Skip to main content

Capability Role and Permission Behavior Guide

Warrant lets you decide, one capability at a time, what each person can do.

Written by Austin Carroll

1. What this guide is for

This guide explains exactly what each of the seven capability groups do and don't allow, how roles combine, and what happens when something is not granted. Read it before building or editing roles so you do not grant authority you did not intend to.

The seven capability groups are View, Scan, Review, Create/Upload, Submit, Approve, and Admin.

The Roles matrix also lists Comment, Relevancy Feedback, View Brand Portal, Manage Brand Portal, Delete and Reassign. Each is covered below alongside the group it relates to.

2. The three rules that govern everything

Rule 1: Deny by default

When Enforce capability permissions is on (Settings → Members → Roles), a person can do only what a role assigned to them grants, either directly or through a group. A capability that no assigned role grants is denied. There are no "block" settings and no implicit grants.

What this means in practice:

  • Someone with no role assignment can do nothing that is gated by a capability.

  • Turning enforcement on for a company that has no role assignments yet locks out every non-admin immediately. Warrant shows a confirmation before you switch enforcement on, and lists the users who would lose access. Read it. Turning enforcement off again restores the earlier behavior and is a single click.

  • Legacy company-level admins (Admin, Super Admin, Owner) are not subject to capability denial and keep the full capability set. This is why the person turning enforcement on often sees nothing wrong while everyone else is locked out. Test with a non-admin account before you announce the change.

  • With enforcement off, capabilities are not enforced and the roles below have no effect. Folder and file sharing permissions still apply either way.

Rule 2: Roles are additive

A role is a bundle of capabilities. A person's effective permissions are the union of every active role assigned to them, whether assigned directly to the person or inherited through a group.

  • Giving someone a second role can only add capability. It can never take one away.

  • There is no "deny" capability. To remove an ability, remove or pause the role (or group membership) that supplies it. If two roles overlap, removing one of them does not remove a capability the other still grants.

  • To check what someone can do, open their page from Settings → Members. Effective capabilities shows every capability they actually hold, and Roles lists each role that reaches them, labelled when it is Draft or Inactive or only arrives through a paused group.

Rule 3: Separation of duties protects approvals

When Separation of duties (maker-checker) is on, a person cannot approve an asset they submitted themselves, even if they hold both Submit and Approve. This is enforced when the approval is attempted, not by convention. The switch has no effect while Enforce capability permissions is off.

  • Assigning both Submit and Approve to one person requires a written rationale, stored on the assignment.

  • An admin who overrides a separation-of-duties block must enter a written justification. The override and the justification are written to the audit log.

  • The rationale requirement also counts roles in Draft or Inactive status, so switching a role on later cannot quietly create the combination.

  • Editing a role's permissions, or switching a paused role back to Active, so that someone assigned to it would hold both Submit and Approve is refused until their assignment has a written rationale.

3. Capability reference

Each group below says what it allows, what it does not, and the traps to avoid.

View

Allows: Seeing assets, folders, saved searches, reports and dashboards, and their compliance results.

Does not allow: Running scans, commenting, uploading, submitting or approving. View is a prerequisite for most other work in practice, so nearly every role includes it.

Watch for:

  • View is also the baseline for creating a report: you cannot save a report over data you cannot see.

  • Role without View: A person whose roles do not include View cannot open assets, folders or reports, even if their roles grant other capabilities such as Comment. Make sure every role that needs library access includes View.

  • File and folder sharing grants (who can open a given folder or file) are separate from the View capability and still apply.

  • Brand Portal access has its own pair of capabilities, View Brand Portal and Manage Brand Portal. Until a role (in any status) is granted either one, View also gives Brand Portal view. After that, only people holding an active role with View Brand Portal, Manage Brand Portal or Admin can open it.

Scan

Allows: Starting compliance scans on assets.

Does not allow: Changing scan findings' relevance, adding review feedback, or submitting results for approval. Removing Scan blocks scanning everywhere in Warrant.

