Bitfocus AS
logo
logo
Bitfocus AS
logo
logo
Sign upSign in

Loading...

Bitfocus

Subscribe to our newsletter

The latest news, articles, and resources, sent to your inbox.

FacebookInstagramGitHubYouTubeLinkedIn

Products

  • Buttons
  • Companion

Integrations

  • Supported Devices
  • Developer Community
  • Connection Development

Support

  • Support Overview
  • Documentation
  • Video Tutorials
  • Community Forum

Sales

  • Resellers & Integrators
  • Buttons Pricing

Updates

  • Case Studies
  • Events & Trade Shows
  • Press Releases
  • Product Updates
  • Webinars

Legal

  • Legal Overview
  • Privacy Policy
  • Buttons EULA
  • Terms & Cookie Policy

Company

  • About us
  • Press kit
  • Careers

© 2026 Bitfocus AS. All rights reserved.

Grant access to specific resources
Docs for
Overview
Getting started
What is Bitfocus Buttons?
Install Buttons and get started
Manage your Buttons license
Activate Buttons offline
Find your way around Buttons
Create your first backup
Add an ATEM connection
Choose a control method
Choose an installation path
Install Buttons on Debian or Ubuntu
Understand HA clustering
Kubernetes HA
Update or remove Buttons
Positions
Understand positions
Create a position
Add controls and sections to a position
Create your first button
Use a connection's presets
Build more capable button actions
Add more feedback to a button
Organize controls in a section
Shift Section
Organize controls with a Folder Section
Add a Popover Section
Build and reuse a Shared Section
Build a Router Section
Understand Custom Routers
Custom Router panel
Surfaces
Surface compatibility
Add and attach a surface
Device orientation
Connections
Update a connection's module safely
Monitor and troubleshoot a connection
Router integrations
VideoHub and AJA KUMO
Utah Scientific BPS
Generic SW-P-08
Nevion VideoIPath
Arkona BLADE//runner
Routing
Physical routing
Configure ports and labels
Take a physical route
Understand route status
Topology graph
Routing Presets
Get started with virtual routing
Configure Nested Shapes
Reverse routing
Tielines
Routing Projects
Routing settings
Troubleshoot a route
Tally
Understand the Tally system
Send ATEM tally and labels to a UMD
Interpret Active Tally state
TSL/UMD connections
Diagnose tally problems
NMOS
Understand NMOS in Buttons
Connect Buttons to an NMOS Registry
Built-in Registry Server
Configure NMOS connections
Discover and adopt
Browse the NMOS inventory
Manage NMOS multicast addresses
Diagnose NMOS problems
Understand Cuelists
Build a Cuelist
Read and advance a running Cuelist
Control a Cuelist from a Position
Workflows
Understand workflows
Build your first workflow
Reuse a group of workflow nodes safely
Troubleshoot a workflow
Recipes
Sequence a timed automation
Call an HTTP endpoint from a workflow
REST endpoint
Use variables
Understand variable scope
Understand nested variables
Update expressions for v1.8
Plan and use Tags
Access
Create and manage users
Create roles and assign permissions
Grant access to specific resources
Show different controls by role
Sessions
Set up PIN and NFC sign-in
SSO
Get started with SSO
Connect a generic OIDC provider
Connect LDAP or Active Directory
Map identity claims to roles
Secure a Buttons deployment
Integrations
External control
Connect to Bitfocus Listener
USB Relay
Install USB Relay on Windows
Install USB Relay on macOS
Install USB Relay on Linux
Install USB Relay on a Raspberry Pi
Get started with the Control API
Secure and monitor the Control API
Control API reference
API reference
Administration
Enable and manage installable features
Services and health
Configure and monitor scheduled backups
Restore a backup and verify it
Export or import Buttons configuration
Store and rotate connection secrets
Replace the HTTPS certificate
HA backup and recovery
Settings
Collect support information
Reference
Glossary
Button Inspector reference
Network ports reference
Expressions
Internal actions reference
Routing Presets panel reference
Startup configuration reference
Workflow nodes
Connection workflow nodes
Workflow workflow nodes
Internal workflow nodes
Position workflow nodes
API workflow nodes
Utility workflow nodes

Loading...

