# Trust Level Permissions Reference

**URL:** https://meta.discourse.org/t/trust-level-permissions-reference/224824
**Category:** Using Discourse
**Tags:** trust-levels, reference
**Created:** [April 20, 2022, 8:03am UTC](https://meta.discourse.org/t/trust-level-permissions-reference/224824 "2022-04-20T08:03:29Z")
**Posts on this page:** 12
**Page:** 2

<div class="post-metadata">

### Author: ![nathank](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nathank/32/290039_2.png) [@nathank](https://meta.discourse.org/u/nathank)
#### Post date: [April 23, 2024, 12:12am UTC](https://meta.discourse.org/t/trust-level-permissions-reference/224824/62 "2024-04-23T00:12:09Z")

</div>

> [@JammyDodger](#):
>
> Make Personal Message/Public Topic ✅

This doesn’t seem to be the case any more - in my site, it seems to be admins only (discovered after attempting to coach one of my mods to convert a topic to public). I can’t find a setting that governs this.

Not sure if this is a regression or is deliberate.

---

<div class="post-metadata">

### Author: ![Lilly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/lilly/32/575047_2.png) [@Lilly](https://meta.discourse.org/u/Lilly)
#### Post date: [April 23, 2024, 3:54am UTC](https://meta.discourse.org/t/trust-level-permissions-reference/224824/63 "2024-04-23T03:54:42Z")

</div>

Hmmm, I just tested this and for me it’s still working as expected and allowing moderators to make a topic from a pm:

test user admin panel showing perimissions:

 ![image](https://global.discourse-cdn.com/meta/original/4X/e/5/3/e5376a668ee0fc75712837ec1f9f98aac0ab14c3.png)

logged in as test user with PM to self:

 ![image](https://global.discourse-cdn.com/meta/original/4X/8/d/0/8d094caa324be7df9398205359bb7e28162e4976.png)

 ![image](https://global.discourse-cdn.com/meta/original/4X/f/a/0/fa054f009d1d49e2504e55e8a55e5179d2d05b44.png)

Did you try it with a test moderator account?

---

<div class="post-metadata">

### Author: ![nathank](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nathank/32/290039_2.png) [@nathank](https://meta.discourse.org/u/nathank)
#### Post date: [April 23, 2024, 4:41am UTC](https://meta.discourse.org/t/trust-level-permissions-reference/224824/64 "2024-04-23T04:41:14Z")

</div>

Okay - I understand the issue now. It has to do with the interaction of deletion and changes to the admin menu of topics which don’t refresh until the page is reloaded. This is a bug (albeit it a _very_ minor one).

To repro:

1. Visit an existing Topic (can be a PM) with an account with moderator/admin privileges
2. Delete the Topic
  - Note that the option to `Make Public Topic / Make Personal Message` remains visible

3. Refresh the page
  - Note that the option to `Make Public Topic / Make Personal Message` is no longer present

4. Undelete the Topic
  - the option to `Make Public Topic / Make Personal Message` remains absent until the page is refreshed

It seems like a page refresh is needed after deletion / undeletion of a topic. Perhaps this should be included in the action of topic deletion/undeletion?

---

<div class="post-metadata">

### Author: ![zhang\_zhiyuan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/zhang_zhiyuan/32/430883_2.png) [@zhang\_zhiyuan](https://meta.discourse.org/u/zhang_zhiyuan)
#### Post date: [September 11, 2024, 7:42am UTC](https://meta.discourse.org/t/trust-level-permissions-reference/224824/68 "2024-09-11T07:42:50Z")

</div>

It is real clear to understand.

---

<div class="post-metadata">

### Author: ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### Post date: [May 6, 2025, 6:17am UTC](https://meta.discourse.org/t/trust-level-permissions-reference/224824/69 "2025-05-06T06:17:14Z")

</div>

There’s a green tick against TL0 for muting a user. Having had a quick run through for this topic [Which roles are allowed to mute other users? - #4 by JammyDodger](https://meta.discourse.org/t/which-roles-are-allowed-to-mute-other-users/361739/4), it seems this is a TL1 ability. Could someone update the doc. 🙏

* * *

Also, ‘staff notices’ has had a name change too.

