Workflow Authorisation Overview
This article provides an overview of the levels of permission that users can be assigned for viewing and editing workflows.
Estimated Read Time: 7 minutes
Sections in this article:
Overview
Workflow authorisation settings control what users can see and do within workflows. Each user can be assigned a different level of access, and this can vary across each workflow board.
Gatekeeper offers several types of workflow authorisation, each suited to a different responsibility. Broadly, these split into two levels:
- Workflow-level access: applies across an entire workflow board, covering every card in every phase.
- Card and phase-level access: applies only to specific cards, or to cards while they sit in a specific phase. This lets a user interact with cards relevant to them, even if they don't otherwise have access to the workflow board itself.
Workflow-Level Access
-
Workflow Administrator: The highest level of workflow authorisation, applied globally across the tenant rather than to a single workflow. They can create new workflows, edit all existing ones, and add cards directly to any board. They have admin access to all cards, including the ability to delete or archive cards, and can complete approvals or actions on behalf of the card owner. They also have access to Workflow Reports.
- Local Workflow Administrator: Grants administrative access to specific workflows. They must be explicitly assigned to each relevant workflow, allowing them to edit the workflow configuration and add cards directly to the board. They cannot archive or delete the workflow, or create new workflows.
- Local Workflow Collaborator: Provides read-only access to specific workflows. They can view all cards within the workflow, but cannot edit them. Like Local Workflow Administrators, they must be explicitly assigned as collaborators for each relevant workflow.
Card and Phase-Level Access
These permission types are commonly used for people who don't hold any of the workflow-level access types above.
- Dynamic View Only Access: Automatically grants read-only access to cards on a specific workflow for the card creator and related users. This access follows the card through every phase of its lifecycle, meaning the relevant people can follow a card's progress throughout the whole workflow. This can be granted to the Card Creator themselves, their Team Manager, and their whole team.
- Phase Owners: Lets a user manage a card while it's in a specific phase, even if they don't hold any workflow-level access. A phase owner can view, open, and act on the card for as long as it's in that phase.
- Phase Collaborators: Lets a user view a specific card while it's in a specific phase, without needing any workflow-level access. Unlike phase owners, they can't make changes or take any action on the card.
Note: When a user is tagged in a message on a workflow card, they're granted limited access to it. To learn more, see Workflow Messaging.
Assign Workflow Authorisation
Who Can Assign Workflow Authorisation?
The ability to assign access to others depends on the user's permissions. The table below outlines which users can assign each type of workflow authorisation:
| Workflow Authorisation Type | Who Can Assign |
| Workflow Administrator | Global Administrators with the Users additional permission |
| Local Workflow Administrator | Workflow Administrators |
| Local Workflow Collaborator | Workflow Administrators |
| Dynamic View Only Access | Workflow Administrators |
| Phase Owners | Workflow Administrators and Local Workflow Administrators |
| Phase Collaborators | Workflow Administrators, Local Workflow Administrators, and Phase Owners |
Assign a Workflow Administrator
To assign a user as a Workflow Administrator:
- From the navigation menu, expand Settings, then click Users.
- Expand the 3 dots on the relevant user, then select Edit.

- From the Additional Permissions section, select the Workflow Administrator checkbox, then click Save.

Assign Local Workflow Access
Workflow Administrators can manage access to specific workflows by assigning Local Administrators and Collaborators. To assign local access to a workflow:
- Click Workflows from the navigation menu.
- Expand the 3 dots on the relevant workflow, then select Local Workflow Authorisation.

- Click Set Workflow Administrator or Set Workflow Collaborator as required.

- Select the relevant user, team, or workflow group from the dropdown menu, then click Save.
Assign Dynamic View Only Access
To enable read-only access to the Card Creator and related users:
- Click Workflows from the navigation menu.
- Expand the 3 dots on the relevant workflow, then select Local Workflow Authorisation.

- Under Dynamic View Only Access, enable the toggles for the relevant user types.

Once enabled, the relevant people automatically gain read-only access when a card is submitted, which remains in place through every phase of the workflow.
Note: Enabling Card Creator's team requires Card Creator and Team Manager of Card Creator to also be enabled. Turning this on automatically enables the other toggles.
Assign Phase Owners
Phase ownership can be configured on each phase of a workflow. To learn more, see Workflow Phase Owners Overview.
FAQs
If I enable Dynamic View Only Access, does it apply to cards that are already sitting on the workflow, or only new ones?
Access to existing cards will be granted when they move phase. Access is worked out at the point a card enters a phase, so cards already in progress won't be visible until their next transition.
What happens if a user ends up with more than one type of access on the same workflow or card?
The most privileged access always applies. For example, someone who's a Local Workflow Collaborator individually but also belongs to a team assigned as a Local Workflow Administrator gets administrator rights, since that outranks collaborator. The same logic applies at card level: a user with Dynamic View Only Access who's also made a phase owner gets edit access while the card is on that phase.
If I assign a workflow group/team as a Local Workflow Administrator/Collaborator, and later remove a user from that group/team, do they lose access?
Yes. Group/team membership and local workflow access stay in sync, so removing someone from the group/team removes their local access automatically, without needing to update the workflow separately.
I have access to a workflow card, but can't open the vendor or contract record it relates to in the Vault. Why not?
Workflow access and Vault access are controlled separately. Workflow authorisation, such as being a Local Workflow Collaborator or phase owner, is assigned through the workflow itself, while access to records in the Vault depends on a user's core roles and permissions. Having one doesn't automatically grant the other.