Skip to main content

The implementation team

Who decides what

Admin permission groups

Admin access uses six permission groups. Each group grants read (see the pages) or write (change them). Items a user can’t read are hidden from the sidebar. Some pages need more than a group:
  • Agent Flows and Document Templates require a staff account to create and edit.
  • Access-control policy rows are edited in the staff admin. Some Access Control diagnostics require a superuser.
Give reviewers and SMEs read access to Model & Define early. Reviewing the ontology and artifact types in the product between workshops is much faster than reviewing screenshots.
Keep superuser and access-control policy editing with Experio until handover, unless the client’s legal team owns ethical walls and has been trained on the policy model.

Setting permissions

Group roles are assigned in the staff admin (/staff/). Open the user, and add a row per group under Group Permissions, with read or write. The same page sets staff status under Admin Options. Only superusers can do this, so the FFE sets up the client’s accounts during Phase 0. If the client uses SSO, configure it first on Administer > SSO Configuration, so that accounts exist before workshops start. See SSO Configuration.