GROUP** in [feature toggles page](https://edx.readthedocs.io/projects/edx-platform-technical/en/latest/featuretoggles.html)

---

<div class="post-metadata">

**Author:** ![jill](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.openedx.org/jill/32/3188_2.png) [@jill](https://discuss.openedx.org/u/jill)\
**Post date:** [June 21, 2023, 1:30am UTC](https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447/6 "2023-06-21T01:30:13Z")

</div>

@mcan Here’s my plugin (which you’re welcome to copy, fork, whatever you need): [GitHub - pomegranited/tutor-contrib-enable-feature-flag: Demonstrates how to add a feature flag to Tutor](https://github.com/pomegranited/tutor-contrib-enable-feature-flag)

It uses the new method for adding patches, under the plugin’s `patches` dir: [feat: enables ENABLE\_CREATOR\_GROUP flag · pomegranited/tutor-contrib-enable-feature-flag@295de35 · GitHub](https://github.com/pomegranited/tutor-contrib-enable-feature-flag/commit/295de3579c5253be515901a4529b216e39748c78)

> I also could not found any setting named **ENABLE\_CREATOR\_GROUP** in [feature toggles page](https://edx.readthedocs.io/projects/edx-platform-technical/en/latest/featuretoggles.html)

I guess those docs are out of date… these docs show it:

[https://edx.readthedocs.io/projects/edx-installing-configuring-and-running/en/open-release-maple.master/feature\_flags/feature\_flag\_index.html](https://edx.readthedocs.io/projects/edx-installing-configuring-and-running/en/open-release-maple.master/feature_flags/feature_flag_index.html)

---

<div class="post-metadata">

**Author:** ![mcan](https://avatars.discourse-cdn.com/v4/letter/m/b38774/32.png) [@mcan](https://discuss.openedx.org/u/mcan)\
**Post date:** [June 21, 2023, 9:55am UTC](https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447/7 "2023-06-21T09:55:11Z")

</div>

@jill I am grateful for the plugin. I installed it using pip and enabled it and restarted tutor. Then I opened \<studio\_page\>/admin/course\_creators/coursecreator/ But page just looks like this.

 ![image](https://us1.discourse-cdn.com/flex020/uploads/openedx/original/2X/a/ab1dc6325205f44cb9293613172b0a987dd7a822.png)  
I can’t add course creator, just like before I enable your plugin. So, I checked if plugin is working, and used the codes you mentioned below.

> [@jill](#):
>
> ```auto
> (tutor) $ tutor dev dc exec cms ./manage.py cms shell
> 
> from django.conf import settings
> settings.FEATURES.get("ENABLE_CREATOR_GROUP")
> 
> ```

And It returned False. I checked the env folder with **grep -r “ENABLE\_CREATOR\_GROUP”** and found

```auto
env/apps/openedx/config/cms.env.yml: ENABLE_CREATOR_GROUP: true
env/apps/openedx/config/lms.env.yml: ENABLE_CREATOR_GROUP: true

```

So, it seems plugin is changing the flag but somehow it is not applied to docker images. I tried to restart and **tutor images build --no-cache openedx** but nothing changed.

Thank you a lot for all your help.

---

<div class="post-metadata">

**Author:** ![mcan](https://avatars.discourse-cdn.com/v4/letter/m/b38774/32.png) [@mcan](https://discuss.openedx.org/u/mcan)\
**Post date:** [June 23, 2023, 7:32am UTC](https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447/8 "2023-06-23T07:32:36Z")

</div>

Well, I found out what is the issue. I entered into cms\_1 docker then navigated to ~/edx-platform/cms/envs, and run **grep -r “ENABLE\_CREATOR\_GROUP”** command. Result was,

```auto
devstack.py:FEATURES['ENABLE_CREATOR_GROUP'] = False
common.py: 'ENABLE_CREATOR_GROUP': True,
test.py:FEATURES['ENABLE_CREATOR_GROUP'] = False

```

I realized what was happening. setting in devstack.py is overriding it. I don’t know if there is a way to disable it. Therefore, I installed and enabled plugin in my production server. Then I re-run python codes to check ENABLE\_CREATOR\_GROUP and it was true. This means, they force some of feature settings to be false. @jill But, I still can’t add course creators inside _/admin/course\_creators/coursecreator/_

---

<div class="post-metadata">

**Author:** ![jill](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.openedx.org/jill/32/3188_2.png) [@jill](https://discuss.openedx.org/u/jill)\
**Post date:** [June 26, 2023, 12:33am UTC](https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447/9 "2023-06-26T00:33:13Z")

</div>

> [@mcan](#):
>
> I realized what was happening. setting in devstack.py is overriding it. I don’t know if there is a way to disable it.

Uck… that’s annoying, I’m so sorry this is so difficult! It really shouldn’t be.

