It is possible to grant certain permissions at platform level to specific users. To do this, administrators must create user groups and then assign permissions to them.
In the screenshot below, three groups have been created for the platform:
Support Team.
User Validation.
Users And Project Validation.
.png?sv=2026-02-06&spr=https&st=2026-08-24T00%3A13%3A59Z&se=2026-08-24T00%3A24%3A59Z&sr=c&sp=r&sig=3AQ9pXokWFR0Nv0RGcKfbjTRfwmHK%2F1gieVs0ESnqAk%3D)
The “Support Team” group is authorised to manage PDF templates, but it is possible to add further ones:
.png?sv=2026-02-06&spr=https&st=2026-08-24T00%3A13%3A59Z&se=2026-08-24T00%3A24%3A59Z&sr=c&sp=r&sig=3AQ9pXokWFR0Nv0RGcKfbjTRfwmHK%2F1gieVs0ESnqAk%3D)
Global MediaWiki Administrator: grants MediaWiki administrative rights across all projects.
Global Tracker Administrator: grants Tracker administrative rights across all projects.
Platform administration: grants site administrator rights. Users with this delegation will see an ‘Administration’ tab appear in the navigation bar.
Project Approbation: grants the right to approve project creations.
REST projects management: grants the right to create, suspend or activate projects via the REST API.
REST read only administrator: grants the right to browse the entire REST API with the privileges of a read-only platform administrator. Users assigned this role should only use it with the REST API, as using it via the web interface may result in inconsistent behaviour.
Retrieve User Membership Information: grants the right to view the group(s) to which any user belongs.
See information about system events through the REST API: grants the right to query the GET /system_events endpoint of the REST API.
User management: grants the right to manage users—namely to modify their status, username, etc.—via the REST API.
Information
A security mechanism prevents you from deleting the user group that holds the final platform administration permission; otherwise, you may no longer be able to access the platform administration.