Permissions
Every action in Mezzanine, from seeing balances to proposing a payment, is a permission. The Permissions page lists them all and shows exactly who holds each one. It’s where you change who can do what.
You’ll find it in the sidebar under System Controls → Permissions.
Why use it
Section titled “Why use it”When money moves, who could have done this?
needs a clear answer. This page gives it one permission at a time: the groups that hold it, the people who hold it directly, or everyone in the organization. It’s the page to open before an audit, after someone changes role, or when a teammate says they can’t see something they need.
How it works
Section titled “How it works”- You find a permission in the list, or search for it.
- You see who holds it: groups, individual people, or Everyone.
- You add or remove holders. Your changes are staged, not saved yet.
- You click Save changes and confirm. Only then does anyone’s access change.
- People who lack a permission can ask for it from the screen that turned them away. An Owner or Admin reviews the request in Requires Action.
When to use it
Section titled “When to use it”- Before an audit or board review, to check who can see or move what.
- When you set up a new group, to switch on what it can do. See Give an outside auditor view-only access.
- When one person needs a one-off permission that their group shouldn’t have. Add them directly.
- When access is too broad, for example a permission open to Everyone that should be limited to a group.
Using the page
Section titled “Using the page”Permissions are grouped into Money & Finance, Records & Documents and System Controls & Legal, then by the part of the product they cover. Each row shows who holds it at a glance: Everyone, Not granted, or the holders’ avatars. An app your organization hasn’t installed shows as one row tagged Not installed. Nobody can hold its permissions until it’s installed from the App Library.
Use Search permissions to find one by name.
Click a permission to open it on the right:
- What this permission does: a short description.
- Who has this: every group and person that holds it. A holder marked with a lock can’t be removed. The Owner group always holds everything.
- Add group or person: opens a list of Groups and People to add, plus Everyone at the top. Click Done when you’ve finished adding. Click the × on a holder to remove them.
As you make changes, a bar at the bottom counts them, for example 2 permissions changed
. Click Save changes, check the list under Save these changes?
, then click Save changes again. Discard throws your staged changes away. If you try to leave the page with unsaved changes, you’re asked whether to Discard and leave or Stay on this page.
Everyone
Section titled “Everyone”Some permissions can be open to the whole organization. Everyone and specific groups or people don’t mix. Adding a group or person to a permission held by Everyone switches Everyone off, and adding Everyone replaces the individual holders.
Edit permissions include the matching view
Section titled “Edit permissions include the matching view”Holding a permission that changes something also lets you see it. You don’t need to grant both.
| If someone holds | They can also |
|---|---|
| Manage team | View team |
| Manage groups | View groups |
| Edit permissions | View permissions |
| Add and edit contacts | View contacts |
| Start wallet verification | View wallet verification |
| Manage entities | View entities |
| Install and configure apps | View app library |
| Manage company files | View company files |
| Manage evergreen artifacts | View evergreen artifacts |
| Propose bill payments | View outgoing transfers |
| Propose internal transfers | View outgoing transfers |
| Manage recurring payments | View recurring payments |
Two exceptions. Start wallet verification doesn’t include View contacts. Edit general organization settings doesn’t include anything, because anyone can already open Organization Settings.
This page shows what was granted, not what follows from it. Someone who holds Manage team won’t be listed under View team, but they can still see the team.
Permissions only Owners and Admins can hold
Section titled “Permissions only Owners and Admins can hold”Some permissions come only with membership of the Admin or Owner group. They can’t be given to a custom group, to a person directly, or to Everyone, and they can’t be requested. On these, the page shows Only Owners and Admins can hold this.
in place of the add button.
- Manage team
- Manage groups
- Edit permissions
- Edit general organization settings
- Manage approval policies
Add and remove admins is held only by Owners. The page shows Only Owners can hold this.
To give someone one of these, add them to the Admin group on the Groups page. Only an Owner can do that.
Asking for a permission
Section titled “Asking for a permission”When you open a page or click a button you don’t have access to, you’ll see a message naming the permission you’re missing, such as You do not have permission to view contacts
, with a Request Permission button.
- Click Request Permission.A window opens titled Request permission.
- If you’re offered a choice under What do you need?, pick one. You’re usually offered the view permission and its matching edit permission.
- Optionally, explain why under Why do you need this? (optional). Whoever reviews it sees your words.
- Click Send request.The button changes to Requested, with
An administrator will review this from their inbox.
An Owner or Admin sees the request in Requires Action. They can grant the permission to you directly, or add you to a group that holds it. Joining a group gives you everything that group can do, not only the permission you asked for.
If the permission is one only Owners and Admins can hold, there’s no request button. You’ll see “Only Owners and Admins can hold permission. Ask one of them to add you to the Admin group.”
Good to know
Section titled “Good to know”- Nothing changes until you save. Staged changes are lost if you discard them or leave the page.
- A direct grant sits on top of groups. Removing someone from a group doesn’t remove permissions granted to them directly. Check the person’s Permissions tab on Our Team to see everything they hold and where it comes from.
- Open to Everyone means everyone, including people you invite later. Check which permissions show Everyone before you invite someone from outside the organization.
- One open request per permission. If you’ve already asked, the button reads Requested until someone decides.
Who can use it
Section titled “Who can use it”| To… | You need |
|---|---|
| See this page | View permissions |
| Change who holds a permission | Edit permissions (Owners and Admins only) |
| Grant or turn down a permission request | To be an Owner or Admin |
| Request a permission | Nothing. Any member can ask |
If you can’t open the page, it says You do not have permission to view permissions
and lets you request access. If you can see the page but not change it, clicking Add group or person explains which permission you’re missing.