Beyond the blanket "All {Resource}s" grants covered in
Create roles and assign permissions, most resource types also let you grant a role access to individual positions, connections, or other resources one at a time: useful for a role that should only touch a specific set of things rather than everything of that type.
Before you begin#
- A role already created: see Create roles and assign permissions.
- A sense of exactly which individual resources this role needs, since specific grants are set one resource at a time, not by folder or group.
Which resource types support specific grants#
Positions, Shared Sections, Connections, NMOS Connections, Surfaces, Workflows, and Cuelists all offer a Specific {Resource}s card alongside their All {Resource}s card. Tags, Routing, Users, Roles, and Projects don't: for these, access is all-or-nothing only, granted from the All {Resource}s card.
System Admin is a special case: it has a similar-looking Specific System Admins card, but its rows aren't resources you create: they're Bitfocus's own fixed list of system capabilities (General, SSO, Icons, Configuration Data, Services, Certificates, License Management, Backups, NMOS Settings, Secrets, API management), the same set every role sees.
Note
Routing access is granted as a single all-or-nothing permission covering every relation, rule, and route request together: there's no way to grant a role access to just one specific route or rule.
Grant access to a specific resource#
- Open the role and select the resource type.
- Open the Specific {Resource}s card.
- Use the search box to find the resource by name.
- Set its access level: No access, Read, or Update (plus a separate Execute column for Workflows and Cuelists). A specific grant can never reach Delete: that level exists only on the All {Resource}s card, so it always applies to every resource of that type at once, never to one resource individually.
The list is flat: every resource of that type appears as its own row, with no folder or grouping option to select several at once, if a role needs access to many individual resources, expect to set each one separately.
How a specific grant combines with a blanket grant#
A specific grant can only add access on top of what All {Resource}s already grants: it can never take access away, and since it tops out at Update (or Execute), it can never exceed a blanket Delete grant either. If All Positions already grants Read, you can still add a specific grant of Update on one particular position to raise it further, but you can't use a specific grant to reduce access to a single position below what the blanket grant already provides. Confirmed live: once All Positions is at Read, the specific-grant row for that position shows Read as its own floor, with No access disabled and unselectable. The editor won't let you save a combination like that, since there'd be nothing for the lower grant to actually restrict.
Check the result as that role#
There's no built-in way to view a resource the way a specific user or role would see it: no "sign in as" or impersonation feature exists. To confirm what a role can actually do, either sign in with an account that holds only that role, or temporarily add your own account to it, check the result, and remove it again afterward.
If you get stuck#
What you see | What to try |
|---|
A resource type has no Specific {Resource}s card. | That type only supports all-or-nothing access: check whether All {Resource}s already covers what you need. |
You can't find a resource in the specific-access search. | Search matches the resource's name only: confirm you're searching the right resource type's list, and that the resource hasn't been renamed. |
A specific grant you set doesn't seem to do anything. | If All {Resource}s already grants an equal or higher level, the specific grant has nothing left to add: check the blanket grant first. |
You need to grant access to many individual resources at once. | There's no bulk or folder selection: each one needs its own row. If this becomes unmanageable, consider whether a blanket All {Resource}s grant fits the role better. |
You want to confirm exactly what a role can see. | Sign in as an account holding only that role: there's no admin preview or impersonation feature to check this without actually signing in. |
Where to go next#