Skip to main content
A global permission is an access grant placed directly on the Workspace (organization) entity itself, the top of the permission hierarchy. Because every object, page, view, and record sits beneath the workspace, a grant here cascades to all of them unless a more specific grant overrides it. This is how you give someone workspace-wide reach without granting each entity one by one. Manage them from the Workspace panel at the top of Settings → Permissions.

How it works

Permissions in Custral are access grants on entities, not a separate list of named capabilities. Each grant pairs a subject with a level:
  • Subject: a user or a group.
  • Level: an access level: Read, Comment, Edit, Delete, Admin, or Owner (each level includes everything below it).
A grant on the Workspace entity is “global” because it flows down the inheritance chain to every sub-entity. Granting a group Admin on the workspace makes that group an admin of everything in it; granting Read makes the workspace broadly readable.
When the Workspace panel shows “No global grants. All users inherit access from their role,” it means nobody has an explicit workspace-level grant and access is coming entirely from each user’s role and from grants on individual entities.

Granting workspace-wide access

1

Open the Workspace panel

Go to Settings → Permissions. The Workspace panel sits at the top, above the Sections & Pages and Objects tabs.
2

Edit the workspace grants

Click Edit to open the access modal for the workspace entity.
3

Add a subject and level

Add a user or group and pick an access level (e.g. Admin for workspace administrators). Save.
The grant takes effect immediately and cascades to every object, page, and record unless a narrower grant overrides it lower down.

Relationship to roles and entity grants

  • Roles set each user’s baseline.
  • Entity grants (on a specific object, page, or record) layer on top. See Permissions overview.
  • Global (workspace) grants are entity grants on the workspace itself, so they’re the broadest layer.

Troubleshooting

See also