Review

Allows: Reviewer actions on scan findings in an approval: dismissing a finding, restoring it, and marking it relevant.

Does not allow: Approving, submitting, or uploading.

Watch for:

  • Relevancy Feedback is its own capability. Thumbs up and down votes on findings tune how strictly each policy is applied for your company, so it is granted separately from Review. Submitter and Creator do not include it. Repeated "not relevant" votes on a policy raise a policy task, make Warrant apply that policy more strictly, and can lead to its new findings being dismissed automatically. Grant Relevancy Feedback sparingly.

  • Comment is a separate capability from Review. You can let a submitter comment inline on a specific scan flag without giving them reviewer feedback powers, so the flag-level conversation lives with the flag for audit purposes. Grant Comment alone to give discussion access without influence over relevancy scoring.

Create/Upload

Allows: Adding new assets and uploading files. Enforced everywhere assets are created or uploaded.

Does not allow: Submitting for approval, approving, or administering. Creating an asset does not let you send it into an approval flow.

Watch for: Reviewer roles (Proofreader, LOB Reviewer) do not include Create/Upload by design, so reviewers cannot add assets.

Submit

Allows: Sending an asset into an approval flow, including resubmitting.

Does not allow: Approving. A person with Submit but not Approve never appears in the approver picker.

Watch for:

  • Submit and Approve in the same person triggers the rationale requirement in Rule 3.

  • It is easy to tick Approve when you meant Submit. The two checkboxes sit next to each other in the permission grid, and checkbox changes save immediately with no confirmation. Re-read a role after editing it.

Approve

Allows: Acting as an approver on an approval step. Only people holding this capability can be selected in the approver picker, and Warrant rejects an approval from anyone without it.

Does not allow: Approving your own submission (separation of duties), uploading, or submitting, unless those are separately granted.

Watch for:

  • Approve is the only difference between a LOB Reviewer (approves) and a Proofreader (review only).

  • Approval steps can be assigned to a group. Any active member of the group can fulfill a group-assigned step. If the group is paused, its members cannot act on that step (see section 5).

Delete

Allows: Permanently deleting assets and versions. Archive is always available to everyone.

Watch for: The Allow all members to delete switch on the Roles page lets every member delete, whatever their roles say. Leave it off to grant Delete only through roles.

Reassign

Allows: Reassigning approvals to a different reviewer or group, without granting Admin. Approvals cannot be reassigned to a paused group.

Admin

Allows: Managing the company's configuration, including roles and permissions, groups, users and invitations, and the Enforce capability permissions and separation-of-duties settings.

Watch for:

  • Settings access: Someone whose admin power comes only from the Admin capability on a role (for example Compliance Admin) can open the Approvals and AI Policies settings. Roles, Groups, Members and the other admin settings need the Admin or Super Admin access level.

  • Admin through a group: A group with Admin access gives its active members real admin permission. A user who is already an Admin or Super Admin is not restricted by group settings.

  • Role-change limits: Only Super Admins can grant or edit Super Admin. An Admin cannot grant Super Admin or edit a Super Admin's role, and nobody can change their own role.

  • Invitations: A Member can invite at the Member level only. Inviting at Admin or Super Admin level requires you to be an Admin or Super Admin.

  • Pausing a role that holds Admin asks for confirmation and names who is affected. Pausing a role that would remove your own admin access is refused.

  • Only admins can change a role's or group's status.

4. Capability-by-role matrix

"Yes" means the role grants the capability. A blank means denied. Roles are bundles you can edit, so check your own workspace on Settings → Members → Roles.

Role template

View

Scan

Review

Comment

Create/Upload

Submit

Approve

Admin

Submitter

Yes

Yes

Yes

Creator

Yes

Yes

Yes

Yes

Yes

Proofreader

Yes

Yes

Yes

LOB Reviewer

Yes

Yes

Yes

Yes

Yes

Compliance Admin

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Company Admin / Super Admin / Owner (legacy)

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

The table shows the core capabilities. In addition, Proofreader and LOB Reviewer include Relevancy Feedback, and Compliance Admin includes Relevancy Feedback, Delete and Reassign. No built-in role includes View Brand Portal or Manage Brand Portal. Capabilities added to the built-in roles after your workspace was set up are not added to your copies automatically, so check the Roles page.

