Edit a permission group¶
Tune exactly what a permission group grants: the actions its members can take, the records they can reach, and which protected fields they may see in the clear.
The editor opens when you create a group or click Edit on a group in the permission groups list. Its settings are organized into tabs, and a Save button at the top stores your changes — an unsaved changes note appears while you have edits pending.
Prerequisites
- You are signed in to the Backoffice with a role that grants the Manage permissions permission.
- You have selected the workspace for the firm whose group you want to edit.
Set the roles¶
The Roles tab holds a tree of the capabilities the group can grant. Select a branch to grant everything beneath it, or expand it to grant individual actions.
Note
The roles tree only offers what your firm is entitled to hold. The platform sets a ceiling on each firm's roles, so you can never grant a member more than your firm itself is permitted — the tree simply hides anything above that ceiling. These ceilings are managed for you by the platform.
Set the resources¶
The Resources tab controls which records and areas the group can reach.
At the top of the tab is the Use workspace permissions switch:
- On (the usual choice) — the group follows the workspace's own access rules. Whatever the workspace already allows a member to reach, this group allows too, and the resource rows below are shown but inactive.
- Off — the group ignores the workspace default and reaches only the resources you select in the tree below. Turn this off when you need to spell out access explicitly.
Choose which protected fields members can reveal¶
The Field masking tab lets you lift masking on specific fields for this group's members. When a firm protects a field with field-level security — for example a government ID — most people see it masked. Ticking a field here lets this group's members see that field in the clear.
Only fields the workspace actually masks appear in this list. If nothing is masked in the workspace, the tab tells you there is nothing to unmask.
Warning
Revealing a protected field exposes sensitive personal data to everyone in the group. Grant it only to members who genuinely need it, such as compliance reviewers.
Rename the group¶
The General tab holds the group's Name. Edit it and click Save.