# About Permission Sets

In Vault, permission sets are a way to group permissions together. Security profiles or user roles then use the permission sets to grant or restrict users' access to certain features, particularly system administration functions such as user management or object record creation. For example, the permission sets applied to the _IT Administrator_ security profile allow users with that profile to manage users and groups, but not studies and sites.

## Accessing Permission Set Configuration

To configure permission sets, you must have the _Admin: Permission Sets: Read_, _Create_, _Edit_, and _Delete_ permissions.

With the right access, you can manage permission sets from **Admin > Users & Groups > Permission Sets**.

<div class="note-border alert-info">
  <div class="alert alert-info" role="alert">
    <div><i class="far fa-info-circle"></i></div>
    <div class="alert-text">
      <p><strong>Note</strong>: You can only grant permissions that you also have. For example, if you do not have any of the <em>Vault Owner Actions</em> section permissions, you cannot turn those permissions on when editing a permission set.</p>
    </div>
  </div>
</div>



## About 'All' Permissions {#all-permissions}

Throughout the permission sets configuration, there are permissions like **All Configuration** and **All Audit**. Granting these permissions gives users all permissions under them. However, this functions differently from simply selecting each sub-permission. If a future release of Vault adds new permissions to an area, permission sets with the 'All' permission will automatically select those new permissions.

## About Permission Dependencies

Granting certain permissions automatically grants additional permissions. When editing, these dependent permissions will be greyed out as long as their controlling permission is selected.

For example, when you grant the _Web Actions: Delete_ permission, you automatically grant the _Web Actions: Edit_ permission.

## About User Role Permissions

As an added layer of access alongside security profiles, you can optionally grant permissions with _User Roles_ added to _User_ records. This can simplify complex security profile configurations. See <a href="/en/gr/69197/">Managing Permissions with User Roles</a> for more information.

## Admin Permissions {#admin-permissions}

Access to administrator-type functionality is controlled by permissions assigned via permission sets and security profiles. The sections below align with the headings on the **Admin** tab of the **Permission Sets** page.

In addition to license type, security profile, user role, and permission set, some access is controlled by the <a href="/en/gr/14691/#domain_admin_setting">**Domain Admin** user setting</a>.