---

<div class="post-metadata">

### Author: ![Lilly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/lilly/32/575047_2.png) [@Lilly](https://meta.discourse.org/u/Lilly)
#### Post date: [May 6, 2025, 1:10pm UTC](https://meta.discourse.org/t/trust-level-permissions-reference/224824/70 "2025-05-06T13:10:14Z")

</div>

Thanks Jammy 🙏 - I’ve updated the OP. 🙂

---

<div class="post-metadata">

### Author: ![calebhearth](https://avatars.discourse-cdn.com/v4/letter/c/ebca7d/32.png) [@calebhearth](https://meta.discourse.org/u/calebhearth)
#### Post date: [June 6, 2025, 3:15pm UTC](https://meta.discourse.org/t/trust-level-permissions-reference/224824/71 "2025-06-06T15:15:40Z")

</div>

I don’t see a listing here for what the trust level is for authorizing user API access (as mentioned here: ["Sorry, you do not have the required trust level to access the user API" when on iOS](https://meta.discourse.org/t/sorry-you-do-not-have-the-required-trust-level-to-access-the-user-api-when-on-ios/71084)). Based on that, it seems that 0 is the minimum level, but it can be configured as well. Can that be documented here? Or did I not read well enough?

---

<div class="post-metadata">

### Author: ![Moin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/moin/32/554653_2.png) [@Moin](https://meta.discourse.org/u/Moin)
#### Post date: [June 6, 2025, 3:47pm UTC](https://meta.discourse.org/t/trust-level-permissions-reference/224824/72 "2025-06-06T15:47:01Z")

</div>

Welcome to Meta 👋

I think you are right; the permission and the related setting aren’t included in the table.

The `user_API_key_allowed_groups` setting’s default is trust level 0. The admin and moderator groups cannot be removed from the setting. However, to limit permissions, admins can remove the trust level 0 group, which includes all users who signed up. Then only staff are allowed to use the user API. They can also add other groups to restrict access to specific groups.

 ![Screenshot_20250606_173719_Firefox](https://global.discourse-cdn.com/meta/original/4X/3/b/4/3b4ada30569b844f494e3c8b7de4049d08ec6a7c.jpeg)

---

<div class="post-metadata">

### Author: ![patrickemin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/patrickemin/32/520162_2.png) [@patrickemin](https://meta.discourse.org/u/patrickemin)
#### Post date: [July 16, 2025, 10:08pm UTC](https://meta.discourse.org/t/trust-level-permissions-reference/224824/73 "2025-07-16T22:08:39Z")

</div>

> [@JammyDodger](#):
>
> Absolutely. 👍 🙂 You can even pull up the raw version of the post by using the ‘raw’ link if that makes it easier?

Did not know about this raw link, I learn everyday 😁

---

<div class="post-metadata">

### Author: ![agemo](https://avatars.discourse-cdn.com/v4/letter/a/ac91a4/32.png) [@agemo](https://meta.discourse.org/u/agemo)
#### Post date: [August 25, 2025, 9:59am UTC](https://meta.discourse.org/t/trust-level-permissions-reference/224824/74 "2025-08-25T09:59:36Z")

</div>

Is there a way to restrict some user levels from being able to upload some or all other than the basic all vs staff approach found aim `ADMIN > FILES > Authorized extension` or `> Authorized extension for staff`?

---

<div class="post-metadata">

### Author: ![ondrej](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ondrej/32/198804_2.png) [@ondrej](https://meta.discourse.org/u/ondrej)
#### Post date: [August 27, 2025, 2:00pm UTC](https://meta.discourse.org/t/trust-level-permissions-reference/224824/75 "2025-08-27T14:00:57Z")

</div>

Does the `Embedded media post allowed groups` site setting help?

Or use this theme component

> [@Restrict uploads](https://meta.discourse.org/t/restrict-uploads/112688):
>
> This is a very small theme component that will remove the upload button from the composer toolbar and disable drag-and-drop uploading for users that are under a specified trust level. Illustration Settings hammer_and_wrenchRepository [github.com/tshenry/discourse-restrict-uploads](https://github.com/tshenry/discourse-restrict-uploads)open_bookNew to Discourse Themes? [Beginner’s guide to using Discourse Themes](https://meta.discourse.org/t/beginners-guide-to-using-discourse-themes/91966) Install this theme component

---

<div class="post-metadata">

### Author: ![agemo](https://avatars.discourse-cdn.com/v4/letter/a/ac91a4/32.png) [@agemo](https://meta.discourse.org/u/agemo)
#### Post date: [August 27, 2025, 7:17pm UTC](https://meta.discourse.org/t/trust-level-permissions-reference/224824/76 "2025-08-27T19:17:11Z")

</div>

Thank you. I think that component will do nicely.

[Previous page](https://meta.discourse.org/t/trust-level-permissions-reference/224824.md?page=1)