Common configurations

What you want

Grant

Do not grant

Marketers who build and send for approval but never approve

Creator

Approve

Staff who can scan and discuss findings but not submit

Submitter

Submit, Create/Upload

Reviewers who give feedback but cannot sign off

Proofreader

Approve

Authoritative approvers who cannot alter the asset pipeline

LOB Reviewer

Create/Upload, Submit

An admin who must also submit

Admin plus Submit (written rationale required)

Approve on the same person, unless unavoidable

5. Groups, status, and how changes take effect

Groups and role assignment

  • Groups are membership only. A person gets a group's roles by being a member. You can also assign a role to a person directly.

  • Folder and file sharing grants (who can open a given folder or file) are a separate system and are not changed by roles.

Draft and Inactive: pausing roles and groups

Every role and every group has a status.

Status

Meaning

Grants anything?

Active

Works normally. The default for all existing roles and groups.

Yes

Draft

Being built. You can edit it and assign people and groups ahead of time.

No

Inactive

Retired but kept, with assignments, for audit and possible re-activation.

No

What a paused role does: grants nothing to anyone assigned to it, directly or through a group. Switching it back to Active restores permissions immediately, with no sign-out. Use Draft to stage a role change for many people and switch it on in one step.

What a paused group does: its members get nothing from it. No admin powers, no roles, no access to files and folders shared with the group, no approvals routed through the group and no notifications because of it. Membership, access and role assignments are preserved while the group is paused.

Safeguards and gotchas:

  • Pausing a group that is a reviewer on waiting approvals shows a warning with the count and asks for confirmation. Approvals cannot be reassigned to a paused group.

  • A paused group's item grants still restrict the item. They just stop granting access to its members.

  • Pausing the only role someone holds can leave them with no access. Warrant warns you and names the people affected. If that role is their only View source, they will see no assets, folders or reports.

  • Status changes are recorded in the audit log, and the access-review export labels paused roles and groups, for example "QA Uploader (Draft)".

When changes take effect

Role changes, group changes and promotions or demotions apply right away, with no sign-out needed. After any change, check the person's Effective capabilities on their page under Settings → Members to confirm the result.

6. Configuration checklist: avoid unintended authority

  1. Before enabling enforcement: Assign roles to everyone first, including your own team. Confirm the lockout list in the pre-enable dialog.

  2. Start from templates: Begin with Submitter, Creator, Proofreader, LOB Reviewer and Compliance Admin rather than building from scratch.

  3. Stage with Draft: Build new roles as Draft, assign them, review, then switch them to Active in one step.

  4. Keep Submit and Approve apart: Give them to the same person only when you must, and write down why.

  5. Be sparing with Relevancy Feedback: Repeated "not relevant" votes can lead Warrant to dismiss a policy's new findings automatically for your company.

  6. Check for overlaps: Because roles add up, look for people who hold roles through both a group and a direct assignment.

  7. Re-open the role after you save it: Permission checkboxes save immediately. Confirm that the boxes you intended are the ones set.

  8. Test as a non-admin: Admins bypass capability checks, so an admin's own view proves nothing.

  9. Use Effective capabilities on a person's page to answer "why can't someone submit?" and the access-review export for periodic recertification.

  10. Demoting an admin? The change applies immediately. Confirm that the person's Access level now reads Member, and check their Effective capabilities.

7. Audit and access reviews

  • Role, permission, status and separation-of-duties changes are recorded in the audit log, with who, what and from-to values.

  • The access-review export is a point-in-time report of every user, their groups, roles and effective permissions, with paused roles and groups labelled.

Did this answer your question?