Permissions reference

Every permission with a one-line meaning, the item it applies to and where it appears on the Roles page.

Every API call is allowed or refused by a permission: an action name such as records:update, optionally limited to one item such as a record type or a queue. This page lists every permission and what it allows. Roles are made of these permissions, and a service account's access key can do exactly what its roles allow.

For the rule format that combines permissions, conditions and field hiding, see Policy format.

How permissions are named

A permission is service:action. Two wildcards exist in rules:

  • records:* means every records permission.
  • * means everything.

Most permissions apply to the whole workspace. Several are checked against a specific item, called the resource, so a role can be limited to it:

Resource Used by
A record type key, such as invoices records:*, fields:*
A queue key queues:*
A workbook key sheets:*
A Drive space key drive:*
A calendar key calendar:*
A form key forms:*
A site key (or assets for images) content:*
A messaging connection key comms:*
A register key pos:*
A knowledge collection key knowledge:*
A record type key (the template's record type) pdf:generate

Everything else is checked against the whole workspace. When a rule's resources is ["*"] or left out, it covers every item.

Special cases

  • The owner of a workspace implicitly holds every permission and cannot be removed or reduced. There is no other all-powerful account type: someone who needs everything gets a role that grants *.
  • Service accounts (access keys) are never the owner. They hold exactly what their roles grant.
  • People who are not signed in hold only what the role marked Use for visitors who are not signed in grants. See Public endpoints.
  • A permission you do not hold answers 403 FORBIDDEN. A record, workspace or item you may not read at all answers 404 NOT_FOUND.
  • You can only give away what you hold. Someone who is not the owner cannot create or edit a role, assign people or keys to a role, or invite someone into a role, if that grants more than they hold themselves.
  • Account and billing routes (billing:*, your own security settings, creating a workspace) are for signed-in people and never for access keys.

The permissions

The last column says where to find each permission on the Roles page (Team & Permissions › Roles): the app name, then the level. A permission shown as "Only through Advanced rules" is not part of any level.

Business records

Resource: record type key.

Permission What it allows On the Roles page
records:read Read records and their fields Business records › Can view
records:create Create records Business records › Can add & edit
records:update Change records Business records › Can add & edit
records:delete Delete records Business records › Full control
records:import Import records from CSV Business records › Can add & edit
records:export Export records to CSV Business records › Can add & edit

Record types and fields

Resource: workspace (types) or record type key (fields).

Permission What it allows On the Roles page
types:read List record types Business records › Can view
types:create Create record types Business records › Full control
types:update Rename or change a record type Only through Advanced rules
types:delete Delete record types Business records › Full control
fields:read List fields Business records › Can view
fields:create Add fields and change them (auto-numbering, formulas, descriptions) Business records › Full control
fields:delete Delete fields Business records › Full control
quality:run Start a data quality scan Business records › Full control

Analytics

Resource: workspace.

Permission What it allows On the Roles page
insights:query Run queries and open reports Analytics & reports › Can query & read
insights:manage Save reports and dashboards, manage indexes and external data sources Analytics & reports › Full control

Ask Axis

Resource: workspace.

Permission What it allows On the Roles page
agent:chat Chat with the assistant Ask Axis assistant › Can use
agent:view_usage See AI usage and spend Ask Axis assistant › Use & see AI spend
agent:manage_mcp Manage shared connectors for outside tools Ask Axis assistant › Full control

Functions

Resource: workspace.

Permission What it allows On the Roles page
functions:read Read functions and their code Custom code › Can view
functions:create Create, change and delete functions Custom code › Full control
functions:invoke Run a function Custom code › Can run

Flows

Resource: workspace.

Permission What it allows On the Roles page
flows:read See flows and run history Automations › Can view
flows:create Create flows Automations › Full control
flows:update Change flows. A flow then runs with the editor's permissions Automations › Full control
flows:delete Delete flows Automations › Full control
flows:run Start a flow by hand Automations › Can run

Work queues

Resource: queue key.

Permission What it allows On the Roles page
queues:read See a queue, its items and reports Work queues › Can view
queues:create Create queues Work queues › Full control
queues:update Change a queue's stages and rules Work queues › Full control
queues:delete Delete a queue, or delete items Work queues › Full control
queues:enqueue Add items to a queue Work queues › Can work the queue
queues:transition Move, scan and claim items, and run stage buttons Work queues › Can work the queue

Sheets

Resource: workbook key.

Permission What it allows On the Roles page
sheets:read Open and read workbooks Sheets › Can view
sheets:write Edit cells, rows, columns and tabs Sheets › Can edit
sheets:manage Create, rename and delete workbooks Sheets › Full control

Drive

Resource: space key.

Permission What it allows On the Roles page
drive:read List and download files in team spaces Files › Can view
drive:write Upload, move and delete files in team spaces Files › Can edit
drive:manage Create and delete spaces, and manage their sharing Files › Full control

Calendar

Resource: calendar key (team and record calendars).

