Permissions
When sharing an object with someone in the system, a user can grant the recipient any of the following permissions to the object.
-
View: This level of permission allows the recipient to share the object in one of the following ways:
- System-wide so that all users can see it (not available for all objects)
- With external users who don’t have a Workfront license (not available for all objects)
- With an email address (available only for documents)
-
Contribute: (not available for all objects)
-
Manage: When someone shares an object, the recipient’s rights to the object are determined by a combination of the recipient’s access level and the permissions to the object that were granted by the sharer. The lowest degree of access available in that combination is what determines what the recipient can do with the object.
INFO
Example: If the recipient’s access level doesn’t allow project editing, that person can’t edit or delete a project even if the sharer granted permissions to manage it.Or, if the recipient’s access level allows project editing, but the sharer granted view-only permissions to a project, the user cannot edit or delete the project.
The following table compares a user’s general access to objects (defined by the user’s access level) to permissions for a specific shared object:
Access level | Permissions | |
---|---|---|
Granted by a Workfront administrator in the access level of a user | ✓ | |
Granted by a user sharing an object at the object level | ✓ | |
Inherited from a higher-ranking shared object | ✓ |
- If a user shares an object with certain permissions and that object has any child objects below it, the recipient inherits the same permissions for those child objects.
- If an access level restricts users from deleting certain objects, this doesn’t keep them from deleting child objects that are contained in those objects.
More example scenarios
When Olivia shares a Workfront project with Tony, Tony’s access to it is determined by a combination of two things:
- Tony’s access level, assigned by the Workfront administrator
- Tony’s permissions to the project, specified by Olivia
Tony’s actions on the project can be further restricted on the project, but they cannot be unrestricted beyond what is allowed on his access level:
- If Tony’s access level doesn’t allow him to create tasks, he can’t add tasks to the project , even if Olivia gave him permissions to add tasks to it.
- If Tony’s access level does allow him to create tasks, but Olivia did not grant permissions to add tasks to the project, he can’t add tasks to that project, but he can add tasks to other projects where he has been granted permissions to do so.