The implementation team
Who decides what
Admin permission groups
Admin access uses six permission groups. Each group grants read (see the pages) or write (change them). Items a user can’t read are hidden from the sidebar.
Some pages need more than a group:
- Agent Flows and Document Templates require a staff account to create and edit.
- Access-control policy rows are edited in the staff admin. Some Access Control diagnostics require a superuser.
Recommended bundles
Setting permissions
Group roles are assigned in the staff admin (/staff/). Open the user, and add a row per group under Group Permissions, with read or write. The same page sets staff status under Admin Options. Only superusers can do this, so the FFE sets up the client’s accounts during Phase 0.
If the client uses SSO, configure it first on Administer > SSO Configuration, so that accounts exist before workshops start. See SSO Configuration.