Workflow Authorisation Overview
This article provides an overview of the levels of permission that users can be assigned for viewing and editing workflows.
Estimated Read Time: 7 minutes
Sections in this article:
Overview
Workflow authorisation settings control what users can see and do within workflows. Each user can be assigned a different level of access, and this can vary across each workflow board.
Gatekeeper offers several types of workflow authorisation, each suited to a different responsibility. Broadly, these split into two levels:
- Workflow-level access: applies across an entire workflow board, covering every card in every phase.
- Card and phase-level access: applies only to specific cards, or to cards while they sit in a specific phase. This lets a user interact with cards relevant to them, even if they don't otherwise have access to the workflow board itself.
Workflow-Level Access
-
Workflow Administrator: The highest level of workflow authorisation, applied globally across the tenant rather than to a single workflow. They can create new workflows, edit all existing ones, and add cards directly to any board. They have admin access to all cards, including the ability to delete or archive cards, and can complete approvals or actions on behalf of the card owner. They also have access to Workflow Reports.
- Local Workflow Administrator: Grants administrative access to specific workflows. They must be explicitly assigned to each relevant workflow, allowing them to edit the workflow configuration and add cards directly to the board. They cannot archive or delete the workflow, or create new workflows.
- Local Workflow Cards Manager: Grants full card access on specific workflows, without access to the workflow's configuration. They must be explicitly assigned to each relevant workflow, and can view, create, edit, and progress cards through phases. Unlike a Local Workflow Administrator, they can't delete or archive cards, open the Controls tab on a card, or change the workflow's configuration.
- Local Workflow Collaborator: Provides read-only access to specific workflows. They can view all cards within the workflow, but cannot edit them. They must be explicitly assigned to each relevant workflow.
Card and Phase-Level Access
These permission types are commonly used for people who don't hold any of the workflow-level access types above.
- Dynamic View Only Access: Automatically grants read-only access to cards on a specific workflow for the card creator and related users. This access follows the card through every phase of its lifecycle, meaning the relevant people can follow a card's progress throughout the whole workflow. This can be granted to the Card Creator themselves, their Team Manager, and their whole team.
- Phase Owners: Lets a user manage a card while it's in a specific phase, even if they don't hold any workflow-level access. A phase owner can view, open, and act on the card for as long as it's in that phase. They will lose access to the card once it moves out of the phase.
- Phase Collaborators: Lets a user view a specific card while it's in a specific phase, without needing any workflow-level access. Unlike phase owners, they can't make changes or take any action on the card. They will lose access to the card once it moves out of the phase.
Note: When a user is tagged in a message on a workflow card, they're granted limited access to it. To learn more, see Workflow Messaging.
Workflow Access Comparison Table
Expand the section below to see a full breakdown of each access type:
Workflow Access Comparison Table
| Workflow-Level Access | Card and Phase-Level Access | ||||||
|---|---|---|---|---|---|---|---|
| Capability | Workflow Administrator | Local Workflow Administrator | Local Workflow Cards Manager | Local Workflow Collaborator | Dynamic View Only Access | Phase Owner | Phase Collaborator |
| Add new workflows | ✓ | – | – | – | – | – | – |
| Configure the workflow (e.g. phases, forms, access, triggers, transitions) | ✓ | ✓ | – | – | – | – | – |
| View cards | All cards, tenant-wide | All cards on the workflow | All cards on the workflow | All cards on the workflow | Cards they created or are related to | Cards while in their phase | Cards while in their phase |
| Create cards | ✓ | ✓ | ✓ | – | – | – | – |
| Edit and progress cards through phases | ✓ | ✓ | ✓ | – | – | ✓ | – |
| Reassign the phase owner | ✓ | ✓ | ✓ | – | – | ✓ | – |
| Open the Controls tab on a card, for example to delete or archive cards | ✓ | ✓ | – | – | – | – | – |
Assign Workflow Authorisation
Who Can Assign Workflow Authorisation?
The ability to assign access to others depends on the user's permissions. The table below outlines which users can assign each type of workflow authorisation:
| Workflow Authorisation Type | Who Can Assign |
| Workflow Administrator | Global Administrators with the Users additional permission |
| Local Workflow Administrator | Workflow Administrators |
| Local Workflow Cards Manager | Workflow Administrators |
| Local Workflow Collaborator | Workflow Administrators |
| Dynamic View Only Access | Workflow Administrators |
| Phase Owners | Workflow Administrators, Local Workflow Administrators, and Local Workflow Cards Managers |
| Phase Collaborators | Workflow Administrators, Local Workflow Administrators, Local Workflow Cards Manager, and Phase Owners |
Assign a Workflow Administrator
To assign a user as a Workflow Administrator:
- From the navigation menu, expand Settings, then click Users.
- Expand the 3 dots on the relevant user, then select Edit.