### Configuration

|Permission|Access Details|
|--- |--- |
|Configuration: All Configuration|Grants all 'Configuration' permissions; individual permissions are explained below.|
|Configuration: All Configuration Read|Grants all 'Read' permissions in 'Configuration'; individual permissions are explained below.|
|Email Settings: Read|Grants read-only permission to the **Configuration > Email Settings** page|
|Email Settings: Edit|Grants edit permission to the **Configuration > Email Settings** page|
|Login Message: Read|Grants read-only permission to the **Configuration > Login Message** page|
|Login Message: Edit|Grants edit permission to the **Configuration > Login Message** page|
|Picklists: Read|Grants read-only permission to the **Business Admin > Picklist** page|
|Picklists: Edit|Grants edit permission to the **Business Admin > Picklist** page|
|User Account Emails: Read|Grants read-only permission to the **Configuration > User Account Emails** page|
|User Account Emails: Edit|Grants edit permission to the **Configuration > User Account Emails** page|
|Lifecycle Colors: Read|Grants read-only permission to the **Configuration > Lifecycle Colors** page|
|Lifecycle Colors: Edit|Grants edit permission to the **Configuration > Lifecycle Colors** page|
|Pages: Read|Grants read-only permission to **Configuration > Pages**|
|Pages: Edit|Grants edit permission to **Configuration > Pages**|
|Searchable Object Fields: Read|Grants read-only permission to the **Configuration > Searchable Objects** page|
|Searchable Object Fields: Edit|Grants edit permission to the **Configuration > Searchable Objects** page|
|Document Tags: Read|Grants read-only permission to the **Configuration > Document Tags** page.|
|Document Tags: Edit|Grants edit permission to the **Configuration > Document Tags** page.|
|Tabs: Read|Grants read-only permission to the **Configuration > Tabs** page|
|Tabs: Create|Grants the ability to create new tabs in the **Configuration > Tabs** page|
|Tabs: Edit|Grants the ability to edit existing tabs in the **Configuration > Tabs** page|
|Tabs: Delete|Grants ability to delete existing tabs in the **Configuration > Tabs** page|
|Tab Collections: Read|Grants read-only permission to the **Configuration > Tab Collections** page|
|Tab Collections: Create|Grants the ability to create new tabs collections in the **Configuration > Tab Collections** page|
|Tab Collections: Edit|Grants the ability to edit existing tab collections in the **Configuration > Tab Collections** page|
|Tab Collections: Delete|Grants ability to delete existing tab collections in the **Configuration > Tab Collections** page|
|Document Web Actions: Read|Grants read-only permission to the **Configuration > Web Actions** page|
|Document Web Actions: Create|Grants ability to create new web actions in the **Configuration > Web Actions** page|
|Document Web Actions: Edit|Grants ability to edit existing web actions in the **Configuration > Web Actions** page|
|Document Web Actions: Delete|Grants ability to delete web actions in the **Configuration > Web Actions** page|
|Object Web Actions: Read|Grants read-only permission to the **Configuration > Object Web Actions** page|
|Object Web Actions: Create|Grants ability to create new actions in the **Configuration > Object Web Actions** page|
|Object Web Actions: Edit|Grants ability to edit existing actions in the **Configuration > Object Web Actions** page|
|Object Web Actions: Delete|Grants ability to delete actions in the **Configuration > Object Web Actions** page|
|Document Types: Read|Grants read-only permission to the **Configuration > Document Types** page|
|Document Types: Create|Grants ability to create new document types, subtypes, and classifications in the **Configuration > Document Types** page|
|Document Types: Edit|Grants ability to edit existing document types, subtypes, and classifications in the **Configuration > Document Types** page|
|Document Types: Delete|Grants ability to delete document types, subtypes, and classifications in the **Configuration > Document Types** page|
|Document Relationships: Read|Grants read-only permission to the **Configuration > Document Relationships**{: #document-relationships-permission} page|
|Document Relationships: Create|Grants the ability to create new document relationship types in the the **Configuration > Document Relationships** page|
|Document Relationships: Edit| Grants the ability to edit existing document relationship types in the the **Configuration > Document Relationships** page|
|Document Relationships: Delete|Grants the ability to delete document relationship types in the the **Configuration > Document Relationships** page|
|Document Fields: Read|Grants read-only permission to the **Configuration > Document Fields** page|
|Document Fields: Create|Grants ability to create new document fields in the **Configuration > Document Fields** page|
|Document Fields: Edit|Grants ability to edit existing document fields in the **Configuration > Document Fields** page|
|Document Fields: Delete|Grants ability to delete document fields in the **Configuration > Document Fields** page|
|Field Dependencies: Read|Grants read-only permission to the **Configuration > Field Dependencies** page|
|Field Dependencies: Create|Grants ability to create field dependencies in the **Configuration > Document Fields** page|
|Field Dependencies: Edit|Grants ability to edit existing field dependencies in the **Configuration > Document Fields** page|
|Field Dependencies: Delete|Grants ability to delete field dependencies in the **Configuration > Document Fields** page|
|Field Layout: Read|Grants read-only permission to the **Configuration > Field Layouts** page|
|Field Layout: Create|Grants ability to create new field layouts in the **Configuration > Document Fields** page|
|Field Layout: Edit|Grants ability to edit existing field layouts in the **Configuration > Document Fields** page|
|Field Layout: Delete|Grants ability to delete field layouts in the **Configuration > Document Fields** page|
|Document Lifecycles: Read|Grants read-only permission to **Configuration > Document Lifecycles**, including all sub-pages (lifecycles, states, etc.)|
|Document Lifecycles: Create|Grants ability to create new items within **Configuration > Document Lifecycles** including lifecycles, lifecycle states, and workflows|
|Document Lifecycles: Edit|Grants ability to edit existing items within **Configuration > Document Lifecycles**, including lifecycles, lifecycle states, and workflows|
|Document Lifecycles: Delete|Grants ability to delete existing items within **Configuration > Document Lifecycles**, including lifecycles, lifecycle states, and workflows|
|Object Lifecycles: Read|Grants read-only permission to **Configuration > Object Lifecycles**, including all sub-pages (lifecycles, states, etc.)|
|Object Lifecycles: Create|Grants ability to create new items within **Configuration > Object Lifecycles**, including lifecycles, lifecycle states, etc.|
|Object Lifecycles: Edit|Grants ability to edit existing items within **Configuration > Object Lifecycles**, including lifecycles, lifecycle states, etc.|
|Object Lifecycles: Delete|Grants ability to delete existing items within **Configuration > Object Lifecycles**, including lifecycles, lifecycle states, etc.|
|Object Workflows: Read|Grants read-only permission to **Configuration > Object Workflows**|
|Object Workflows: Create|Grants ability to create new workflows within **Configuration > Object Workflows**|
|Object Workflows: Edit|Grants ability to edit existing workflows within **Configuration > Object Workflows**|
|Object Workflows: Delete|Grants ability to delete existing workflows within **Configuration > Object Workflows**|
|Document Messages: Read|Grants read-only permission to **Configuration > Document Messages**|
|Document Messages: Create|Grants ability to create new messages within **Configuration > Document Messages**|
|Document Messages: Edit|Grants ability to edit existing messages within **Configuration > Document Messages**|
|Document Messages: Delete|Grants ability to delete existing messages within **Configuration > Document Messages**|
