Roles and Permissions
Roles decide what each person can see and do. Use this page when someone cannot find a menu or button they need, when a new team member starts, or when you want a group of people, such as supervisors, to share the same access.
| Menu | Access Control > Roles; Access Control > Users |
| Permission | Manage Roles; Manage users |
| Feature | Roles (Orchard Core); Enhanced Roles adds the role picker for content items |
What you see depends on your role. If the menu, a button or a setting on this page is missing, ask your administrator to give you the permission listed above or to turn on the feature. Only administrators can turn features on and change site settings.
How roles work
- A permission is one thing a person may do, for example Manage Contact Center queues or Run 'Phone Number Verifications' Report.
- A role is a named set of permissions, for example Supervisor.
- A user can hold several roles. They get every permission of every role they hold. Permissions only add up; no role takes a permission away.
- Menus, buttons and settings only appear when one of the person's roles has the permission they need. That is why two people can see a different admin menu.
- A feature's permissions only appear in the role editor once the feature is turned on.
Orchard Core includes some roles out of the box. Administrator can do everything. Authenticated applies to every signed-in person, and Anonymous applies to visitors who are not signed in. When a CrestApps feature is turned on, it usually gives its management permissions to the Administrator role.
The User Manual pages list the permission each screen needs in the table at the top. Use those names when you ask for access or grant it.
Give someone access
Most of the time you only need step 1.
- Give the person a role. Open Access Control > Users, edit the user, tick the role that already has the access they need, and save.
- Or add the permission to a role. Open Access Control > Roles, edit the role, tick the permission in the list (it is grouped by feature), and save. Everyone who holds that role gets it.
- Or create a new role. On Access Control > Roles, click Add Role, name it, save it, then edit it to tick its permissions, and give it to the right users.
Prefer roles that match job titles, such as Agent, Supervisor and Manager. Changing one role then updates everyone in that job at once.
If the screen still does not appear after you give the permission, the feature may be off. Features are turned on under Tools > Features.
For the role editor itself, see the Orchard Core Roles documentation.
Let editors pick roles on a content item
The Enhanced Roles feature adds a Role Picker part. Add it to a content type when each item should carry a list of roles, for example to say which teams a page is for. The Content Access Control feature uses the same picker to limit who can view an item.
Add the role picker to a content type
- Open Content > Content Definition > Content Types and edit the content type.
- Click Add Parts, tick Role Picker, and save.
- Edit the Role Picker part on the content type to set the options below, and save.
You need the Edit content types permission.
| Field | What it does |
|---|---|
| Exclude roles | Roles that editors cannot pick. Leave it empty to offer every role. |
| Required? | Editors must pick at least one role before they can save the item. |
| Allow multiple? | Editors can pick more than one role. Without it, they pick one. |
| Hint | Help text shown under the picker. |
Pick roles on an item
When you edit an item of that type, the picker lists the roles in alphabetical order. Type in its search box to find a role. When more than one role is allowed, use Select All or Deselect All to change every role at once, and the picked roles are shown with a tick. Save or publish the item.