- From the Additional Permissions section, select the Workflow Administrator checkbox, then click Save.

Assign Local Workflow Access
Workflow Administrators can manage access to specific workflows by assigning Local Administrators, Cards Managers, and Collaborators. To assign local access to a workflow:
- Click Workflows from the navigation menu.
- Expand the 3 dots on the relevant workflow, then select Local Workflow Authorisation.

- Click Set Workflow Administrator, Set Workflow Cards Manager, or Set Workflow Collaborator as required.

- Select the relevant user, team, or workflow group from the dropdown menu, then click Save.
Assign Dynamic View Only Access
To enable read-only access to the Card Creator and related users:
- Click Workflows from the navigation menu.
- Expand the 3 dots on the relevant workflow, then select Local Workflow Authorisation.

- Under Dynamic View Only Access, enable the toggles for the relevant user types.

Once enabled, the relevant people automatically gain read-only access when a card is submitted, which remains in place through every phase of the workflow.
Note: Enabling Card Creator's team requires Card Creator and Team Manager of Card Creator to also be enabled. Turning this on automatically enables the other toggles.
Assign Phase Owners
Phase ownership can be configured on each phase of a workflow, so that users are automatically assigned to cards when they enter that phase. To learn more, see Workflow Phase Owners Overview.
Assign Phase Collaborators
Phase collaborators are assigned on individual workflow cards. To do this:
- Navigate to the workflow and click on the relevant card to open it.
- Click the
pencil icon next to Phase Collaborator. - Select the required users from the dropdown list, then click Update.

FAQs
If I enable Dynamic View Only Access, does it apply to cards that are already sitting on the workflow, or only new ones?
Access to existing cards will be granted when they move phase. Access is worked out at the point a card enters a phase, so cards already in progress won't be visible until their next transition.
What happens if a user ends up with more than one type of access on the same workflow or card?
The most privileged access always applies. For example, someone who's a Local Workflow Collaborator individually but also belongs to a team assigned as a Local Workflow Administrator gets administrator rights, since that outranks collaborator. The same logic applies at card level: a user with Dynamic View Only Access who's also made a phase owner gets edit access while the card is on that phase.
If I assign a workflow group or team as a Local Workflow Administrator, Cards Manager or Collaborator, and later remove a user from that group or team, do they lose access?
Yes. Group/team membership and local workflow access stay in sync, so removing someone from the group/team removes their local access automatically, without needing to update the workflow separately.
I have access to a workflow card, but can't open the vendor or contract record it relates to in the Vault. Why not?
Workflow access and Vault access are controlled separately. Workflow authorisation, such as being a Local Workflow Collaborator or phase owner, is assigned through the workflow itself, while access to records in the Vault depends on a user's core roles and permissions. Having one doesn't automatically grant the other.
What's the difference between a Local Workflow Administrator and a Local Workflow Cards Manager?
Both can view, create, edit and progress every card on the workflow they've been assigned to. The difference is that a Local Workflow Cards Manager can't change the workflow's configuration (e.g. adding phases, amending triggers, configuring transitions, and assigning local access), delete or archive cards, or open the Controls tab on a card.
Do you get a notification when you're assigned access?
Assigning Workflow Administrators, Local Workflow Administrators/Cards Managers/Collaborators or Dynamic View Only Access does not trigger a notification. Phase Owners and Phase Collaborators can be notified when they're assigned, but only if it's been enabled for that phase. See Configure Workflow Notifications for how to set this up.
What's the difference between a Phase Collaborator and a Local Workflow Collaborator?
A Phase Collaborator only has read-only access to the specific card they're added to, and only while it's in that phase. A Local Workflow Collaborator has read-only access to every card on the whole workflow, regardless of phase.