|Object Messages: Read|Grants read-only permission to **Configuration > Object > Messages**|
|Object Messages: Create|Grants ability to create new messages within **Configuration > Object Messages**|
|Object Messages: Edit|Grants ability to edit existing messages within **Configuration > Object Messages**|
|Object Messages: Delete|Grants ability to delete existing messages within **Configuration > Object > Messages**|
|Objects: Read|Grants read-only permission to **Configuration > Objects**|
|Objects: Create|Grants ability to create new objects within **Configuration > Objects**|
|Objects: Edit|Grants ability to edit existing objects within **Configuration > Objects**|
|Objects: Delete|Grants ability to delete existing objects within **Configuration > Objects**|
|Overlays: Read|Grants read-only permission to **Business Admin > Templates > Overlays**|
|Overlays: Create|Grants ability to create new overlay templates within **Business Admin > Templates > Overlays**|
|Overlays: Edit|Grants ability to edit existing overlay templates within **Business Admin > Templates > Overlays**|
|Overlays: Delete|Grants ability to delete existing overlay templates within **Business Admin > Templates > Overlays**|
|Rendition Types: Read|Grants read-only permission to **Configuration > Rendition Types**|
|Rendition Types: Create|Grants ability to create new rendition types within **Configuration > Rendition Types**|
|Rendition Types: Edit|Grants ability to edit existing rendition types within **Configuration > Rendition Types**|
|Rendition Types: Delete|Grants ability to delete existing rendition types within **Configuration > Rendition Types**|
|Report Types: Read|Grants read-only permission to **Configuration > Report Types** and report views within **Configuration > Report Views**|
|Report Types: Create|Grants ability to create new report types within **Configuration > Report Types** and report views within **Configuration > Report Views**|
|Report Types: Edit|Grants ability to edit existing report types within **Configuration > Report Types** and report views within **Configuration > Report Views**|
|Report Types: Delete|Grants ability to delete existing report types within **Configuration > Report Types** and report views within **Configuration > Report Views**|
|Signature & Cover Pages: Read|Grants read-only permission to **Business Admin > Templates > Signature & Cover Pages**|
|Signature & Cover Pages: Create|Grants ability to create new signature page templates within **Business Admin > Templates > Signature & Cover Pages**|
|Signature & Cover Pages: Edit|Grants ability to edit existing signature page templates within **Business Admin > Templates > Signature & Cover Pages**|
|Signature & Cover Pages: Delete|Grants ability to delete existing signature page templates within **Business Admin > Templates > Signature & Cover Pages**|
|Formatted Output Records: Read|Grants read-only permission to **Business Admin > Templates > Formatted Outputs**|
|Formatted Output Records: Create|Grants ability to create new formatted outputs within **Business Admin > Templates > Formatted Outputs**|
|Formatted Output Records: Edit|Grants ability to edit existing formatted outputs within **Business Admin > Templates > Formatted Outputs**|
|Formatted Output Records: Delete|Grants ability to delete existing formatted outputs within **Business Admin > Templates > Formatted Outputs**|
|Page Links: Read|Grants read-only permission to **Configuration > Page Links**.|
|Page Links: Create|Grants ability to create new page links within **Configuration > Page Links**.|
|Page Links: Edit|Grants ability to edit existing page links within **Configuration > Page Links**.|
|Page Links: Delete|Grants ability to delete existing page links within **Configuration > Page Links**.|
|Custom Messages: Read|Grants read-only permission to **Configuration > Notification Templates**.|
|Custom Messages: Create|Grants ability to create new custom notification templates within **Configuration > Notification Templates**.|
|Custom Messages: Edit|Grants ability to edit existing custom notification templates within **Configuration > Notification Templates**.|
|Custom Messages: Delete|Grants ability to delete existing custom notification templates within **Configuration > Notification Templates**.|
|Templates: Read|Grants read-only permission to **Business Admin > Templates > Documents & Binders**|
|Templates: Create|Grants ability to create new document or binder templates within **Business Admin > Templates > Documents & Binders**|
|Templates: Edit|Grants ability to edit existing document or binder templates within **Business Admin > Templates > Documents & Binders**|
|Templates: Delete|Grants ability to delete existing document or binder templates within **Business Admin > Templates > Documents & Binders**|
|Action Triggers: Read|Grants ability to view _Triggers_ tab on an object.|
|Action Triggers: Create|Grants ability to create Action Triggers.|
|Action Triggers: Edit|Grants ability to edit Action Triggers, including reordering, activating configurations, reverting active configurations, and turning Action Triggers on and off.|
|Action Triggers: Delete|Grants ability to delete Action Triggers.|
|Business Admin Objects: Read|Grants the ability to to view and access the **Objects** tab within **Business Admin**.|
|Logs: All Audit|Grants ability to view all audit histories in **Admin > Logs**|
|Logs: System Audit|Grants ability to view **System Audit History** in **Admin > Logs**|
|Logs: Login Audit|Grants ability to view **Login Audit History** in **Admin > Logs**|
|Logs: Document Audit|Grants ability to view **Document Audit History** in **Admin > Logs**|
|Logs: Object Record Audit|Grants ability to view **Object Record Audit History** in **Admin > Logs**|
|Logs: Domain Audit|Grants ability to view **Domain Audit History** in **Admin > Logs**|
|Logs: Developer Logs|Grants ability to view the **Developer Logs** in **Admin > Logs**, such as the _Debug Log_ and _Runtime Log_.|
|Logs: API Usage|Grants ability to view **API Usage Logs** in **Admin > Logs**|
|Logs: Collab Auth Error Logs|Grants ability to view **Collaborative Authoring Error Log** in **Admin > Logs**|
|Spark Queues: Read|Grants read-only permission to Spark queues in **Connections > Spark Queues**|
|Spark Queues: Create|Grants ability to create Spark queues in **Connections > Spark Queues**|
|Spark Queues: Edit|Grants ability to edit existing Spark queues in **Connections > Spark Queues**|
|Spark Queues: Delete|Grants ability to delete Spark queues in **Connections > Spark Queues**|
|Spark Queues: Queue Log|Grants ability to view the Spark **Queue Log** in **Admin > Logs**|
|Vault Java SDK: Read|Grants read permission on components using the Vault Java SDK|
|Vault Java SDK: Create|Grants create permission on components using the Vault Java SDK|
|Vault Java SDK: Edit|Grants edit permission on components using the Vault Java SDK|
|Vault Java SDK: Delete|Grants delete permission on components using the Vault Java SDK|
|Vault Tokens: Read|Grants the ability to view _Vaulttoken_ records using MDL.|
|Vault Tokens: Create|Grants the ability to create _Vaulttoken_ records using MDL.|
|Vault Tokens: Edit|Grants the ability to alter _Vaulttoken_ records using MDL.|
|Vault Tokens: Delete|Grants the ability to drop _Vaulttoken_ records using MDL.|
|Inbound Email Addresses: Read|Grants read-only permission to **Configuration > Inbound Email Addresses**|
|Inbound Email Addresses: Create|Grants ability to create new addresses in **Configuration > Inbound Email Addresses**|
|Inbound Email Addresses: Edit|Grants ability to edit existing addresses in **Configuration > Inbound Email Addresses**|
|Inbound Email Addresses: Delete|Grants ability to delete existing addresses in **Configuration > Inbound Email Addresses**|
|Inbound Email Addresses: Email Log|Grants ability to view the **Email Log** in **Admin > Logs**|
|Inbound Email Addresses: Reprocess Emails|Grants ability to use the **Reprocess Emails** user action|
|Inbound Email Addresses: Delete Emails|Grants ability to use the **Delete Emails** user action|

