Skip to content

Delegated rights without full admin

Not everyone needs to be a full administrator to maintain ONE area. The full admin (tenant_role:manage) sees everything; but in the permission matrix you can grant a single targeted right that opens just that one tab — the colleague cannot reach the other settings.

Each opens on a full admin OR that targeted right — so the full admin doesn’t need it separately, while the delegated colleague gets exactly this much:

Right What it opens What they can do
site:manage Sites tab Site master data and granting access
layout:manage Diary elements + Lists tabs The diary’s structure, fields and shared lists
home:manage Home page tab The content of the post-login page
report:template:manage Report template tab The structure and appearance of the diary PDF
name_list:manage Roster tab The colleague roster used for attendance
task:issue Instructions + Tasks tabs Issuing management instructions / tasks
  1. Go to the Permissions tab and find (or create) the role you are delegating to.
  2. Turn on the right above in the role’s row (if a column is unclear, hover its header).
  3. Assign the role to the colleague on the Users / Invite tab.

Role and matrix details: Custom roles and the permission matrix.

  • The right opens the TAB; the system checks scope separately. For example, editing the company base of the Home page requires access to all sites; with a site-scoped right the colleague can only edit that site’s level.
  • The full admin already sees these — grant the delegated right only to someone who is NOT a full admin.
  • The Administrator role’s rights cannot be restricted (locked row in the matrix); if someone needs a narrower scope, give them a custom role built from delegated rights rather than trying to restrict the Administrator.

Last updated: