website/docs/users-sources/access-control/manage_permissions.md
For instructions on viewing and managing permissions, see the following topics. To learn more about the concepts and fundamentals of authentik permissions, refer to About Permissions.
To learn about using Initial Permissions, a pre-defined set of permissions, refer to our documentation.
You can view all permissions that are assigned to a user, group, role, flow, stage, or other objects.
To view permissions assigned for a specific role:
Here we'll use flows as an example for objects with a detail page.
Here we'll use stages as an example for objects without a detail page.
You can assign or remove permissions to a user, role, group, flow, stage, or other objects.
To assign or remove object permissions for a specific role:
To assign or remove global permissions for a role:
Can access admin interface permissionsYou can use a role to grant regular users, who are not superusers nor Admins, the right to view the Admin interface. This can be useful in scenarios where you have a team who needs to be able to create certain objects (flows, other users, etc) but who should not have full access to the Admin interface.
To assign the Can access Admin interface permission to a role:
admin in the Search field and click the search icon.Be aware that any rights beyond viewing the Admin interface will need to be assigned as well; for example, if you want a non-administrator user to be able to create flows in the Admin interface, you need to grant those global permissions to add flows.