### Domain Administration

<div class="note-border alert-info">
  <div class="alert alert-info" role="alert">
    <div><i class="far fa-info-circle"></i></div>
    <div class="alert-text">
      <p><strong>Note</strong>: Give careful consideration when granting the permissions below, as these allow control over all Vaults in a multi-Vault domain. Users must have the <strong>Domain Admin</strong> setting in addition to these permissions.</p>
    </div>
  </div>
</div>



|Permission|Access Details|
|--- |--- |
|Domain Administration: All Domain Admin|Grants all permissions related to Domain Administration|
|Domain Administration: All Domain Admin Read|Grants read-only permissions to all Domain Administration areas|
|Domain Administration: Reset All Passwords|Grants permission to <a href="/en/gr/1985/">reset all user passwords</a>.|
|Domain Settings: Read|Grants read-only permission to **Settings > Domain Settings**|
|Domain Settings: Edit|Grants edit permission to **Settings > Domain Settings**|
|SSO Settings: Read|Grants read-only permission to **Settings > SAML Profiles**|
|SSO Settings: Edit|Grants edit permission to **Settings > SAML Profiles**|
|Security Policies: Read|Grants read-only permission to **Settings > Security Policies**|
|Security Policies: Create|Grants permission to create new security policies in **Settings > Security Policies**|
|Security Policies: Edit|Grants permission to edit existing security policies in **Settings > Security Policies**|
|Network Access Rules: Read|Grants read-only permission to **Settings > Network Access Rules**|
|Network Access Rules: Create|Grants permission to create new network access rules in **Settings > Network Access Rules**|
|Network Access Rules: Edit|Grants permission to edit existing network access rules in **Settings > Network Access Rules**|
|Network Access Rules: Delete|Grants permission to delete existing network access rules in **Settings > Network Access Rules**|

### Operations

|Permission|Access Details|
|--- |--- |
|Operations: All Operations|Grants all permissions for job scheduler and **Rendition Status**|
|Operations: All Operations Read|Grants read-only permissions all areas of the **Operations** tab|
|Jobs: Read|Grants read-only access to **Operations > Job Definitions**|
|Jobs: Create|Grants ability to create new job definitions|
|Jobs: Edit|Grants ability to edit existing job definitions|
|Jobs: Delete|Grants ability to delete job definitions|
|Jobs: Interact|Grants ability to manage scheduled job instances (start, stop, cancel, etc.)|
|Renditions: Read|Grants read-only access to **Operations > Rendition Status**|
|SDK Job Queues: Read|Grants read-only permission to SDK job queues in **Operations > SDK Job Queues**|
|SDK Job Queues: Create|Grants ability to create SDK job queues in **Operations > SDK Job Queues**|
|SDK Job Queues: Edit|Grants ability to edit SDK job queues in **Operations > SDK Job Queues**|
|SDK Job Queues: Delete|Grants ability to delete SDK job queues in **Operations > SDK Job Queues**|
|Email Notifications: Read|Grants permission to view the **Operations > Email Notification Status** page and the **Admin > Operations > Email Suppression List** page|
|Email Notifications: Delete|Grants the ability to delete a record from the <a href="/en/gr/542073/">Email Suppression</a> list|

### Security

|Permission|Access Details|
|--- |--- |
|Security: All Security Admin|Grants all 'Security' permissions; individual permissions are explained below.|
|Security: All Security Admin Read|Grants all 'Read' permissions in 'Security'; individual permissions are explained below.|
|Security Settings: Read|Grants read-only access to **Settings > Security Settings**|
|Security Settings: Edit|Grants edit access to **Settings > Security Settings**|
|Users: Read|Grants read-only access to **Users & Groups > Vault Users**|
|Users: Create|Grants access to create new users or add users from another Vault from **Users & Groups > Vault Users**|
|Users: Edit|Grants access to edit existing users from **Users & Groups > Vault Users**|
|Users: Assign Group|Grants access to assign users to groups from **Users & Groups > Vault Users**|
|Users: Grant Support Login|Grants permission to give Vault Support user account access for a specific user from **Users & Groups > Vault Users**|
|Users: Delegate Admin|Grants permission to give delegate access to another user's account from **Users & Groups > Vault Users**|
|Users: Add Cross-Domain Users|Grants permission to add cross-domain users from **Users & Groups > Vault Users**|
|Users: Manage User Object|Grants ability to create, modify, and add User object records.|
|Groups: Read|Grants read-only access to **Users & Groups > Groups**|
|Groups: Create|Grants ability to create new groups from **Users & Groups > Groups**|
|Groups: Edit|Grants ability to edit existing groups from **Users & Groups > Groups**|
|Groups: Delete|Grants ability to delete existing groups from **Users & Groups > Groups**|
|Groups: Assign Users|Grants ability to assign users to groups from **Users & Groups > Groups**|
|Security Profiles: Read|Grants read-only access to **Configuration > Security Profiles**|
|Security Profiles: Create|Grants ability to create new security profiles from **Configuration > Security Profiles**|
|Security Profiles: Edit|Grants ability to edit existing security profiles from **Configuration > Security Profiles**|
|Security Profiles: Delete|Grants ability to delete existing security profiles from **Configuration > Security Profiles**|
|Security Profiles: Assign Users|Grants ability to assign users to a security profile from **Users & Groups > Security Profiles**. You must also have at least the same permissions as those associated with a security profile to assign users.|
|Permission Sets: Read|Grants read-only access to **Configuration > Permission Sets**|
|Permission Sets: Create|Grants ability to create new permission sets from **Configuration > Security Profiles**|
|Permission Sets: Edit|Grants ability to edit existing permission sets from **Configuration > Security Profiles**|
|Permission Sets: Delete|Grants ability to delete existing permission sets from **Configuration > Security Profiles**|

