Skip to main content

Permissions

Permissions in Docwize determine which features, modules, and actions a user or group can use within the system. They are separate from document-level access, which is managed through Access Control.

Permissions can be assigned at group level or at individual user level. Configuring permissions is a task for administrators with access to the Admin Console.

How permissions work

Group-level permissions are the foundation. When a group is created, administrators assign permissions to it. Every user in that group inherits those permissions. Because groups can represent roles or access tiers, this is the most scalable way to manage permissions across many users.

User-level permissions can be added on top of group membership where an individual needs capabilities that their group does not have. These appear alongside inherited group permissions in the user's Permissions panel.

Permissions inherited from a group appear greyed out in the user's Permissions panel and cannot be changed from there. To change a permission that comes from a group, it must be changed at the group level — which will affect all members of that group.

A user may belong to multiple groups. Their effective permissions include those from all groups they belong to, plus any permissions granted directly at the user level.

note

Permissions control what features and actions a user can access. They are separate from folder security, project security, and document-level access, which are managed in Access Control. A user may have permission to create documents but still be unable to see a particular document if they lack folder or project access.

Accessing the Permissions panel

The Permissions panel is accessed through the Settings dialog, available from both the Users and Groups pages in the Admin Console.

Settings icon

'Settings' icon

Once the Settings dialog is open, the left-hand navigation provides access to the following panels:

PanelWhat it shows
DetailsMain details for the selected user or group
PermissionsThe permissions list for the selected user or group
FoldersFolder-access scope
Dataviews & InterfacesAccess to dataviews and interfaces
ProjectsProject-related access
RecordsRecords-related access or record scope

Permission reference

Admin Console Permissions panel

Admin Console Permissions panel

The table below lists all visible permission categories and options.

CategoryPermissionDescription
Administration and SecurityGroup and User AdminAllows administration of users and groups in the Admin Console.
Access Token GenerationAllows creation or management of access tokens for integrations or API-related use.
View AuditsAllows viewing audit information or audit logs.
Explorer and ViewsCreate FoldersAllows creating folders in Explorer.
View FoldersAllows folders to be visible in Explorer.
View LocationsAllows locations to be visible in Explorer.
View Folder ViewsAllows access to saved folder-view layouts or folder-based views in Explorer.
View Tag TreeAllows the tag tree to be visible in Explorer.
ReportsAllows access to report-style or dataview-style outputs in Explorer.
View InterfacesAllows access to configured interfaces in Explorer.
View DashboardsAllows dashboard views to be visible in Explorer.
Documents and OfficeFull Document DetailsAllows access to the full Document Details view.
Create DocumentsAllows creation of new documents, including placeholders where applicable.
Delete Self Owned DocumentsAllows deletion of documents owned by the current user.
Delete Other Users DocumentsAllows deletion of documents owned by other users.
Document PermissionsAllows viewing or managing document-level permissions.
Unlock DocumentsAllows locked documents to be unlocked.
Enable WOPIAllows documents to be opened through WOPI-compatible Office viewing functionality.
Enable WOPI EditingAllows editing through WOPI-compatible Office editing functionality.
Can TranslateAllows use of document translation features.
Enable Auto RedactionAllows use of automated redaction features.
Review DocumentAllows access to document review actions such as annotations, notes, tags, or similar review tools.
Deny DownloadsPrevents document downloads for the selected user or group.
Bypass Edit SecurityAllows document editing despite normal edit-security restrictions.
Docwize OCRAllows use of Docwize's OCR functionality to process and extract text from document images.
WorkflowsWorkflows - CreateAllows workflows to be created or initiated.
Workflows - Create TemplateAllows workflow templates to be created.
Workflows - View AllAllows all workflows on a document to be viewed in Document Details.
Workflows - Revoke AnyAllows workflows to be revoked regardless of ownership.
Workflows - Modify Action RecipientAllows workflow action recipients to be changed.
Workflows - Create Global FilterAllows global workflow filters to be added to the Inbox.
Replay WorkflowAllows workflow steps or actions to be replayed.
Undo Actions TakenAllows previously taken workflow actions to be undone.
Use Legacy SignaturesAllows the legacy signature workflow to be used instead of the modern digital signing flow.
Workflows - Assign ExternalAllows workflow actions to be assigned to external users or contacts.
Adhoc Action RequestsAllows creation of ad hoc action requests outside of a structured workflow template.
ProjectsView Project DetailsAllows project details to be viewed.
Create ProjectAllows projects to be created.
Edit ProjectAllows projects to be edited.
Delete ProjectAllows projects to be deleted.
Project PermissionsAllows project-level permissions to be managed.
ContactsView ContactsAllows contacts to be viewed.
Create ContactsAllows contacts to be created.
Edit ContactsAllows contacts to be edited.
Delete ContactsAllows contacts to be deleted.
Metadata and InterfacesLookup ListsAllows access to or management of lookup lists.
Manage Document Custom FieldsAllows document custom fields to be created or managed.
Default extraction configAllows configuration of default extraction settings applied when documents are uploaded.
Dataview SettingsAllows dataview settings to be configured or changed.
Create Email RulesAllows email rules to be created.
Manage InterfacesAllows interfaces to be created or managed.
ToolsCan ChatAllows access to the chat tool.
Can Edit System AgentsAllows editing and configuration of Docwize AI system agents.
Can BucketsAllows access to the Buckets feature, where users can create document collections, manage their contents, and share them with other users or groups.
Manage Company SignaturesAllows company-level signatures to be created and managed. Required to enable and configure the digital signing feature for the instance.
Manage ToursAllows creating and editing of guided product tours.
Tag RecommendationsAllows use of AI-powered tag recommendations.
IntegrationsManage ConnectorsAllows third-party connectors to be configured.

