---
title: "Roles and permissions"
canonical: "https://support.appfire.com/space/CDML/650217543/Roles%20and%20permissions"
format: markdown
---
> Macro (aura-html)


## Overview

> Macro (excerpt)
> 
> How Confluence roles and permissions relate to workflows

The standard Confluence roles and permissions are used in Comala Document Management to manage workflow roles and also access to documents with an applied workflow. In addition, the app can add, remove, and set Confluence page-level restrictions.

## Confluence hierarchy

The roles and permissions for both Confluence and workflows are based on the topology of Confluence itself.

![image](media://68f9b5e2-c8d2-4214-9092-d7ba82bccd47)

  
Workflows, roles, and permissions exist at all three levels of the hierarchy.

> ℹ️ **Page **refers to pages and blog posts.

## Confluence permissions

For an overview of Confluence permissions, see [Atlassian Confluence permissions and restrictions](https://confluence.atlassian.com/doc/permissions-and-restrictions-139557.html).

The following [workflow trigger action macros](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649858941) can be used to change page-level restrictions as a response to a [workflow event](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649759655):

> Macro (contentbylabel)

## Confluence roles

These are the standard roles in Confluence, and how they relate to Comala Document Management.

| Role | Notes |
| --- | --- |
| **Anonymous** | Anyone who is not logged in to Confluence. |
| **User** | Must be logged in to Confluence. |
| **Comala add-on user** | Comala app user used for workflow |
| **Space administrator** | Responsible for<br>- Setting [space permissions](https://confluence.atlassian.com/doc/space-permissions-overview-139521.html) for content access, editing, and deletion
- Selecting which [space workflows](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649827041) are in the space and whether they are active
- Space-level [app configuration](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649956239), including [workflow notifications](https://appfire.atlassian.net/wiki/spaces/CDML/pages/650119000). |
| **Global administrator ** | Responsible for:<br>- [global workflows](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649530159) in the instance, and which workflows are active so they can be added to a space as a space workflow, and are available to add as a page workflow
- [app global configuration](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951), including[ workflow notifications](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649530054)<br>The global administrator can set<br>- which spaces can use [page workflows](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649628831) and [space workflows](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649531846)
- type of [e-signature credentials required](https://appfire.atlassian.net/wiki/spaces/CDML/pages/650347320) for reviewer authentication. The can also manage the expiry for existing user authentication app token or remove user authentication |
| **[System administrator](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649659691)**** ** | Responsible for<br>- [Installation](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649825151), [updating, or changing](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649594169) the Comala Document Management app in your instance |

## Workflow permissions

These are the permissions from the perspective of Comala Document Management:

| Permission | Notes |
| --- | --- |
| **View content** | Users who can **view the content**<br>This requires *all* of the following Confluence permissions:<br>- "**Can use**" – Global permission
- "**View**" – Space permission
- "**View**" – Page (or blog post) permission, or no page-level restrictions<br>Users who only have this permission are sometimes referred to as "Viewers", "View-only users", or "Read-only users". |
| **Edit content** | Users who can **edit the content** (including Admins)<br>This requires *all* of the following Confluence permissions:<br>- *The permissions listed for "****View****" above*
- "**Add**" – Space permission
- "**Edit**" – Page (or blog post) permission, or no page-level restrictions |
| **Workflow admin** | Users who can **administer the workflow at the content level**.<br>This requires *any* of the following Confluence permissions:<br>- System administrator
- Global administrator
- Space administrator<br>You can define additional **Workflow Admin **users, even if they don't have any of the three permissions listed above, by adding users to the `adminusers` property of the [workflow macro](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649662219). This grants the listed users the **Workflow Admin** permission for that particular workflow, and all the content it is applied to. |

## Workflow roles

Workflow roles relate to interactions with the content and the workflow applied to it:

