Administration
Roles and permissions
Create roles, inspect permission drift, and control who can edit or approve.
For workspace users and administrators · Updated October 1, 2026
What this module is for
Create roles, inspect permission drift, and control who can edit or approve.
Use this page when you need to complete the task yourself and understand what each action changes. The steps name the relevant screen, explain why the action belongs in the workflow, and state what to verify before moving on.
Before you start
- Sign in with a role that can view or change the records in this guide.
- Have the product, file, channel, or workspace information ready before starting an action that saves data.
- Use a small test record or file first when an action affects multiple products or a connected channel.
1. Create or inspect a role
Complete these actions in order. They describe the screen to use, the decision to make, and the evidence to check before you move to the next stage.
-
Step 1.1
Do this: Open Roles & Permissions and create a role for a specific responsibility.
Why this matters: This keeps the create or inspect a role work traceable and makes the next review, validation, or handoff easier to complete.
Check before continuing: Look for a confirmation message, a newly created record, or a job status entry. If nothing changes, read the inline field error or job detail before retrying.
-
Step 1.2
Do this: Set the permissions shown in the role form and save.
Why this matters: This keeps the create or inspect a role work traceable and makes the next review, validation, or handoff easier to complete.
Check before continuing: Look for a confirmation message, a newly created record, or a job status entry. If nothing changes, read the inline field error or job detail before retrying.
-
Step 1.3
Do this: Open the detail page to inspect role information, assigned users, and available Duplicate or Analyze Drift actions.
Why this matters: This keeps the create or inspect a role work traceable and makes the next review, validation, or handoff easier to complete.
Check before continuing: Look for a confirmation message, a newly created record, or a job status entry. If nothing changes, read the inline field error or job detail before retrying.
2. Correct access
Complete these actions in order. They describe the screen to use, the decision to make, and the evidence to check before you move to the next stage.
-
Step 2.1
Do this: Assign the role to a team member and ask them to sign in again if access was just changed.
Why this matters: This keeps the correct access work traceable and makes the next review, validation, or handoff easier to complete.
Check before continuing: Look for a confirmation message, a newly created record, or a job status entry. If nothing changes, read the inline field error or job detail before retrying.
-
Step 2.2
Do this: If a user reaches Unauthorized, compare their role with the permission required by that screen.
Why this matters: This keeps the correct access work traceable and makes the next review, validation, or handoff easier to complete.
Check before continuing: Confirm that the named screen or panel is visible and contains the expected values. If a control is missing, check your workspace role before continuing.
-
Step 2.3
Do this: Delete a role only after reassigning its users.
Why this matters: This keeps the correct access work traceable and makes the next review, validation, or handoff easier to complete.
Check before continuing: Look for a confirmation message, a newly created record, or a job status entry. If nothing changes, read the inline field error or job detail before retrying.
Events and statuses to watch
Actions such as saving, importing, exporting, connecting, publishing, and approving can either update a record immediately or create background work. Wait for the on-screen confirmation and then check the relevant list, detail view, or job status before repeating an action.
- Saved or created: confirm the record appears with the intended values.
- Queued, running, or processing: wait for completion and open the job or event detail if progress stops.
- Failed, partial, rejected, or blocked: read the specific message, correct the source data or permissions, then retry only the affected work.