Before you start
Consider whether a Profile or a Package is more appropriate. Manual grants are best for individual exceptions. If you need to give the same permissions to several users, a Profile or Package will save time and make future changes much easier.
Granting a permission
- Open Manage Permissions and select the application.
- If the app has more than one permission, click on the permission you want to grant.
- On the permission detail page, click New Authorization.
- In the modal, type the user's personal code or click Search User to find them by name.
- The system immediately checks:
- If the user is the Founder — manual grants are unnecessary and blocked.
- If the user already has an active grant for this permission — a duplicate warning will appear.
- If the user already receives this permission via a Profile — a profile overlap warning will appear (you can still proceed; the manual grant will take precedence).
- Select the permission value (access level, structures, groups, etc.).
- Optionally set a scope parameter (e.g., a specific structure for UOR-type permissions).
- Optionally set Valid From and Valid Until dates.
- Click Confirm. The permission is active immediately.
Editing a permission
- Find the user in the Active Authorizations table.
- Click the pencil button on their row.
- Adjust the value or the validity dates. Note: the start date is read-only — it is preserved from the original grant to maintain an accurate audit trail. A new record is created internally for history.
- Confirm. The change takes effect immediately.
Change Detection: If you open the edit modal but do not actually change anything, submitting will show a "No changes detected" notice and the record will not be updated.
Revoking a permission
- Find the user in the Active Authorizations table.
- Click the ban button on their row.
- Confirm. The permission is deactivated immediately and moves to the Inactive tab.
Restoring a revoked permission
Switch to the Inactive / History tab. Find the revoked record and click Restore. You can optionally set a new validity window for the restored grant. A new active record is created — the old revoked record is kept for auditing.