Reviewing and Removing Active Grants
The Active Grants panel on Applications Access Control lists the saved ACL rows for the current workspace. Use it to confirm who received a grant, what the grant covers, and which capabilities it supplies.
Before you start
- After the permission mismatch is fixed, open Applications > More > Permissions. Do not use a direct route as a workaround.
- Know the user or role, resource, and capability you are reviewing.
- Remember that one person can receive access through direct grants, several roles, and broader resource scopes.
Read a grant
Each row can contain:
| Field | Meaning |
|---|---|
| Principal name | The user or role saved on the grant. |
| user or role badge | The principal type. |
| Scope badge | Global, Workspace, Application, or Page. |
| Resource name | The selected resource for non-global grants. |
| Capability badges | View, Edit, and/or Open in Builder. |
| by | The account that last saved the grant. |
| Date and time | When the grant was originally created. |
The count beside Active Grants is the total number of current ACL rows.
Filter and refresh the list
- Select a scope tab:
- All shows every grant.
- Global shows organization-wide Applications grants.
- Workspace shows workspace grants.
- App shows application grants.
- Page shows page grants.
- Review the count on each tab.
- Select Refresh to reload the list from the server.
These tabs filter only by resource scope. The page does not provide a principal-name search or a user/role filter, so review all rows in the selected scope.
Update an existing grant
There is no edit control on a grant row. To change its capabilities:
- In Grant Access, select the same principal type and principal.
- Select the same resource scope and resource.
- Select the required capabilities.
- Select Save Permission.
RAPTIX updates the matching ACL row. A matching row has the same principal type, principal, resource type, and resource identifier.
Remove a grant
- Locate the exact row in Active Grants.
- Select the remove icon on that row.
- Review the row again, then select Remove in the inline confirmation. Select the cancel control to keep it.
- Wait for the success message and refreshed list.
Removal deletes only that ACL row. It does not remove the user from a role, change other grants, or cancel administrator access.
Audit checklist
For a routine access review:
- Review Global grants first.
- Review broad Workspace grants.
- Confirm that role grants still match current job responsibilities.
- Look for direct user grants that should now be supplied by a role.
- Confirm that Edit and Open in Builder are limited to people who need builder access.
- Remove obsolete rows and refresh the list.
- Ask affected users to reload Applications and verify the result.
Applications grants do not have an expiry field. Use your organization's review and offboarding process to remove stale access.
Troubleshooting
A recently saved grant is not visible
Select All, then select Refresh. Confirm that you are not viewing a different scope tab.
Removing a row did not remove access
Check for:
- a direct grant at another scope;
- a grant to any of the user's roles;
- a broader Global, Workspace, or Application grant; or
- administrator access.
Capabilities are additive, so any applicable grant can preserve access.
The remove operation fails
Reload the list and try again. The row may already have been removed in another session. If the page reports an access error, confirm that you are an administrator or can open the Applications More tools.
A grant shows an old creation time after an update
Updating a matching grant changes its capabilities in place. The visible date is the original grant time, so use the current capability badges to confirm the saved state.
