Appearance
Configure Role Permissions
Permissions control the specific actions a user in a role can perform. When you create a custom role, you assign permissions to define its capabilities.
Access role permissions
- Go to Settings → Roles.
- Find the role you want to configure. Only custom roles can be edited; built-in roles (Admin, Owner) cannot be modified.
- Click the role name to open it.
- Go to the Permissions section to view all available permissions and manage assignments.
Grant a permission
- In the Permissions section, search or browse the permission list.
- Check the checkbox next to each permission you want to grant.
- Click Save changes to apply your changes.
All users with this role immediately gain the selected permissions.
Revoke a permission
- In the Permissions section, find the permission you want to revoke.
- Uncheck the checkbox next to the permission.
- Click Save changes to apply your changes.
All users with this role immediately lose the revoked permission.
Permission categories
Your team has access to a comprehensive set of permissions organized by feature area. These include:
- User management — invite users, manage team members, view user details
- Roles — create and manage roles, view role details and users assigned to roles
- Products and assets — create, edit, delete products and assets; link assets to products
- Campaigns, publications, and items — create campaigns, manage publications and publication items, work with briefings
- Templates and design resources — manage templates, design libraries, master pages, fonts, and project files
- Workflows — create and configure workflows, workflow automations, and workflow configurations
- Data management — manage data fields, forms, variants, and data filters
- Packages — create and manage campaign packages and package setups
- Content rules — create and manage static and dynamic content rulesets and rules
- Sticky notes — create, edit, and view notes and comments on publication items
- Team settings — manage team details, SSO clients, OAuth clients, identity providers, and connections
- Audit trail — view the team's audit trail and activity history
- Exports and integrations — manage export setups, schedule jobs for templates/assets/products, use signed URLs for S3 uploads
To see the complete list of permissions available to your team, open the role editor and browse the Permissions section.
How permissions interact with other settings
Roles and workflow steps: Permissions apply globally across your team, but they can also be restricted further at the workflow step level. A permission might allow a user to perform an action in general, but a specific workflow step might limit who can take that action based on the workflow configuration. For example, a user might have permission to "Patch publication items" but be restricted from doing so at a particular workflow step where only specific roles are allowed.
Roles and content groups: Permissions define what a user can do, while Content groups and content rules define which records a user can see or edit. A user's access is the combination of both settings. For example, a user might have permission to "Edit products" but only see products assigned to their content group(s). If a user is not in any content groups, they may see all records (depending on your team's content rules configuration).