### About

|Permission|Access Details|
|--- |--- |
|About: Vault Information: Read|Grants read-only permission to the **Admin > About > Vault Information** page|
|About: Domain Information: Read|Grants read-only permission to the **Admin > About > Domain Information** page|

### Settings {#settings}

|Permission|Access Details|
|--- |--- |
|Settings: All Settings Edit|Grants edit permissions for all pages in **Admin > Settings**|
|Settings: All Settings Read|Grants read-only permission for all pages in **Admin > Settings**|
|General Configuration: Read|Grants read-only permission to the **Settings > General Settings** page <br>Additionally grants read-only permission to the **Settings > Help Settings** page as well as <a href="/en/gr/18132/">feature enablement</a>|
|General Configuration: Edit|Grants edit permission to the **Settings > General Settings** page <br> Additionally grants edit permission to the **Settings > Help Settings** page as well as <a href="/en/gr/18132/">feature enablement</a>|
|Checkout: Read|Grants read-only permission to the **Settings > Checkout Settings** page|
|Checkout: Edit|Grants edit permission to the **Settings > Checkout Settings** page|
|Versioning: Read|Grants read-only permission to the **Settings > Versioning Settings** page|
|Versioning: Edit|Grants edit permission to the **Settings > Versioning Settings** page|
|Branding: Read|Grants read-only permission to the **Settings > Branding Settings** page|
|Branding: Edit|Grants edit permission to the **Settings > Branding Settings** page|
|Search: Read|Grants read-only permission to the **Settings > Search Settings** page|
|Search: Edit|Grants edit permission to the **Settings > Search Settings** page|
|Language: Read|Grants read-only permission to the **Settings > Language Settings** page|
|Language: Edit|Grants edit permission to the **Settings > Language Settings** page|
|Application: Read|Grants read-only permission to the **Settings > Application Settings** page|
|Application: Edit|Grants edit permission to the **Settings > Application Settings** page|
|Renditions: Read|Grants read-only permission to the **Settings > Rendition Settings** page|
|Renditions: Edit|Grants edit permission to the **Settings > Rendition Settings** page|

### Deployment

|Permission|Access Details|
|--- |--- |
|Migration Packages: Create|Grants ability to create new outbound Configuration Migration Packages from **Admin > Deployment**|
|Migration Packages: Deploy|Grants ability to deploy Configuration Migration Packages from **Admin > Deployment**|
|Environment: Vault Configuration Report |Grants ability to run a Vault Configuration Report from **Admin > Deployment**|
|Environment: Vault Comparison|Grants ability to use Vault Compare from **Admin > Deployment**|
|Sandbox: Read  |Grants ability to view sandboxes in the **Admin > Deployment > Sandbox Vaults** page|
|Sandbox: Create|Grants ability to create sandboxes in the **Admin > Deployment > Sandbox Vaults** page. Also grants the ability to build and promote a pre-production Vault to a production Vault.|
|Sandbox: Edit  |Grants ability to edit and refresh sandboxes in the **Admin > Deployment > Sandbox Vaults** page  |
|Sandbox: Delete|Grants ability to delete and refresh sandboxes in the **Admin > Deployment > Sandbox Vaults** page|

## Application Permissions {#applicationpermissions}

Access to certain Vault-area functionality is controlled by permissions assigned via permission sets and security profiles. The sections below align with the headings in the **Application** tab of the **Permission Sets** page.

There are three layers of security applied to actions. First, you must have a license type that allows the action. For example, the _Read-Only User_ license type does not allow access to reports. Second, you must have a permission set that grants the correct permission. For example, you would need the **Read Dashboards and Reports** permission to see any dashboard. Third, for document actions, you must have the correct document role-based permissions. For example, even with a permission set that grants the **Bulk Update** permission, you would also need the **Edit Fields** permission on any documents that you're attempting to update in order to perform a bulk document field edit.

