Who can see a knowledge base
Access shows who reaches this knowledge base and which documents they get, and previews what an audience really retrieves. Changes happen on Documents and in Access Control.
- The Knowledge Base module visible in your left-hand navigation.
- These permissions: Knowledge Base · Kb — VIEW, Knowledge Base · Document — UPDATE.
- Read access to the roles, departments and groups directory — without it this page is replaced by Access Forbidden.
If Knowledge Base isn't in your navigation, your role doesn't have visibility for it — ask a workspace administrator, or see Permissions and module visibility.
Steps
Open the knowledge base, then select Access in its section navigation.
Select How access works. Layer 1 · KB access gates the whole knowledge base by role; Layer 2 · Document visibility is set per document, then intersected with the viewer’s role, department and people group at retrieval. Both must pass; Layer 2 only narrows.
Under Layer 2 · Document visibility, Roles in use, Departments and People groups list every tag in use. Unrestricted is the only value that widens reach.
Choose a Role, Department and Group, then select Preview access. The result — This audience can retrieve 12 of 40 documents. — marks each document Reachable or Not reachable with a reason, over the first 200 documents.
Layer 2 is edited on Documents: tick rows and select Reassign access, or open a document and select Edit beside its Access. A reassign replaces the tier and all three dimensions, and opens blank for a multi-row selection — saving untouched strips existing tags.
What success looks like
- The preview reports a count for your audience, with a reason per row.
- A reassign confirms with Access reassigned for 3 document(s).
- The document’s access summary reads Public — reachable by everyone, or Internal with your tags.
If something goes wrong
| Symptom | Likely cause | What to do |
|---|---|---|
| Access Forbidden replaces the page. | It also reads the roles, departments and groups directory. | Ask an administrator for those read permissions. |
| KB-scoped role grants are not available yet. | Neither that table nor access-change history is live in this build. | Manage grants in Access Control. |
| The preview is stamped computed locally or Layer-1 denied. | The server preview failed, or the audience fails Layer 1. | Trust a local result loosely; for Layer-1 denied, grant a role first. |
| Nobody can retrieve a document. | It is internal with no role, department or group tagged. | Reassign it with a tag, Unrestricted / all internal users, or Public. |
Next
- Roles, Departments and Groups — the Layer-2 dimensions; only a role carries permissions.
- Uploading documents — where access is first set.