Working with permissions

Understand permission levels, how access is decided, and how grants flow down folders so the right people can view, run, edit or administer your processes and other items.

Help CentreAdministration

Every item in Automize – a process, form, wiki, bot, credential, queue, folder and more – has an owner and a set of permissions that decide what other people can do with it. This article explains the permission levels and how Automize works out who is allowed to do what. To grant access to other people, read Sharing and collaboration.

1. Permission levels

Access is granted at one of five levels. Each level includes everything the levels below it can do.

  1. None – no access. The item is not visible.
  2. Viewer – read-only. Can open and view the item, but not run or change it.
  3. Operator – view and run. Can execute a process or bot, but cannot edit it.
  4. Editor – view, run, comment, export and edit. Can change the item's content.
  5. Admin – everything an Editor can do, plus share the item with others, delete it, and manage who else has access.

2. How Automize decides your access

When you open an item, Automize checks the following in order and uses the first rule that applies:

  1. Owner or superuser – if you own the item (or you are a system superuser), you have full Admin access.
  2. An explicit grant – if the item, or any folder above it, has been shared with you (directly, with a team you belong to, or with everyone in your company), you get that permission level. Where more than one grant applies, the highest level wins.
  3. A company-owned item – items owned by the company as a whole (rather than a single person) give everyone in that company Editor access by default.
  4. Another person's item in your company – items owned by a colleague that have not been shared with you give you Viewer access by default.
  5. Anything else – people outside your company get no access unless an item has been explicitly shared with them.

3. Permissions flow down folders

Permissions are inherited down the folder tree. If you share a folder with someone, they get that same access to every process, form and sub-folder inside it – unless a more specific grant lower down raises it. This makes a folder the easiest place to manage access for a whole group of related items at once.

4. Company admins and superusers

A company admin can manage users, roles and workspace settings, and can step in to force-unlock an item another user has locked. A superuser is a system-level administrator whose access overrides the normal permission checks. Read Roles and administrators for more.

Related articles

See it working on your own data

Everything documented here ships with the platform – try the document tools free, or go live in 7 days.