### Vault Actions {#Vault_Actions}

<table class="wbord" style="height: 5240px;">
  <tr style="height: 24px;">
    <td style="width: 164px; height: 24px;">
      <strong>Permission</strong>
    </td>
    <td style="width: 454px; height: 24px;">
      <strong>Access Details</strong>
    </td>
  </tr>
  <tr style="height: 48px;">
    <td style="width: 164px; height: 48px;">
      Vault Actions: All Vault Actions
    </td>
    <td style="width: 454px; height: 48px;">
      Grants all 'Vault Actions' permissions; see details for individual permissions below.
    </td>
  </tr>
  <tr style="height: 48px;">
    <td style="width: 164px; height: 48px;">
      Dashboards and Reports: All
    </td>
    <td style="width: 454px; height: 48px;">
      Grants all 'Dashboard' permissions; see details for individual permissions below.
    </td>
  </tr>
  <tr style="height: 96px;">
    <td style="width: 164px; height: 96px;">
      Dashboards and Reports: Read Dashboards and Reports
    </td>
    <td style="width: 454px; height: 96px;">
      Grants permission to run any reports that other users have shared with you.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Dashboards and Reports: Create Dashboards
    </td>
    <td style="width: 454px; height: 72px;">
      Grants permission to create new dashboards and to edit any dashboards that you created or to which other users have given you the Editor role.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Dashboards and Reports: Delete Dashboards
    </td>
    <td style="width: 454px; height: 72px;">
      Grants permission to delete your own dashboards or dashboards to which other users have given you the Editor role.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Dashboards and Reports: Share Dashboards
    </td>
    <td style="width: 454px; height: 72px;">
      Grants permission to use the <strong>Share</strong> action on dashboards that you created or to which other users have given you the Editor role.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Dashboards and Reports: Schedule Reports
    </td>
    <td style="width: 454px; height: 72px;">
      Grants permission to use the <strong>Schedule</strong> action to schedule flash reports.
    </td>
  </tr>
  <tr style="height: 96px;">
    <td style="width: 164px; height: 96px;">
      Dashboards and Reports: Administer Dashboards
    </td>
    <td style="width: 454px; height: 96px;">
      Grants permission to view and edit all dashboards, including dashboards created by another user who has not shared them. With this permission, a user may share and delete other users' dashboards.
    </td>
  </tr>
  <tr>
    <td style="width: 164px;">
      Dashboards and Reports: Display API Name Dashboards
    </td>
    <td style="width: 454px;">
      Grants permission to view the API names of dashboards.
    </td>
  </tr>
  <tr>
    <td style="width: 164px;">
      Dashboards and Reports: Read Group Membership
    </td>
    <td style="width: 454px;">
      Grants permission to view reports that contain both users and groups.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Workflow: All Workflow
    </td>
    <td style="width: 454px; height: 72px;">
      Grants all 'Workflow' permissions; see details below for individual permissions. This does not include 'Workflow Administration' permissions.
    </td>
  </tr>
  <tr style="height: 24px;">
    <td style="width: 164px; height: 24px;">
      Workflow: Start
    </td>
    <td style="width: 454px; height: 24px;">
      Grants permission to start workflows.
    </td>
  </tr>
  <tr style="height: 24px;">
    <td style="width: 164px; height: 24px;">
      Workflow: Participate
    </td>
    <td style="width: 454px; height: 24px;">
      Grants permission to participate in workflows. Also grants permission to use VQL to query workflow data. Learn more in the <a class="external-link " href="https://developer.veevavault.com/vql/#Querying_Workflows" target="_blank" rel="noopener">Developer Documentation<i class="fa fa-external-link" aria-hidden="true"></i></a>.
    </td>
  </tr>
  <tr style="height: 48px;">
    <td style="width: 164px; height: 48px;">
      Workflow: Read and Understand
    </td>
    <td style="width: 454px; height: 48px;">
      Grants permission to participate in Read & Understood workflows.
    </td>
  </tr>
  <tr style="height: 48px;">
    <td style="width: 164px; height: 48px;">
      Workflow: eSignature
    </td>
    <td style="width: 454px; height: 48px;">
      Grants permission to provide an eSignature as part of a workflow.
    </td>
    </tr>
    <tr style="height: 48px;">
    <td style="width: 164px; height: 48px;">
      Workflow: Query
    </td>
    <td style="width: 454px; height: 48px;">
    Grants permission to use VQL to query workflow data. Learn more in the <a class="external-link " href="https://developer.veevavault.com/vql/#Querying_Workflows" target="_blank" rel="noopener">Developer Documentation<i class="fa fa-external-link" aria-hidden="true"></i></a>.
  </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Workflow Administration: All Workflow Admin
    </td>
    <td style="width: 454px; height: 72px;">
      Grants all 'Workflow Administration' permissions; see details below for individual permissions. This does not include 'Workflow' permissions.
    </td>
  </tr>
  <tr style="height: 96px;">
    <td style="width: 164px; height: 96px;">
      Workflow Administration: Cancel
    </td>
    <td style="width: 454px; height: 96px;">
      Grants permission to cancel any active workflow or open task that you can see, even if you are not the workflow or task owner. If your Vault uses Atomic Security for Active Workflow Actions, users must have both this permission and access through Atomic Security.
    </td>
  </tr>
  <tr style="height: 96px;">
    <td style="width: 164px; height: 96px;">
      Workflow Administration: View Active
    </td>
    <td style="width: 454px; height: 96px;">
      Grants permission to view all active Read & Understood workflows on the document for non-current document versions in Quality Vaults, including those on which you are not a participant.
    </td>
  </tr>
  <tr style="height: 120px;">
    <td style="width: 164px; height: 120px;">
      Workflow Administration: Reassign
    </td>
    <td style="width: 454px; height: 120px;">
      Grants permission to reassign workflow tasks that are currently assigned to other users, even if you are not the workflow owner. If your Vault uses Atomic Security for Active Workflow Actions, users must have both this permission and access through Atomic Security.
    </td>
  </tr>
  <tr style="height: 96px;">
    <td style="width: 164px; height: 96px;">
      Workflow Administration: Update Participants
    </td>
    <td style="width: 454px; height: 96px;">
      Grants permission to add a participant to a workflow, even if you are not the workflow owner. If your Vault uses Atomic Security for Active Workflow Actions, users must have both this permission and access through Atomic Security.
    </td>
  </tr>
  <tr style="height: 96px;">
    <td style="width: 164px; height: 96px;">
      Workflow Administration: Email Participants
    </td>
    <td style="width: 454px; height: 96px;">
      Grants permission to email workflow participants, even if you are not the workflow owner. If your Vault uses <a href="/en/gr/47850/#active-workflow-actions">Atomic Security for Active Workflow Actions</a>, users must have both this permission and access through Atomic Security. Learn more about <a href="/en/gr/50506/">Managing Active Document Workflows</a> or <a href="/en/gr/33553/">Managing Active Object Workflows</a>.
    </td>
  </tr>
  <tr style="height: 120px;">
    <td style="width: 164px; height: 120px;">
      Workflow Administration: Update Workflow Dates
    </td>
    <td style="width: 454px; height: 120px;">
      Grants permission to update all workflow dates or specific task due dates, even if you are not the workflow owner. If your Vault uses Atomic Security for Active Workflow Actions, users must have both this permission and access through Atomic Security.
    </td>
  </tr>
  <tr>
    <td style="width: 164px;">
      Workflow Administration: Replace Workflow Owner
    </td>
    <td style="width: 454px;">
      Grants permission to replace the workflow owner on an active workflow.
    </td>
  </tr>
  <tr style="height: 48px;">
    <td style="width: 164px; height: 48px;">
      API: All API
    </td>
    <td style="width: 454px; height: 48px;">
      Grants all 'API' permissions; see details for individual permissions below.
    </td>
  </tr>
  <tr style="height: 24px;">
    <td style="width: 164px; height: 24px;">
      API: Access API
    </td>
    <td style="width: 454px; height: 24px;">
      Grants basic permission to complete a Vault API call and download files from file staging, and access to Vault Loader. Users must have both this permission and <em>File Staging: Access</em> to download files.
    </td>
  </tr>
  <tr style="height: 48px;">
