Permissions reference
This reference lists every permission a security role can grant or veto, level by level, followed by the built-in roles.
Server permissions
Abilities that apply to the whole installation, from reaching the product at all to administering it.
| Group | Permissions |
|---|---|
| Application access | Use Application |
| Repositories | Create and Manage Repositories · Delete Repository |
| Users and directories | View Users and Groups · Manage Users and Groups · Manage User Directories · Manage Password Policies |
| Roles | Manage Server Roles · Manage Repository Roles · Manage Item Roles · Assign Server Roles |
| Platform | Edit Server Settings · Can Customize · Manage Licenses |
| Support and integration | Access Support Features · Can Report Issues · Access REST API · Develop Extensions |
Notes: Edit Server Settings opens the Server Settings pages; Can Customize opens Customization and the email template editor, and is enough for changing the Default Landing Page.
Repository permissions
Repository-wide abilities, assigned per repository or on all repositories.
| Group | Permissions |
|---|---|
| Access | Use Repository · View Repository Tree |
| Configuration areas | Manage Repository Configuration · Manage Custom Properties · Manage Risk Configuration · Manage Control Configuration · Manage Performance Indicator Configuration · Manage Journey Configuration · Manage Capability Configuration · Manage Opportunity Configuration |
| Roles and permissions | Assign Repository Roles · Set Any Item Permissions |
| Performance data | Add Performance Indicator Data · Modify Performance Indicator Data |
| Cycles and governance | Allow Bulk Approvals · Manage Cycle Groups · View Cycle Groups · Manage Retention Policies and Archive · Manage Proposals WorkflowWorkflow An automated or semi-automated sequence of tasks that moves work from initiation to completion, often with routing rules and human-task assignments. |
| Deleted items | View All Deleted Objects |
Notes: the Manage … Configuration permissions gate the matching areas of Repository Configuration — for example, Manage Risk Configuration is what makes Repository → Risks appear. Set Any Item Permissions is the repository-level safeguard against lockout. Item permissions are assigned per item and inherited, so a role assignment on one item can leave nobody holding Administer there — and therefore nobody able to correct it. This permission reaches any item's Permissions tab regardless of the item-level roles, so a repository administrator can always put it right.
Item permissions
Abilities on repository items, inherited down the tree.
| Group | Permissions |
|---|---|
| Reading | View · See Unapproved · See History · Print · View Cycle Information |
| Editing | Create · Modify · Rename · Move · Delete · Administer |
| Diagram comments | Add Diagram Comments · View All Diagram Comments · Modify Own Diagram Comments · Delete Own Diagram Comments · Resolve/Reopen Own Diagram Comments · Move Any Diagram Comments · Delete Any Diagram Comments · Resolve/Reopen Any Diagram Comments |
| Cycle participation | Approve · Review · Endorse |
| Cycle management | Manage Approval Cycle · Manage Review Cycle · Manage Endorsement Cycle · Manage Acknowledgement Cycle · Set Approvers · Set Reviewers · Set Endorsers · Set Acknowledgers |
| Risk and control data | Add Risk Data · Modify Risk Data · View Control Assessments · Add Control Assessments |
| Watching | Manage Elective Watchers · Manage Required Watchers |
| Other | Modify Project Status |
Notes: Administer unlocks an item's Permissions tab in full — role assignments and any user's effective permissions. See Unapproved is the approval gate between work in progress and the approved version.
Built-in roles
The roles that ship with a cloud installation. All of them can be inspected — and copied as starting points — under Admin → Security Roles.
| Level | Role | What it's for |
|---|---|---|
| Server | Administrator (Customer Admins) | Full administration. |
| Server | User | Use the application — the role everybody needs; assigned to the Everybody group by default. |
| Server | API User | REST API access. |
| Server | Deny all | Veto on everything — blocks a user or group outright. |
| Repository | Administrator | Repository-wide management. |
| Repository | User | Use the repository and see its tree. |
| Item | Administrator | Everything on the item. |
| Item | Author | Edit and run cycles. |
| Item | Viewer | Read, including unapproved versions, with comment participation. |
| Item | View approved only | Read approved versions only — pairs with the approval gate. |
| Item | None | No grants — a placeholder assignment. |
| Item | Deny all | Veto on everything. |
A cloud installation also carries iGrafx-internal roles (for iGrafx system administrators and consultants); they appear in the lists but aren't yours to manage.
Related
- Security roles and permissions — how the model works
- Assign security roles
- License capability matrix — the license side of access