1. Docs
  2. Assigning access

Assigning access

Giving someone a role at one of your places, and taking it back. This is how a person goes from being in your directory to being able to do something.

Overview

The people on this page are your application's end users, the ones in your directory: they sign in to your product, never to this Workspace. Granting your own staff authority happens on the Administrators page, not here. An identity on its own can sign in and do nothing. Access comes from an assignment: one person, one role, at one place. Until someone makes that assignment, being in the directory means only that the person exists.

Assigning access needs the assign capability. Being able to see people, or to invite them, does not include being able to decide what they may do.

What an assignment is

Three things together, and all three matter. A fourth is optional.

The person, chosen from the people you already administer.The role, chosen from the roles you are permitted to grant.The place, chosen from the places you administer. The role applies there and everywhere beneath it, so assigning at a region reaches every store inside it.Optionally a window: a date it starts, a date it ends, or both. Left blank, access begins immediately and does not expire, which is what most assignments want.

The roles you may hand out

You cannot hand out every role that exists, only the ones your own role permits. An account administrator decides that list when they compose your role, which is what stops assignment becoming a way of granting more authority than you hold. If a role you expect is not offered, it is not that the role is missing: it is not one of yours to give. Two people are exempt, and hold the whole list: the account owner, and anyone granted authority over every Environment.

Changing and removing

An assignment can be changed after the fact: a different role, a different window, or both. Its place is fixed when it is made, so putting someone's role somewhere else means removing this assignment and making another. Removing takes the role away at that place and nothing else: the person stays in the directory, keeps any other roles they hold elsewhere, and can be assigned again later. Neither is a deletion of the person.

Removing is not bounded by the roles you may grant. If someone in your places holds a role you could never hand out yourself, you can still take it away, because withdrawing access can never hand out more of it.

Next Step

Every assignment, change, and removal is recorded. Activity shows what has happened in the places you administer.

Environment
API version
v1.0
On this page Was this page helpful?

Tell us how we can improve this guide.