Permissions reference
Every permission with a one-line meaning, the item it applies to and where it appears on the Roles page.
Every API call is allowed or refused by a permission: an action name such as records:update, optionally limited to one item such as a record type or a queue. This page lists every permission and what it allows. Roles are made of these permissions, and a service account's access key can do exactly what its roles allow.
For the rule format that combines permissions, conditions and field hiding, see Policy format.
How permissions are named
A permission is service:action. Two wildcards exist in rules:
records:*means every records permission.*means everything.
Most permissions apply to the whole workspace. Several are checked against a specific item, called the resource, so a role can be limited to it:
| Resource | Used by |
|---|---|
A record type key, such as invoices |
records:*, fields:* |
| A queue key | queues:* |
| A workbook key | sheets:* |
| A Drive space key | drive:* |
| A calendar key | calendar:* |
| A form key | forms:* |
A site key (or assets for images) |
content:* |
| A messaging connection key | comms:* |
| A register key | pos:* |
| A knowledge collection key | knowledge:* |
| A record type key (the template's record type) | pdf:generate |
Everything else is checked against the whole workspace. When a rule's resources is ["*"] or left out, it covers every item.
Special cases
- The owner of a workspace implicitly holds every permission and cannot be removed or reduced. There is no other all-powerful account type: someone who needs everything gets a role that grants
*. - Service accounts (access keys) are never the owner. They hold exactly what their roles grant.
- People who are not signed in hold only what the role marked Use for visitors who are not signed in grants. See Public endpoints.
- A permission you do not hold answers
403 FORBIDDEN. A record, workspace or item you may not read at all answers404 NOT_FOUND. - You can only give away what you hold. Someone who is not the owner cannot create or edit a role, assign people or keys to a role, or invite someone into a role, if that grants more than they hold themselves.
- Account and billing routes (
billing:*, your own security settings, creating a workspace) are for signed-in people and never for access keys.
The permissions
The last column says where to find each permission on the Roles page (Team & Permissions › Roles): the app name, then the level. A permission shown as "Only through Advanced rules" is not part of any level.
Business records
Resource: record type key.
| Permission | What it allows | On the Roles page |
|---|---|---|
records:read |
Read records and their fields | Business records › Can view |
records:create |
Create records | Business records › Can add & edit |
records:update |
Change records | Business records › Can add & edit |
records:delete |
Delete records | Business records › Full control |
records:import |
Import records from CSV | Business records › Can add & edit |
records:export |
Export records to CSV | Business records › Can add & edit |
Record types and fields
Resource: workspace (types) or record type key (fields).
| Permission | What it allows | On the Roles page |
|---|---|---|
types:read |
List record types | Business records › Can view |
types:create |
Create record types | Business records › Full control |
types:update |
Rename or change a record type | Only through Advanced rules |
types:delete |
Delete record types | Business records › Full control |
fields:read |
List fields | Business records › Can view |
fields:create |
Add fields and change them (auto-numbering, formulas, descriptions) | Business records › Full control |
fields:delete |
Delete fields | Business records › Full control |
quality:run |
Start a data quality scan | Business records › Full control |
Analytics
Resource: workspace.
| Permission | What it allows | On the Roles page |
|---|---|---|
insights:query |
Run queries and open reports | Analytics & reports › Can query & read |
insights:manage |
Save reports and dashboards, manage indexes and external data sources | Analytics & reports › Full control |
Ask Axis
Resource: workspace.
| Permission | What it allows | On the Roles page |
|---|---|---|
agent:chat |
Chat with the assistant | Ask Axis assistant › Can use |
agent:view_usage |
See AI usage and spend | Ask Axis assistant › Use & see AI spend |
agent:manage_mcp |
Manage shared connectors for outside tools | Ask Axis assistant › Full control |
Functions
Resource: workspace.
| Permission | What it allows | On the Roles page |
|---|---|---|
functions:read |
Read functions and their code | Custom code › Can view |
functions:create |
Create, change and delete functions | Custom code › Full control |
functions:invoke |
Run a function | Custom code › Can run |
Flows
Resource: workspace.
| Permission | What it allows | On the Roles page |
|---|---|---|
flows:read |
See flows and run history | Automations › Can view |
flows:create |
Create flows | Automations › Full control |
flows:update |
Change flows. A flow then runs with the editor's permissions | Automations › Full control |
flows:delete |
Delete flows | Automations › Full control |
flows:run |
Start a flow by hand | Automations › Can run |
Work queues
Resource: queue key.
| Permission | What it allows | On the Roles page |
|---|---|---|
queues:read |
See a queue, its items and reports | Work queues › Can view |
queues:create |
Create queues | Work queues › Full control |
queues:update |
Change a queue's stages and rules | Work queues › Full control |
queues:delete |
Delete a queue, or delete items | Work queues › Full control |
queues:enqueue |
Add items to a queue | Work queues › Can work the queue |
queues:transition |
Move, scan and claim items, and run stage buttons | Work queues › Can work the queue |
Sheets
Resource: workbook key.
| Permission | What it allows | On the Roles page |
|---|---|---|
sheets:read |
Open and read workbooks | Sheets › Can view |
sheets:write |
Edit cells, rows, columns and tabs | Sheets › Can edit |
sheets:manage |
Create, rename and delete workbooks | Sheets › Full control |
Drive
Resource: space key.
| Permission | What it allows | On the Roles page |
|---|---|---|
drive:read |
List and download files in team spaces | Files › Can view |
drive:write |
Upload, move and delete files in team spaces | Files › Can edit |
drive:manage |
Create and delete spaces, and manage their sharing | Files › Full control |
Calendar
Resource: calendar key (team and record calendars).
