Roles, permissions and entity access
Access in Governax is decided by two independent things: the role you hold in the organisation, and whether you can reach a given entity. Confusing the two accounts for most access questions we get.
Two separate questions#
Holding a role does not imply reaching an entity, and reaching an entity does not imply permission to change things in it.
The three organisation roles#
If you are looking for a read-only role, it is not here. Read-only is a property of your relationship to one entity, not to the whole company, so it lives on the entity axis as reader. That is what lets you give an auditor one entity’s ledger without giving them every entity’s.
The three entity grades#
Being able to open an entity is not the same as being able to change it. Everyone granted an entity holds one of three grades in it, and they form a ladder: each one includes everything below it.
It is entity_admin rather than admin because the bare word already means two other things here: a Governax platform administrator, and an administrator of a whole organisation. An entity admin is neither. They run exactly the entity they were granted and have no standing in any other, nor in the organisation itself.
Reader is the default. Someone granted an entity with no grade chosen, including anyone who accepts an invitation carrying an entity, is a reader until somebody deliberately raises them. That is the safe end on purpose: a new route added to the product is closed to them until a decision is made about which grade should reach it.
What is actually gated today#
This is where documentation usually drifts from reality, so here is the precise position.
Which entities you can open#
Owners and admins bypass entity membership entirely and are entity admins of every entity in the organisation, including ones created later. Everyone else must be granted the specific entity, and hitting an entity they were not granted returns NOT_ENTITY_MEMBER.
Governax platform administrators#
Separate from organisation roles, Governax staff hold a platform administrator role used to review new workspaces and, if necessary, suspend an organisation. It is not something a customer is granted, and it is not part of your role model.
- Suspension and the other blocked states are described in When access is blocked.