| Role | Notes |
| --- | --- |
| **Viewer** | Consumer of content<br>- Must have **View content** permission |
| **Author** | Responsible for producing (creating, editing) content<br>- Must have **Edit content** permission |
| **Assignee** | A user who is<br>- [assigned as a reviewer](https://appfire.atlassian.net/wiki/spaces/CDML/pages/650347935)  to an approval, or
- [assigned to a workflow task](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649792357)<br>Assignment is optional by default, but can be required or prevented in the workflow or app configuration.<br>See:<br>- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649694643](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649694643)
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649662337](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649662337)
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/650315819](https://appfire.atlassian.net/wiki/spaces/CDML/pages/650315819) |
| **Reviewer** | Responsible for reviewing content.<br>See:<br>- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/650153766](https://appfire.atlassian.net/wiki/spaces/CDML/pages/650153766)
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/650313809](https://appfire.atlassian.net/wiki/spaces/CDML/pages/650313809)<br>Must have **Edit content** permission |
| Reviewers can optionally be required to authenticate their identity prior to making a review.<br>See:<br>- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649890845](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649890845) |
| **Approver or rejector** | A **Reviewer** who has either approved or rejected content during a content review.<br>These can be used in some of the [compatible third-party apps](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649330694). The values can be accessed using the [Workflow supplier](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649726882) or as a [value reference](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649694302). |
| In some elements of the user interface and macros, the term **Approver** is used to refer to a **Reviewer** or **Assignee**. |
| **Producer** | Collective term for Authors, Assignees, and Reviewers.<br>Namely, all users who have **Edit content** permission. |
| **Workflow Admin** | Can force workflows into a specific state on a page-by-page basis.<br>See:<br>- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649760835](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649760835)<br>Can remove `stickylabels`<br>See:<br>- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649662219](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649662219)<br>Must have **Workflow Admin** permission |
| When [applying workflows at the space-level](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649531846), Confluence administrators and space administrators can use the [Initialize](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649827807) feature to bulk transition all documents for a given workflow into a given state. |

## Page mode

When a space is running in [page mode](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649628831), users with **Edit content** permission can apply a page workflow and edit the applied workflow using the [page tools menu:](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649856105)

- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/1245478922](https://appfire.atlassian.net/wiki/spaces/CDML/pages/1245478922)
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649726655](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649726655)
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/650119254](https://appfire.atlassian.net/wiki/spaces/CDML/pages/650119254)

## Space mode

When a space is running in [space mode](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649531846), a space workflow has been made active in the document management dashboard and applied to all the pages and blog posts in the space by a space administrator. On pages with the space workflow applied, there are no options for editors to add or remove the workflow:

- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/1243152995](https://appfire.atlassian.net/wiki/spaces/CDML/pages/1243152995)
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649827041](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649827041)

## App configuration

| Setting | **Use** | Where | Notes |
| --- | --- | --- | --- |
| **Workflow Activity and Drafts Visibility** | Can users who only have **View content** permission (but not Confluence **edit** or **admin** permission) view documents in a draft workflow state when the workflow includes a final state? | - [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951)
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649956239](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649956239) | - **Default setting**: View-only users can only view the last approved version created on transition to the workflow final state (if present)
- **Option: **Visibility set to let view-only users view content in a workflow draft state<br>See:<br>- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649794062](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649794062)
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/650119122](https://appfire.atlassian.net/wiki/spaces/CDML/pages/650119122) |
| **Tasks mode** | Can users other than the task creator and assignee complete or assign tasks? | - [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951)
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649956239](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649956239) | - **Default setting**: **Lenient.** Any user with view and edit permission can complete a task
- **Option: Strict. **If user is assigned, only the assignee can complete the task |
| **Space workflows** | Which spaces in the instance can use and apply [space workflows](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649531846)? | - [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951) | - **Default setting: Any**<br>Space workflows can be restricted to added space keys. |
| **Page workflows** | Which spaces in the instance can use and apply [page workflows](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649628831)? | - [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951) | - **Default setting: Any**<br>Page workflows can be restricted to added space keys. |
| **Workflow Importer Group** | Which Confluence administrators and space administrators can import workflows from the [Workflows Exchange repository](https://appfire.atlassian.net/wiki/spaces/WORKFLOW)? | - [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951) | See:<br>- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649857980](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649857980)
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649627884](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649627884) |
| **Email any address** | Can email addresses that are not associated with a Confluence instance be used in the [send-email macro](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649924039) in a workflow trigger custom email notification? | - [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951) |  |
| **Default view** | When using [same-space publishing](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649794062), should users with **Edit content** permission see the draft or the last published (final state) version of content by default? | - [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649956239](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649956239) |  |

## Testing roles and permissions

Whilst developing and testing workflows, it is useful to view the content from the perspective of another user – such as a Viewer, or a Reviewer – to check that the interface, permissions, notifications, etc., are working as you expect.

> ✅ A third-party app, [Switch User (SU) for Confluence](https://marketplace.atlassian.com/plugins/com.javahollic.confluence.confluencesu/server/overview), can be useful in this context. If you are more adventurous, you could probably do something similar using [Adaptavist ScriptRunner](https://marketplace.atlassian.com/apps/1215215/scriptrunner-for-confluence?tab=overview&hosting=datacenter).

## Related pages

- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649889951)  – Global app permissions
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649956239](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649956239)  – Space-level app permissions
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649957056](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649957056)  – Limit notifications to users, groups, workflow roles, etc.
- [https://appfire.atlassian.net/wiki/spaces/CDML/pages/649923873](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649923873)  – Prevent view-only users from seeing draft (unpublished) content