Skip to main content

Workflow Permissions and Security

Understand workflow step access levels — View, Act, Manage, and Supervise — and how permissions are enforced.

Written by James Ross

Overview

Workflow permissions control what each user can do at a workflow step. Access levels are determined by the user's role in the workflow — participant, assigned user, admin, or supervisor.

Access Levels

  • View — the user can see the workflow step detail but cannot action tasks. Applies to participants who are not assigned to the current task.

  • Act — the user can view and action tasks (approve, reject, complete). Applies to users assigned to the current task.

  • Manage — the user has full access including escalation, reassignment, return for change, and cancellation. Applies to admins and workflow owners.

  • Supervise — the user can observe and oversee the workflow. Applies to supervisors configured on the process.

Quick Steps

Non-Participant Access

  • A user who is not a participant and has no override sees a no-permission tooltip.

  • They cannot view or action the workflow step.

Private Process Workflows

When a workflow runs on a private process, tasks can be assigned to non-stakeholders:

  • The non-stakeholder can action the task (approve, reject, escalate).

  • They cannot navigate back to the process details — an error states the process is private.

Privileged User Bypass

Users with elevated permissions can action tasks not assigned to them from the Workflow Tasks section. The audit logs the acting user distinctly from the assignee.

Important: Unauthorized users are always blocked. Permission checks happen at every step.

Did this answer your question?