Skip to main content

Permissions

Lifecycle permissions control what users can do while an instance is in a state. Use them to make records editable early in a process, read-only after approval, or restricted to specific roles during review.

Common permission decisions​

  • Which roles can view or edit the instance in this state.
  • Whether attributes are editable in this state.
  • Whether users can link or unlink related instances.
  • Whether users can delete the instance.
  • Which promote actions are available from this state.

These permissions affect standard forms, widgets, query results, and API responses. For example, an attribute can appear as read-only when the current state does not allow the user to update it.

Validation guidance​

Validate each role's experience after changing permissions or promote actions. Check that users can complete the actions they need and that restricted actions are hidden or blocked as expected.