Granting access
A grant has three fields. That is the whole permission model.
Writing a grant
Go to Settings → Access → Grants and select Grant access.
Who — select one or more people or groups. Each principal gets its own row, so you can revoke one without touching the others.
Where — the scope. One of three kinds:
- an organisation unit — reaches everything homed at or below it
- a workspace — reaches every register in it
- a single object — one register, and nothing else
What role — see Roles and permissions.
Optionally set an expiry date. Time-boxed access for contractors and secondments is far easier than remembering to revoke it.
Save.
How far a grant reaches
Access is decided by one question: is the grant’s scope anywhere on the target’s chain? The chain runs:
the object → its workspace → its home unit → that unit's matrix line → ancestors → the root
The grants list shows, for each row, how many units and objects it actually reaches. A grant that reaches nothing is flagged — usually it points at a unit where nobody has homed a register yet.
Two gates that a grant cannot cross
| Gate | Set on | Who still gets through |
|---|---|---|
| Closed | A register, by turning off inheritance | Direct grants, workspace grants, administrators, and the read-only auditor ceiling |
| Sealed | A workspace, by marking it independent | Members of the owning independence group only — including the administrator |
Sealed is the only place in the app where being an administrator is not sufficient. That is the point of it: it is the mechanism that lets internal audit keep workpapers the second line cannot read.
Baseline access
Rather than writing one grant per manager, turn baseline access on for a register. Everyone then automatically holds a low role — Reporter — on their own unit and below.
Grants only ever raise that baseline. The result is a grant table that contains the exceptions, not the population.
Never raise the baseline above Reporter to save writing grants. It looks like a shortcut and is actually a decision to give everybody more access than anyone approved.
Revoking
Revoking a grant shows what the person would lose and what they would still hold from other grants — which is usually more than the administrator expects. Every revocation is written to the audit log.