| Permission | What it allows | On the Roles page |
|---|---|---|
calendar:read |
See a calendar's events | Calendars › Can view |
calendar:write |
Add, move and delete events | Calendars › Can edit |
calendar:manage |
Change the calendar, its booking page and subscription link, or delete it | Calendars › Full control |
Document templates
Resource: workspace (read, manage), record type (generate).
| Permission | What it allows | On the Roles page |
|---|---|---|
pdf:read |
See templates and generated documents | Document templates › Can view |
pdf:generate |
Generate a PDF from a template. Also needs write access to the Drive space it is saved in | Document templates › Can generate |
pdf:manage |
Write and edit templates, and preview | Document templates › Full control |
Accounting
Resource: workspace.
| Permission | What it allows | On the Roles page |
|---|---|---|
accounting:read |
Read the journal, ledger, balances and reports | Accounting ledger › Can view |
accounting:post |
Post journal entries and reversals | Accounting ledger › Can post entries |
Payments
Resource: workspace.
| Permission | What it allows | On the Roles page |
|---|---|---|
payments:read |
See payment connections and links | Collecting payments › Can view |
payments:collect |
Create, cancel and refresh payment links | Collecting payments › Can collect |
payments:manage |
Add, change and delete provider connections | Collecting payments › Full control |
In-store checkout
Resource: register key.
| Permission | What it allows | On the Roles page |
|---|---|---|
pos:read |
See registers and sales | In-store checkout › Can view |
pos:sell |
Ring up sales and void unpaid ones | In-store checkout › Can sell |
pos:refund |
Refund paid sales | In-store checkout › Full control |
pos:manage |
Set up registers, brands and devices | In-store checkout › Full control |
Messaging
Resource: connection key.
| Permission | What it allows | On the Roles page |
|---|---|---|
comms:read |
See connections, templates and the delivery log | Messaging › Can view |
comms:connect |
Add a provider account | Messaging › Full control |
comms:manage |
Change or delete connections, write templates, edit the do-not-contact list | Messaging › Full control |
comms:send |
Send a message to one recipient | Messaging › Can send |
comms:broadcast |
Send to many recipients at once | Messaging › Full control |
Online stores
Resource: workspace.
| Permission | What it allows | On the Roles page |
|---|---|---|
marketplaces:read |
See which stores are connected | Online stores › Can see connections |
marketplaces:use |
Read live store data, and call the store from functions | Online stores › Can browse the store |
marketplaces:connect |
Connect, test and disconnect stores | Online stores › Full control |
Ad campaigns
Resource: workspace.
| Permission | What it allows | On the Roles page |
|---|---|---|
campaigns:read |
Read spend and performance | Ad campaigns › Can view |
campaigns:connect |
Connect and disconnect ad accounts | Ad campaigns › Full control |
campaigns:sync |
Refresh data from the platforms | Ad campaigns › Can run campaigns |
campaigns:manage |
Pause, resume and change budgets and dates (this spends money) | Ad campaigns › Can run campaigns |
campaigns:schedule |
Schedule such changes for later | Ad campaigns › Can run campaigns |
Website content
Resource: site key, or assets for images.
| Permission | What it allows | On the Roles page |
|---|---|---|
content:read |
Read pages, including drafts | Website content › Can view |
content:write |
Write and edit pages, upload images, use AI writing help | Website content › Can write drafts |
content:publish |
Publish, unpublish and archive pages | Website content › Can publish |
content:manage |
Create, change and delete sites | Website content › Full control |
content:deliver |
Serve published content to the public. Give it to the visitor role to open a site to the web | Published pages › Readable by anyone |
Forms
Resource: form key.
| Permission | What it allows | On the Roles page |
|---|---|---|
forms:read |
Open a form | Forms › Can view |
forms:submit |
Submit a form | Forms › Can fill in |
forms:responses |
Read what people submitted | Forms › Can read answers |
forms:manage |
Build, publish and delete forms | Forms › Full control |
Knowledge base
Resource: collection key.
| Permission | What it allows | On the Roles page |
|---|---|---|
knowledge:read |
List collections and documents | Knowledge base › Can search |
knowledge:query |
Search. Returns document text | Knowledge base › Can search |
knowledge:write |
Add and remove documents | Knowledge base › Can add documents |
knowledge:manage |
Create and delete collections, choose indexed record types | Knowledge base › Full control |
Notifications
Resource: workspace.
| Permission | What it allows | On the Roles page |
|---|---|---|
notifications:read |
See notification rules | Notifications › Can view |
notifications:create |
Create and change rules | Notifications › Full control |
notifications:delete |
Delete rules | Notifications › Full control |
Audit trail
Resource: workspace.
| Permission | What it allows | On the Roles page |
|---|---|---|
audit:read |
Read the record change history | Audit trail › Can view |
People and permissions
Resource: workspace.
| Permission | What it allows | On the Roles page |
|---|---|---|
iam:invite |
Invite people | People & permissions › Can invite people |
iam:manage_members |
Manage people, service accounts and access keys | People & permissions › Can manage people |
iam:manage_groups |
Create and edit roles | People & permissions › Full control |
iam:simulate |
Ask whether someone can do something (Access check) | People & permissions › Can manage people |
Workspace and billing
Resource: workspace.
| Permission | What it allows | On the Roles page |
|---|---|---|
org:update |
Change workspace name and default currency, and menu groups | Organization settings › Can change settings |
billing:read |
See the plan, usage and statements (signed-in people only, not keys) | Plan & invoices from AxisIQ › Can view |
billing:manage |
Subscribe, change and cancel the plan (signed-in people only, not keys) | Plan & invoices from AxisIQ › Can change the plan |
Related
- Policy format
- Authentication
- In the product: Team & Permissions