Skip to main content

Permissions reference

This reference lists every permission a security role can grant or veto, level by level, followed by the built-in roles.

Server permissions

Abilities that apply to the whole installation, from reaching the product at all to administering it.

GroupPermissions
Application accessUse Application
RepositoriesCreate and Manage Repositories · Delete Repository
Users and directoriesView Users and Groups · Manage Users and Groups · Manage User Directories · Manage Password Policies
RolesManage Server Roles · Manage Repository Roles · Manage Item Roles · Assign Server Roles
PlatformEdit Server Settings · Can Customize · Manage Licenses
Support and integrationAccess Support Features · Can Report Issues · Access REST API · Develop Extensions

Notes: Edit Server Settings opens the Server Settings pages; Can Customize opens Customization and the email template editor, and is enough for changing the Default Landing Page.

Repository permissions

Repository-wide abilities, assigned per repository or on all repositories.

GroupPermissions
AccessUse Repository · View Repository Tree
Configuration areasManage Repository Configuration · Manage Custom Properties · Manage Risk Configuration · Manage Control Configuration · Manage Performance Indicator Configuration · Manage Journey Configuration · Manage Capability Configuration · Manage Opportunity Configuration
Roles and permissionsAssign Repository Roles · Set Any Item Permissions
Performance dataAdd Performance Indicator Data · Modify Performance Indicator Data
Cycles and governanceAllow Bulk Approvals · Manage Cycle Groups · View Cycle Groups · Manage Retention Policies and Archive · Manage Proposals WorkflowWorkflow An automated or semi-automated sequence of tasks that moves work from initiation to completion, often with routing rules and human-task assignments.
Deleted itemsView All Deleted Objects

Notes: the Manage … Configuration permissions gate the matching areas of Repository Configuration — for example, Manage Risk Configuration is what makes Repository → Risks appear. Set Any Item Permissions is the repository-level safeguard against lockout. Item permissions are assigned per item and inherited, so a role assignment on one item can leave nobody holding Administer there — and therefore nobody able to correct it. This permission reaches any item's Permissions tab regardless of the item-level roles, so a repository administrator can always put it right.

Item permissions

Abilities on repository items, inherited down the tree.

GroupPermissions
ReadingView · See Unapproved · See History · Print · View Cycle Information
EditingCreate · Modify · Rename · Move · Delete · Administer
Diagram commentsAdd Diagram Comments · View All Diagram Comments · Modify Own Diagram Comments · Delete Own Diagram Comments · Resolve/Reopen Own Diagram Comments · Move Any Diagram Comments · Delete Any Diagram Comments · Resolve/Reopen Any Diagram Comments
Cycle participationApprove · Review · Endorse
Cycle managementManage Approval Cycle · Manage Review Cycle · Manage Endorsement Cycle · Manage Acknowledgement Cycle · Set Approvers · Set Reviewers · Set Endorsers · Set Acknowledgers
Risk and control dataAdd Risk Data · Modify Risk Data · View Control Assessments · Add Control Assessments
WatchingManage Elective Watchers · Manage Required Watchers
OtherModify Project Status

Notes: Administer unlocks an item's Permissions tab in full — role assignments and any user's effective permissions. See Unapproved is the approval gate between work in progress and the approved version.

Built-in roles

The roles that ship with a cloud installation. All of them can be inspected — and copied as starting points — under Admin → Security Roles.

LevelRoleWhat it's for
ServerAdministrator (Customer Admins)Full administration.
ServerUserUse the application — the role everybody needs; assigned to the Everybody group by default.
ServerAPI UserREST API access.
ServerDeny allVeto on everything — blocks a user or group outright.
RepositoryAdministratorRepository-wide management.
RepositoryUserUse the repository and see its tree.
ItemAdministratorEverything on the item.
ItemAuthorEdit and run cycles.
ItemViewerRead, including unapproved versions, with comment participation.
ItemView approved onlyRead approved versions only — pairs with the approval gate.
ItemNoneNo grants — a placeholder assignment.
ItemDeny allVeto on everything.

A cloud installation also carries iGrafx-internal roles (for iGrafx system administrators and consultants); they appear in the lists but aren't yours to manage.