About privileges

2026-09-09Last updated

Privileges control which actions a user can perform in the partitions they have access to. Users are granted a basic set of privileges by the role they are assigned when their profile is created.

Privilege inheritance rules

Privileges can be inherited from user groups, or replaced at the member (user or user group) level according to the following rules:

  • A privilege that is allowed at the group level can be denied at the member level.
  • A privilege that is denied at the group level is automatically denied at the member level.
  • A privilege that is undefined at the group level can be allowed or denied at the member level.
  • When a user is a member of multiple user groups, the user inherits the most restrictive privilege settings. This means that Deny overrules Allow, and Allow overrules Undefined.
Note:
The default role privileges cannot be modified.

Privilege exceptions for partitions

Along with the privileges defined by their role or parent group, users also have a set of privileges for every partition in which they are an authorized user.

Privileges granted or denied at the partition level are considered exceptions and replace the basic privileges. They can be different for each partition the user has access to.

Note:
Only Administrative and Action privileges, plus the privileges over public tasks, can be overwritten at the partition level.