Managing Applications Access

ApplicationsAdministrators and access managers4 min read
What you’ll learnHow to grant, review, update, and remove access to Applications resources.

Applications Access Control manages who can see and work with resources in the Applications explorer. A grant connects one user or role to a resource scope and one or more capabilities.

Open Applications, select More, then select Permissions. The page opens with Applications selected. Use the Documents tab when you need document-specific permissions instead.

Before you start

  • Confirm whether access should belong to one user or to a role.
  • Identify the narrowest resource scope that covers the person's work.
  • Decide whether the principal needs View, Edit, or Open in Builder.
  • Remember that builder actions can also depend on the workspace plan and other Applications feature permissions. An ACL grant does not enable a feature that is unavailable to the organization.

Grant access

  1. In Grant Access, choose User or Role.

  2. Select the principal:

    • For a user, type at least two characters of the username or email, then select a result.
    • For a role, choose one role from the list.
  3. Choose a Resource scope:

    • Global for all Applications resources.
    • Workspace for selected workspaces and their contents.
    • Application for selected applications and their pages.
    • Page for selected pages only.
  4. For a non-global grant, select the required resources. Application and page choices appear after their parent resources are selected.

  5. Select at least one capability:

    Capability Effect
    View Makes the covered resource available in the Applications explorer.
    Edit Allows covered pages to be opened for editing when the organization has the required builder plan and feature access.
    Open in Builder Grants builder access for the covered resource. Builder availability still depends on plan and feature access.
  6. Select Save Permission.

When several resources are selected, RAPTIX saves one grant for each resource. Saving the same principal, scope, and resource again updates that grant instead of creating a duplicate. After a successful save, the form returns to its defaults: User, Global, and View.

Use Allow All to select all three capabilities. If all are already selected, the same control clears them; at least one capability must be selected before saving.

Review active grants

The Active Grants panel shows the principal, principal type, scope, resource name, capabilities, grantor, and grant time for every current grant.

  • Use All, Global, Workspace, App, and Page to filter by resource scope.
  • Use Refresh to reload the list from the server.
  • Scope tabs do not filter by user or role.
  • An empty tab means no grants exist at that scope.

Remove access

  1. Find the grant in Active Grants.
  2. Select its remove icon.
  3. Select Remove in the inline confirmation.

Removal takes effect for that grant immediately. The principal may still have access through another direct grant, a role grant, an administrator role, or a broader scope. Review all applicable grants before concluding that access has been revoked.

Access behavior

Applications access is additive:

  • A Global View grant exposes all workspaces, applications, and pages.
  • A Workspace grant covers its applications and pages.
  • An Application grant covers its pages and adds the parent workspace for navigation.
  • A Page grant exposes that page and adds its parent application and workspace for navigation.
  • Grants inherited through roles are combined with direct user grants.
  • A narrower grant does not subtract a capability supplied by a broader grant.

Use role grants for stable team access and user grants for genuine individual exceptions. Prefer the narrowest scope that meets the requirement.

Troubleshooting

Access denied appears

Confirm that the account is an administrator or can open the Applications More tools. Being able to browse Applications alone is not enough to manage grants.

A user or role is not available

  • Enter at least two characters when searching for a user.
  • Confirm that the account or role exists in the current RAPTIX workspace.
  • Reload the page if the list was changed in another administration session.

A resource picker is empty

Wait for the hierarchy to finish loading, then confirm that the parent workspace or application is selected. Reload the page if Applications hierarchy data could not be loaded.

The user still cannot see a resource

Confirm that View is selected on an applicable direct or role grant. Ask the user to reload Applications after the grant is saved.

The user still has access after removal

Check for a role grant, Global grant, or grant at a broader parent scope. Removing one row does not remove other applicable grants.

Still stuck? See Get Help with Support or reach your workspace administrator.