Previous
← Create roles and assign permissions
Next
Show different controls by role →
Contact support →
You are viewing documentation for Buttons 1.8.See the docs for Buttons 1.6
Buttons/Access/Grant access to specific resources

Grant access to specific resources

Beyond the blanket "All {Resource}s" grants covered in Create roles and assign permissions, most resource types also let you grant a role access to individual positions, connections, or other resources one at a time: useful for a role that should only touch a specific set of things rather than everything of that type.

Before you begin#

  • A role already created: see Create roles and assign permissions.
  • A sense of exactly which individual resources this role needs, since specific grants are set one resource at a time, not by folder or group.

Which resource types support specific grants#

Positions, Shared Sections, Connections, NMOS Connections, Surfaces, Workflows, and Cuelists all offer a Specific {Resource}s card alongside their All {Resource}s card. Tags, Routing, Users, Roles, and Projects don't: for these, access is all-or-nothing only, granted from the All {Resource}s card.
System Admin is a special case: it has a similar-looking Specific System Admins card, but its rows aren't resources you create: they're Bitfocus's own fixed list of system capabilities (General, SSO, Icons, Configuration Data, Services, Certificates, License Management, Backups, NMOS Settings, Secrets, API management), the same set every role sees.

Note

Routing access is granted as a single all-or-nothing permission covering every relation, rule, and route request together: there's no way to grant a role access to just one specific route or rule.

Grant access to a specific resource#

  1. Open the role and select the resource type.
  2. Open the Specific {Resource}s card.
  3. Use the search box to find the resource by name.
  4. Set its access level: No access, Read, or Update (plus a separate Execute column for Workflows and Cuelists). A specific grant can never reach Delete: that level exists only on the All {Resource}s card, so it always applies to every resource of that type at once, never to one resource individually.
The list is flat: every resource of that type appears as its own row, with no folder or grouping option to select several at once, if a role needs access to many individual resources, expect to set each one separately.

How a specific grant combines with a blanket grant#

A specific grant can only add access on top of what All {Resource}s already grants: it can never take access away, and since it tops out at Update (or Execute), it can never exceed a blanket Delete grant either. If All Positions already grants Read, you can still add a specific grant of Update on one particular position to raise it further, but you can't use a specific grant to reduce access to a single position below what the blanket grant already provides. Confirmed live: once All Positions is at Read, the specific-grant row for that position shows Read as its own floor, with No access disabled and unselectable. The editor won't let you save a combination like that, since there'd be nothing for the lower grant to actually restrict.

Check the result as that role#

There's no built-in way to view a resource the way a specific user or role would see it: no "sign in as" or impersonation feature exists. To confirm what a role can actually do, either sign in with an account that holds only that role, or temporarily add your own account to it, check the result, and remove it again afterward.

If you get stuck#

What you see
What to try
A resource type has no Specific {Resource}s card.
That type only supports all-or-nothing access: check whether All {Resource}s already covers what you need.
You can't find a resource in the specific-access search.
Search matches the resource's name only: confirm you're searching the right resource type's list, and that the resource hasn't been renamed.
A specific grant you set doesn't seem to do anything.
If All {Resource}s already grants an equal or higher level, the specific grant has nothing left to add: check the blanket grant first.
You need to grant access to many individual resources at once.
There's no bulk or folder selection: each one needs its own row. If this becomes unmanageable, consider whether a blanket All {Resource}s grant fits the role better.
You want to confirm exactly what a role can see.
Sign in as an account holding only that role: there's no admin preview or impersonation feature to check this without actually signing in.

Where to go next#

  • Create roles and assign permissions
  • Show different controls by role

Was this helpful?

Was this helpful?

0 of 0 users found this page helpful