    <td style="width: 164px; height: 48px;">
      API: Events API
    </td>
    <td style="width: 454px; height: 48px;">
      Grants access to the Events APIs, used in PromoMats Vaults with CLM integration.
    </td>
  </tr>
  <tr style="height: 24px;">
    <td style="width: 164px; height: 24px;">
      API: Metadata API
    </td>
    <td style="width: 454px; height: 24px;">
      Grants access to metadata APIs, including read and write access to MDL APIs.
    </td>
  </tr>
  <tr style="height: 24px;">
    <td style="width: 164px; height: 24px;">
      API: Direct Data API
    </td>
    <td style="width: 454px; height: 24px;">
      Grants access to the Direct Data API.
    </td>
  </tr>
  <tr style="height: 48px;">
    <td style="width: 164px; height: 48px;">
      CrossLink: Create CrossLink
    </td>
    <td style="width: 454px; height: 48px;">
      Grants ability to create a CrossLink document if this functionality is available on your Vault.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Viewer Administration: Manage Tags
    </td>
    <td style="width: 454px; height: 72px;">
      Grants ability to <a href="/en/gr/7779/">manage annotation tags</a>.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Viewer Administration: Merge Anchors
    </td>
    <td style="width: 454px; height: 72px;">
      Grants ability to <a href="/en/gr/16418/">merge document link anchors</a>.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Viewer Administration  Remove Annotations
    </td>
    <td style="width: 454px; height: 72px;">
      Grants ability to remove annotations brought forward from another version by a different user
    </td>
  </tr>
  <tr style="height: 120px;">
    <td style="width: 164px; height: 120px;">
      Viewer Administration: Manage Anchors
    </td>
    <td style="width: 454px; height: 120px;">
      Grants ability to bring forward anchors. Brought forward anchors have no inbound references. This permission also grants the ability to move and delete any anchor that does not have an inbound reference, and the ability to edit the name of any anchor.
    </td>
  </tr>
  <tr style="height: 144px;">
    <td style="width: 164px; height: 144px;">
      Document: Cancel Checkout
    </td>
    <td style="width: 454px; height: 144px;">
      Grants ability to cancel checkout (using the <strong>Undo Checkout</strong> action) for documents that another user has checked out. You must also have the <strong>Edit Document</strong> role-based permission for a document to perform this action. Document Owners can always cancel checkout if they have the <strong>Edit Document</strong> role-based permission.
    </td>
  </tr>
  <tr style="height: 120px;">
    <td style="width: 164px; height: 120px;">
      Document: Download Document
    </td>
    <td style="width: 454px; height: 120px;">
      Grants ability to download document source files. You must also have the appropriate role-based permissions for a document to perform this action. This permission does not control access to the <strong>Check Out</strong> action or the <strong>Export Binder</strong> action.
    </td>
  </tr>
  <tr style="height: 168px;">
    <td style="width: 164px; height: 168px;">
      Document: Download Rendition
    </td>
    <td style="width: 454px; height: 168px;">
      Grants ability to download document renditions, including <em>Viewable Rendition</em> and <em>PDF with Annotations</em>; without this permission, you also cannot use the <strong>Export Annotations</strong> action. You must also have the appropriate role-based permissions for a document to perform this action. This permission does not control access to the <strong>Export Binder</strong> action.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Document: Bulk Delete
    </td>
    <td style="width: 454px; height: 72px;">
      Grants ability to perform bulk document deletion. You'll also need the correct document role-based permissions to delete a document.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Document: Bulk Update
    </td>
    <td style="width: 454px; height: 72px;">
      Grants ability to perform bulk document updates. You'll also need the correct document role-based permissions to update a document.
    </td>
  </tr>
  <tr style="height: 144px;">
    <td style="width: 164px; height: 144px;">
      Document: Always Allow Unclassified
    </td>
    <td style="width: 454px; height: 144px;">
      Grants the ability to create unclassified documents even without document creation permission on any document type, except for users with the Read-only license type. Users with <strong>Create Document</strong> permission on any document types are automatically allowed to create unclassified documents, regardless of this permission.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Document: Vault File Manager
    </td>
    <td style="width: 454px; height: 72px;">
      Grants ability to check out documents to Vault File Manager using the Check Out to File Manager action or Document Check Out bulk action.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Document: Download Non-Protected Rendition
    </td>
    <td style="width: 454px; height: 72px;">
      Grants ability to download viewable renditions without any Vault-configured security settings or Vault protection applied.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Object: Bulk Action
    </td>
    <td style="width: 454px; height: 72px;">
      Grants the ability to perform bulk object record updates. You'll also need the correct object role-based permissions to update an object record.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Object: Merge Records
    </td>
    <td style="width: 454px; height: 72px;">
      Grants the ability to perform <a href="/en/gr/659058/">record merges</a>. You'll also need the correct object role-based permissions to read, update, and delete the object records.
    </td>
  </tr>
  <tr style="height: 48px;">
    <td style="width: 164px; height: 48px;">
      User: Allow As A Delegate
    </td>
    <td style="width: 454px; height: 48px;">
      Grants the permission to allow a user to be selected as a delegate through the <strong>Delegated Access</strong> feature.
    </td>
  </tr>
  <tr style="height: 192px;">
    <td style="width: 164px; height: 192px;">
      User: View User Information
    </td>
    <td style="width: 454px; height: 192px;">
      Grants the ability to view the name and identifying information of other users in this Vault, use the <strong>Send as Link</strong> action, and view Timeline View and Sharing Settings information on the Doc Info page. Users without this permission may only see the names and identifying details of other users who share the same email domain. For example, Teresa, whose email is tibanez@veepharm.com can see the user information of all @veepharm.com users, but she can't see @medi-review.com users.
    </td>
  </tr>
  <tr style="height: 48px;">
    <td style="width: 164px; height: 48px;">
      User: View User Profile
    </td>
    <td style="width: 454px; height: 48px;">
      Grants users the ability to view their own <a href="/en/gr/7239/">user profile</a> and see the User Profile option in their user dropdown menu.
    </td>
  </tr>
  <tr style="height: 48px;">
    <td style="width: 164px; height: 48px;">
      Search: Manage Archives
    </td>
    <td style="width: 454px; height: 48px;">
      Grants ability to manage <a href="/en/gr/34126/">search archives</a>. This also grants the <strong>View Archive</strong> permission.
    </td>
  </tr>
  <tr style="height: 96px;">
    <td style="width: 164px; height: 96px;">
      Search: Term Suggestions
    </td>
    <td style="width: 454px; height: 96px;">
      Grants ability to see search term suggestions. Search term suggestions are not affected by any other permission. For example, a user will see a search term suggestion for "cholecap" even if they don't have access to the "Cholecap" Product.
    </td>
  </tr>
  <tr style="height: 120px;">
    <td style="width: 164px; height: 120px;">
      Search: User Filters
    </td>
    <td style="width: 454px; height: 120px;">
      Grants ability to see filters on user reference fields when searching for documents or object records, for example, Created By and Last Modified By. This setting is typically disabled for security profiles that apply to sponsors when a CRO wants to hide user information.
    </td>
  </tr>
  <tr style="height: 48px;">
    <td style="width: 164px; height: 48px;">
      Search: View Archive
    </td>
    <td style="width: 454px; height: 48px;">
      Grants ability to view documents in the archive. You'll also need the correct document role-based permissions.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Application: Send to CDN
    </td>
    <td style="width: 454px; height: 72px;">
      Grants ability to send a document to CDN through a private API; this permission is only used by CRM's conversion tool for integrations and should not be applied to users.
    </td>
  </tr>
  