Permission What it allows On the Roles page
calendar:read See a calendar's events Calendars › Can view
calendar:write Add, move and delete events Calendars › Can edit
calendar:manage Change the calendar, its booking page and subscription link, or delete it Calendars › Full control

Document templates

Resource: workspace (read, manage), record type (generate).

Permission What it allows On the Roles page
pdf:read See templates and generated documents Document templates › Can view
pdf:generate Generate a PDF from a template. Also needs write access to the Drive space it is saved in Document templates › Can generate
pdf:manage Write and edit templates, and preview Document templates › Full control

Accounting

Resource: workspace.

Permission What it allows On the Roles page
accounting:read Read the journal, ledger, balances and reports Accounting ledger › Can view
accounting:post Post journal entries and reversals Accounting ledger › Can post entries

Payments

Resource: workspace.

Permission What it allows On the Roles page
payments:read See payment connections and links Collecting payments › Can view
payments:collect Create, cancel and refresh payment links Collecting payments › Can collect
payments:manage Add, change and delete provider connections Collecting payments › Full control

In-store checkout

Resource: register key.

Permission What it allows On the Roles page
pos:read See registers and sales In-store checkout › Can view
pos:sell Ring up sales and void unpaid ones In-store checkout › Can sell
pos:refund Refund paid sales In-store checkout › Full control
pos:manage Set up registers, brands and devices In-store checkout › Full control

Messaging

Resource: connection key.

Permission What it allows On the Roles page
comms:read See connections, templates and the delivery log Messaging › Can view
comms:connect Add a provider account Messaging › Full control
comms:manage Change or delete connections, write templates, edit the do-not-contact list Messaging › Full control
comms:send Send a message to one recipient Messaging › Can send
comms:broadcast Send to many recipients at once Messaging › Full control

Online stores

Resource: workspace.

Permission What it allows On the Roles page
marketplaces:read See which stores are connected Online stores › Can see connections
marketplaces:use Read live store data, and call the store from functions Online stores › Can browse the store
marketplaces:connect Connect, test and disconnect stores Online stores › Full control

Ad campaigns

Resource: workspace.

Permission What it allows On the Roles page
campaigns:read Read spend and performance Ad campaigns › Can view
campaigns:connect Connect and disconnect ad accounts Ad campaigns › Full control
campaigns:sync Refresh data from the platforms Ad campaigns › Can run campaigns
campaigns:manage Pause, resume and change budgets and dates (this spends money) Ad campaigns › Can run campaigns
campaigns:schedule Schedule such changes for later Ad campaigns › Can run campaigns

Website content

Resource: site key, or assets for images.

Permission What it allows On the Roles page
content:read Read pages, including drafts Website content › Can view
content:write Write and edit pages, upload images, use AI writing help Website content › Can write drafts
content:publish Publish, unpublish and archive pages Website content › Can publish
content:manage Create, change and delete sites Website content › Full control
content:deliver Serve published content to the public. Give it to the visitor role to open a site to the web Published pages › Readable by anyone

Forms

Resource: form key.

Permission What it allows On the Roles page
forms:read Open a form Forms › Can view
forms:submit Submit a form Forms › Can fill in
forms:responses Read what people submitted Forms › Can read answers
forms:manage Build, publish and delete forms Forms › Full control

Knowledge base

Resource: collection key.

Permission What it allows On the Roles page
knowledge:read List collections and documents Knowledge base › Can search
knowledge:query Search. Returns document text Knowledge base › Can search
knowledge:write Add and remove documents Knowledge base › Can add documents
knowledge:manage Create and delete collections, choose indexed record types Knowledge base › Full control

Notifications

Resource: workspace.

Permission What it allows On the Roles page
notifications:read See notification rules Notifications › Can view
notifications:create Create and change rules Notifications › Full control
notifications:delete Delete rules Notifications › Full control

Audit trail

Resource: workspace.

Permission What it allows On the Roles page
audit:read Read the record change history Audit trail › Can view

People and permissions

Resource: workspace.

Permission What it allows On the Roles page
iam:invite Invite people People & permissions › Can invite people
iam:manage_members Manage people, service accounts and access keys People & permissions › Can manage people
iam:manage_groups Create and edit roles People & permissions › Full control
iam:simulate Ask whether someone can do something (Access check) People & permissions › Can manage people

Workspace and billing

Resource: workspace.

Permission What it allows On the Roles page
org:update Change workspace name and default currency, and menu groups Organization settings › Can change settings
billing:read See the plan, usage and statements (signed-in people only, not keys) Plan & invoices from AxisIQ › Can view
billing:manage Subscribe, change and cancel the plan (signed-in people only, not keys) Plan & invoices from AxisIQ › Can change the plan