<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=691116991096043&amp;ev=PageView&amp;noscript=1">
Skip to content
  • There are no suggestions because the search field is empty.

Workflow Authorisation Overview

This article provides an overview of the levels of permission that users can be assigned for viewing and editing workflows.

   Estimated Read Time: 7 minutes


Sections in this article: 



Overview

Workflow authorisation settings control what users can see and do within workflows. Each user can be assigned a different level of access, and this can vary across each workflow board.

Gatekeeper offers several types of workflow authorisation, each suited to a different responsibility. Broadly, these split into two levels:

  • Workflow-level access: applies across an entire workflow board, covering every card in every phase.
  • Card and phase-level access: applies only to specific cards, or to cards while they sit in a specific phase. This lets a user interact with cards relevant to them, even if they don't otherwise have access to the workflow board itself.

Workflow-Level Access

  • Workflow Administrator: The highest level of workflow authorisation, applied globally across the tenant rather than to a single workflow. They can create new workflows, edit all existing ones, and add cards directly to any board. They have admin access to all cards, including the ability to delete or archive cards, and can complete approvals or actions on behalf of the card owner. They also have access to Workflow Reports.

  • Local Workflow Administrator: Grants administrative access to specific workflows. They must be explicitly assigned to each relevant workflow, allowing them to edit the workflow configuration and add cards directly to the board. They cannot archive or delete the workflow, or create new workflows.
  • Local Workflow Collaborator: Provides read-only access to specific workflows. They can view all cards within the workflow, but cannot edit them. Like Local Workflow Administrators, they must be explicitly assigned as collaborators for each relevant workflow.

Card and Phase-Level Access

These permission types are commonly used for people who don't hold any of the workflow-level access types above.

  • Dynamic View Only Access: Automatically grants read-only access to cards on a specific workflow for the card creator and related users. This access follows the card through every phase of its lifecycle, meaning the relevant people can follow a card's progress throughout the whole workflow. This can be granted to the Card Creator themselves, their Team Manager, and their whole team.
  • Phase Owners: Lets a user manage a card while it's in a specific phase, even if they don't hold any workflow-level access. A phase owner can view, open, and act on the card for as long as it's in that phase. 
  • Phase Collaborators: Lets a user view a specific card while it's in a specific phase, without needing any workflow-level access. Unlike phase owners, they can't make changes or take any action on the card.

Note: When a user is tagged in a message on a workflow card, they're granted limited access to it. To learn more, see Workflow Messaging.


Assign Workflow Authorisation

Who Can Assign Workflow Authorisation?

The ability to assign access to others depends on the user's permissions. The table below outlines which users can assign each type of workflow authorisation:

Workflow Authorisation Type Who Can Assign
Workflow Administrator Global Administrators with the Users additional permission
Local Workflow Administrator Workflow Administrators
Local Workflow Collaborator Workflow Administrators
Dynamic View Only Access Workflow Administrators
Phase Owners Workflow Administrators and Local Workflow Administrators
Phase Collaborators Workflow Administrators, Local Workflow Administrators, and Phase Owners

Assign a Workflow Administrator

To assign a user as a Workflow Administrator: 

  1. From the navigation menu, expand Settings, then click Users.
  2. Expand the 3 dots on the relevant user, then select Edit.edit users
  3. From the Additional Permissions section, select the Workflow Administrator checkbox, then click Save.
    WF admin

Assign Local Workflow Access

Workflow Administrators can manage access to specific workflows by assigning Local Administrators and Collaborators. To assign local access to a workflow:

  1. Click Workflows from the navigation menu.
  2. Expand the 3 dots on the relevant workflow, then select Local Workflow Authorisation.
    edit local wf authorisation
  3. Click Set Workflow Administrator or Set Workflow Collaborator as required.
    Set local WF access
  4. Select the relevant user, team, or workflow group from the dropdown menu, then click Save.

Assign Dynamic View Only Access

To enable read-only access to the Card Creator and related users

  1. Click Workflows from the navigation menu.
  2. Expand the 3 dots on the relevant workflow, then select Local Workflow Authorisation.
    edit local wf authorisation
  3. Under Dynamic View Only Access, enable the toggles for the relevant user types.
    dynamic access toggles

Once enabled, the relevant people automatically gain read-only access when a card is submitted, which remains in place through every phase of the workflow.

Note: Enabling Card Creator's team requires Card Creator and Team Manager of Card Creator to also be enabled. Turning this on automatically enables the other toggles.

Assign Phase Owners

Phase ownership can be configured on each phase of a workflow. To learn more, see Workflow Phase Owners Overview.

FAQs

If I enable Dynamic View Only Access, does it apply to cards that are already sitting on the workflow, or only new ones?

Access to existing cards will be granted when they move phase. Access is worked out at the point a card enters a phase, so cards already in progress won't be visible until their next transition.

What happens if a user ends up with more than one type of access on the same workflow or card?

The most privileged access always applies. For example, someone who's a Local Workflow Collaborator individually but also belongs to a team assigned as a Local Workflow Administrator gets administrator rights, since that outranks collaborator. The same logic applies at card level: a user with Dynamic View Only Access who's also made a phase owner gets edit access while the card is on that phase.

If I assign a workflow group/team as a Local Workflow Administrator/Collaborator, and later remove a user from that group/team, do they lose access?

Yes. Group/team membership and local workflow access stay in sync, so removing someone from the group/team removes their local access automatically, without needing to update the workflow separately.

I have access to a workflow card, but can't open the vendor or contract record it relates to in the Vault. Why not?

Workflow access and Vault access are controlled separately. Workflow authorisation, such as being a Local Workflow Collaborator or phase owner, is assigned through the workflow itself, while access to records in the Vault depends on a user's core roles and permissions. Having one doesn't automatically grant the other.