What are auto-inherit rules?
An auto-inherit rule is a system-level configuration that automatically grants a permission to users who meet a defined condition — for example, "all members of group STRUCTURED_USERS receive the intranet permission".
These rules are evaluated periodically by the system. When a user gains or loses the qualifying condition (e.g., they join or leave a group), their permission is added or revoked automatically without any administrator action.
How to identify auto rules in Manage Permissions
On a permission's detail page, the description header shows an Automatic Access Rules block listing all active rules for that permission. Each rule appears as a colored badge:
- Structured Staff — all members of the structured staff group
- Heads of Unit — all area managers and department leaders
- …and other organization-specific rules
If a badge shows a warning icon, it means some users who qualify for the rule have been given a manual override (different value). Click the icon tooltip to see who.
Auto vs Manual in the active authorizations table
In the Active Authorizations table, rows for auto-rule members are highlighted with a colored background. Their source column shows an auto badge. You cannot disable or edit these rows directly — access is controlled by the rule condition itself.
Manual override of an auto permission
If a user meets an auto rule but you need to give them a different value (e.g., a higher access level), you can issue a Manual Grant on top of the auto rule:
- Click New Authorization and select the user.
- Set the override value.
- The active table will show both the auto row and your manual row, with a warning indicating the manual override takes precedence.
Losing auto access (revocation)
When a user no longer meets an auto-rule condition, the system logs a lost event in the auto-log and the permission is removed from their active grants automatically. The Inactive tab will show a auto-revoked row for auditing. You can restore the permission manually if needed by clicking the restore button.