Granting access

A grant has three fields. That is the whole permission model.

Writing a grant

  1. Go to Settings → Access → Grants and select Grant access.

  2. Who — select one or more people or groups. Each principal gets its own row, so you can revoke one without touching the others.

  3. Where — the scope. One of three kinds:

    • an organisation unit — reaches everything homed at or below it
    • a workspace — reaches every register in it
    • a single object — one register, and nothing else
  4. What role — see Roles and permissions.

  5. Optionally set an expiry date. Time-boxed access for contractors and secondments is far easier than remembering to revoke it.

  6. Save.

How far a grant reaches

Access is decided by one question: is the grant’s scope anywhere on the target’s chain? The chain runs:

the object → its workspace → its home unit → that unit's matrix line → ancestors → the root

The grants list shows, for each row, how many units and objects it actually reaches. A grant that reaches nothing is flagged — usually it points at a unit where nobody has homed a register yet.

Two gates that a grant cannot cross

Gate Set on Who still gets through
Closed A register, by turning off inheritance Direct grants, workspace grants, administrators, and the read-only auditor ceiling
Sealed A workspace, by marking it independent Members of the owning independence group only — including the administrator

Sealed is the only place in the app where being an administrator is not sufficient. That is the point of it: it is the mechanism that lets internal audit keep workpapers the second line cannot read.

Baseline access

Rather than writing one grant per manager, turn baseline access on for a register. Everyone then automatically holds a low role — Reporter — on their own unit and below.

Grants only ever raise that baseline. The result is a grant table that contains the exceptions, not the population.

Never raise the baseline above Reporter to save writing grants. It looks like a shortcut and is actually a decision to give everybody more access than anyone approved.

Revoking

Revoking a grant shows what the person would lose and what they would still hold from other grants — which is usually more than the administrator expects. Every revocation is written to the audit log.