Before changing permissions

Change permissions at group level where possible. Permissions assigned to a group apply immediately to all current and future members. User-level permissions are harder to audit and maintain at scale — use them only for genuine exceptions.

Understand what a permission grants before assigning it. Some permissions are broad. "Group and User Admin" grants administration of all users and groups in the Admin Console. "Delete Other Users Documents" applies to documents owned by anyone in the system. "Bypass Edit Security" overrides normal editing restrictions.

Remember that permissions and document access are separate. Granting a permission (such as "Create Documents" or "View Interfaces") does not automatically grant access to specific documents, folders, or projects. Document visibility is controlled by Access Control.

Check what a user inherits from their groups before granting user-level permissions. If the required permission already comes from a group, a user-level grant is redundant. If you need to restrict a permission a group grants, that change must be made at the group level.

Coordinate group-level changes with anyone who manages that group. Changing a group permission affects every member immediately.

Common risks

RiskHow it typically happensWhat to check
Permission granted to wrong groupAdmin edits a group without checking all membersReview the full membership of a group before changing its permissions
User has more access than intendedUser is in multiple groups; cumulative permissions exceed what was plannedCheck all group memberships for the user, not just the primary group
Destructive permissions granted too broadly"Delete Other Users Documents" or "Workflows - Revoke Any" assigned at group levelReserve high-impact permissions for small, trusted groups or specific users
Bypassing normal restrictions unintentionally"Bypass Edit Security" granted without understanding its scopeReview with your implementation team before granting this permission.
Permissions confused with document accessAdmin grants permissions but user still cannot see documentsCheck folder and project access separately via Access Control
Group-level permission cannot be removed from user panelAdmin tries to remove a greyed-out permission at the user levelChange the permission at the group level; note this affects all group members

Testing permission changes

Before applying changes in a live environment:

  1. Identify a test user account with the same group memberships as the affected users.
  2. Apply the intended permission change (at group or user level).
  3. Log in as the test user — or ask a trusted colleague with that account — and verify:
    • Can they access the features or actions they should now have?
    • Are they blocked from features or actions they should not have?
    • Does the change behave as expected in both directions?
  4. If testing a group-level change, confirm the change has not inadvertently affected other members of that group.

Docwize does not have an impersonate user or view-as-user feature. A separate test account is required to verify permission changes from a user's perspective.

  • Users — create accounts, assign groups, configure user-level permissions
  • Groups — create and manage groups; assign group-level permissions and folder access
  • Access Control — folder security, project security, and document-level access; separate from permissions
  • Admin Console — overview of all Admin Console areas
  • Digital Signing — user-facing guide to the signing workflow enabled by Manage Company Signatures