From what I can see of [this PR](https://github.com/openedx/edx-platform/pull/26616) which added this feature flag, that dev was done in the old [devstack](http://github.com/openedx/devstack), not Tutor, and they manually override the devstack flag instead of making it properly env-configurable everywhere.

Fixing this requires a PR against edx-platform… I will poke around and raise an issue to get this fixed; stay tuned.

> [@mcan](#):
>
> But, I still can’t add course creators inside _/admin/course\_creators/coursecreator/_

This is really convoluted and bizarre, but also from reading that PR, users need to request course creator access, which creates rows in the CourseCreator table that need an admin user to approve them. These approval requests get emailed to yet another FEATURES setting: `FEATURES['STUDIO_REQUEST_EMAIL']`. I’ve added this to my plugin: [GitHub - pomegranited/tutor-contrib-enable-feature-flag: Demonstrates how to add a feature flag to Tutor](https://github.com/pomegranited/tutor-contrib-enable-feature-flag/)

If you sign into your production Studio as a non-staff, non-superuser, do you see an option to request course creator access?

---

<div class="post-metadata">

**Author:** ![jill](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.openedx.org/jill/32/3188_2.png) [@jill](https://discuss.openedx.org/u/jill)\
**Post date:** [June 26, 2023, 1:32am UTC](https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447/10 "2023-06-26T01:32:16Z")

</div>

> [@jill](#):
>
> Fixing this requires a PR against edx-platform… I will poke around and raise an issue to get this fixed; stay tuned.

Ok, I’m learning a lot here…

We shouldn’t be running `tutor dev` unless we’re actually _doing development on Tutor itself_ ([ref](https://discuss.openedx.org/t/difference-between-tutor-local-and-tutor-dev/9047), though note: this may change too, cf [Tutor Enhancement Proposal (TEP) for a quicker development workflow](https://discuss.openedx.org/t/tutor-enhancement-proposal-tep-for-a-quicker-development-workflow/8595))

- [`tutor dev`](https://docs.tutor.overhang.io/reference/cli/dev.html#tutor-dev) runs openedx with development settings (i.e., `cms/env/devstack.py`).
- [`tutor local`](https://docs.tutor.overhang.io/reference/cli/local.html) uses the production settings, and so allows us to override FEATURES using Tutor’s configurable environment variables.

So even though this devstack issue is confusing, I don’t think a PR to fix it would be accepted. We just need to use `tutor local` when doing local openedx dev. However:

> [@jill](#):
>
> If you sign into your production Studio as a non-staff, non-superuser, do you see an option to request course creator access?

@mcan , if this is still not working for you in `tutor local` / production, please let me know?

---

<div class="post-metadata">

**Author:** ![mcan](https://avatars.discourse-cdn.com/v4/letter/m/b38774/32.png) [@mcan](https://discuss.openedx.org/u/mcan)\
**Post date:** [June 26, 2023, 12:31pm UTC](https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447/11 "2023-06-26T12:31:44Z")

</div>

@jill It all makes sense now. I thought local is for production server and dev is for local development. The plugin you gave me works and I managed to add user as course creator. And combining this with previous knowledge I managed to assign a user to a specific organization as course creator and staff/instructor for organization’s previously created courses. Thank you for your help.

---

<div class="post-metadata">

**Author:** ![jill](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.openedx.org/jill/32/3188_2.png) [@jill](https://discuss.openedx.org/u/jill)\
**Post date:** [June 26, 2023, 9:41pm UTC](https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447/12 "2023-06-26T21:41:17Z")

</div>

So glad we got there in the end!  
Thanks for persevering, and good luck!

---

<div class="post-metadata">

**Author:** ![kmccormick](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.openedx.org/kmccormick/32/8982_2.png) [@kmccormick](https://discuss.openedx.org/u/kmccormick)\
**Post date:** [August 14, 2023, 12:45pm UTC](https://discuss.openedx.org/t/prevent-staff-to-create-courses-for-different-organizations/10447/13 "2023-08-14T12:45:43Z")

</div>

Just stumbling into this old thread now. Glad you folks were able to find a plugin that solves the issue. 🙂

I do want to clarify that `tutor dev` is indeed intended for Open edX development, just like devstack. It had some issues that made many folks prefer devstack, but we have been steadily working through those. Check out [Tutor’s Open edX dev guide](https://docs.tutor.overhang.io/dev.html) for the latest.

It’s also perfectly OK to use `tutor local` for development, but it is missing some things that are good to have in dev mode, like ipdb, automatic code reloading, and uncompressed static assets artifacts.

Regarding ENABLE\_CREATOR\_GROUP: I _believe_ this was set to False for development mode because we wanted it to be easy for devstack users to create test courses without having to explicitly add their test users to the course creator group. In retrospect, this causes a confusing difference in behavior between dev and prod! It would probably be better if the flag were True everywhere, and if devstack handled it by adding users to the course creator group as a provisioning step.
