Hi Julie -
I've been playing around with permissions this week trying to achieve something rather similar (in the hopes of reducing reliance on Masquerading).
When the only following permissions are activated on a role at ccount level, you should be able to prevent users from deleting/editing people, content, and grades:
- View the list of courses
- See the list of users
- View all grades
- view announcements
- view course content
I would use your institution.beta.instructure.com instance and experiment with settings before applying them to your production site. I've done that with my accounts as I try to implement some of the things mentioned in Accessing all student grades, and it's really helpful.
This discussion post is outdated and has been archived. Please use the Community question forums and official documentation for the most current and accurate information.