Skip to main content
Everyone

Permissions and module visibility

What you can do in Elie comes from two things: the modules your organisation is entitled to, and what your role grants inside them. This page is the reference for both.

How visibility works

Two layers decide every action, in this order:

  1. Your organisation must be entitled to the module. Platform staff set entitlements, and no role reaches past them.
  2. Inside an entitled module, your role must grant the permission.

Neither layer hides much. Your menu lists the modules whatever your role holds, because the server authorises each request as it is made rather than each page as it opens. A permission you lack therefore surfaces late: the module is replaced by the 403 / Access Forbidden screen, or a list simply comes back empty with no message. Voice IntELIEgence is the one exception — it is absent from the menu until it is enabled for you, and its address redirects to Access denied. For the full set of symptoms, see What your role can see.

Where permissions are granted

Roles carry permissions; departments and groups carry none. A role's grid is at Access ControlRoles → the role, under Permissions. Each row is one feature, each column one verb, and a - in a cell means that feature has nothing for that verb, so nobody can be granted it. Search by feature name matches the row labels below, spelled exactly as they appear here.

The seven columns

ColumnTicking it lets someone
VIEWSee that an item exists, and read its metadata or summary.
LISTEnumerate every item of that kind.
CREATEAdd a new one.
DELETEDelete one.
READOpen the item itself — its content, configuration or details.
UPDATEChange it, including who belongs to it.
EXECUTEPrivileged actions: triggering a run, assigning roles, resetting a password, verifying integrity.

Knowledge Base

Feature rowWhat it coversColumns offered
Knowledge Base · KbA knowledge base itself — that it exists, its configuration, its members.All seven
Knowledge Base · DocumentThe documents inside one: adding, reading, re-versioning and deleting them.All seven

IntelieDocs

Feature rowWhat it coversColumns offered
IntELIEdocs · DocumentDocuments: their metadata, their content, uploading and deleting them.All seven
IntELIEdocs · SmartextractA Smart Extract orchestrator's configuration.All seven
IntELIEdocs · SmartclassA Smart Classes orchestrator's configuration.All seven
IntELIEdocs · SmartqueueA Smart Queue orchestrator's configuration.All seven
IntELIEdocs · SmartredactA Smart Redact orchestrator's configuration.All but EXECUTE
IntELIEdocs · Redact OriginalViewing the unredacted original of a redacted document.VIEW only
IntELIEdocs · GroupDocument groups and their members.READ, CREATE, UPDATE, DELETE, EXECUTE
IntELIEdocs · WorkbenchViewing documents and tasks in the workbench, and actioning them.READ, EXECUTE
IntELIEdocs · IntakeTriggering document intake processing.EXECUTE only
IntELIEdocs · DoceventTriggering document lifecycle events.EXECUTE only
IntELIEdocs · Audit EventsReading audit events recorded inside IntelieDocs.READ only
IntELIEdocs · Audit IntegrityTriggering an integrity check over those events.EXECUTE only

IntelieKonnect

Feature rowWhat it coversColumns offered
IntELIEKonnect · ImportImport connectors, and starting a run with Fetch now.All seven
IntELIEKonnect · ExportExport connectors, and starting a delivery by hand.All seven

Voice IntELIEgence

Voice rows are prefixed Voice, not the module's full name.

Feature rowWhat it coversColumns offered
Voice · AppA voice application — that it exists, and its configuration.VIEW, CREATE, UPDATE
Voice · ConversationConversations inside an application.VIEW, DELETE
Voice · AuditVoice audit records.VIEW only
Voice · ExportVoice export records.VIEW only

Identity and users

Feature rowWhat it coversColumns offered
Identity & Users · UserPeople: their profiles, their account status, and admin actions such as forcing a password reset or revoking a session.All but CREATE — people arrive by invitation
Identity & Users · InvitationInvitations. CREATE sends one; DELETE revokes a pending one.All but UPDATE
Identity & Users · DepartmentDepartments and their members.All seven
Identity & Users · GroupGroups and their members.All seven

Roles and permissions

Feature rowWhat it coversColumns offered
Roles & Permissions · RoleRoles and their permission sets. UPDATE edits a role's permissions; it is EXECUTE that assigns or revokes a role on a person.All seven

Audit logs

Feature rowWhat it coversColumns offered
Audit Log · EventsTenant audit events.VIEW, LIST, READ, EXECUTE
Audit Log · IntegrityIntegrity checks over those events; EXECUTE starts a verification run.VIEW, LIST, READ, EXECUTE

Next

Steps verified on . Something wrong with this page?