Skip to main content

Who can use LocalForm

By default only administrators can do anything with LocalForm. That is often the wrong shape for the site: the person who reads the registrations is usually a coordinator, a secretary or a teacher, and making them an administrator so they can open a spreadsheet hands them the whole site.

So LocalForm has two permissions of its own, and either can be given to any role.

PermissionWhat it allows
View responsesOpen LocalForm → Responses, filter and search them, read the summary, export to Excel or CSV, print a single response. Also the Forms list, read-only, as the way to reach a form's responses.
Manage formsEverything else: build, edit, duplicate and delete forms, change settings, open and close forms, delete a response, back up and restore.

Managing forms includes viewing responses, so there are two useful settings rather than four: someone who reads the responses, and someone who runs the plugin.

Granting them​

LocalForm → Settings → General → Access lists every role on the site with a box for each permission. Tick and save.

Administrators are shown but cannot be changed - they always have both, and offering to take that away would only be a way of locking yourself out.

The permissions are ordinary WordPress capabilities, localform_manage_forms and localform_view_responses, written onto the roles themselves. A role plugin such as Members or User Role Editor lists them alongside every other capability and can grant them the same way; either screen works, and they agree with each other.

What a viewer sees​

Someone with View responses and nothing else gets the LocalForm menu with two screens:

  • Forms, read-only. The list of forms with their response counts and status, each linking through to its responses. No Add New, no template picker, no Edit, Copy, Delete or Stop accepting.
  • Responses, complete. Every view, filter, summary, export and printout - the whole point of giving them the permission. What they cannot do is delete a response.

Settings, the form editor and the backup file stay out of reach, and the menu does not offer them.

With LocalForm Pro installed​

Pro's own screens - Field Templates, Field Name Rules, Global Webhook Fields, Scheduled Export, Payments and the Build with AI panel - still require a site administrator. Someone given Manage forms without being an administrator can build and edit forms, but Pro's panels inside the editor will not answer for them. Give that person an administrator account, or keep them on View responses, until Pro follows core here.

Nothing about this is unsafe: Pro's checks are stricter than core's, never looser.

Upgrading from an earlier version​

Nothing to do. Anyone who can manage_options - every administrator, and any custom role built to stand in for one - keeps both permissions whether or not the capabilities were ever written onto their role. Access is only ever added by this feature, never taken away.

Scripts and integrations​

The same split applies outside the admin:

  • localform/v1/forms/<id>/submissions (REST) needs View responses; the schema endpoints need Manage forms.
  • The MCP abilities - list-forms, get-form, save-form - need Manage forms, because they read and write the form itself.
  • wp localform runs from the shell as WP-CLI always has, which is a permission granted by the server rather than by WordPress.