<tr style="height: 48px;">
    <td style="width: 164px; height: 48px;">
      Application: Approved Email
    </td>
    <td style="width: 454px; height: 48px;">
      Grants ability to use the <a href="/en/gr/12080/"><strong>Create Email Fragment</strong></a>.
    </td>
  </tr>
  <tr style="height: 96px;">
    <td style="width: 164px; height: 96px;">
      Application: Multichannel Loader
    </td>
    <td style="width: 454px; height: 96px;">
      Ability to access the <strong>CRM Publishing</strong> and <strong>Multichannel Loader</strong> tabs; by default, this permission is only granted to users with the standard <em>System Admin</em> or <em>Vault Owner</em> security profiles.
    </td>
  </tr>
  <tr style="height: 24px;">
    <td style="width: 164px; height: 24px;">
      Views: Share Views
    </td>
    <td style="width: 454px; height: 24px;">
      Grants ability to share custom views with other users.
    </td>
  </tr>
  <tr style="height: 224px;">
    <td style="width: 164px; height: 224px;">
      Views: Make Mandatory
    </td>
    <td style="width: 454px; height: 224px;">
      Grants ability to:
      <ul>
        <li>
Add a custom view to other users' sidebar and make it non-removable
        </li>
        <li>
Modify any other mandatory view
        </li>
        <li>
Delete other users' mandatory views
        </li>
        <li>
Select custom view icons
        </li>
        <li>
Delete system-owned views created through cloning (where applicable)
        </li>
      </ul>
    </td>
  </tr>
  <tr style="height: 96px;">
    <td style="width: 164px; height: 96px;">
      Audit Trail: View
    </td>
    <td style="width: 454px; height: 96px;">
      Grants ability to access the <strong>Audit Trail</strong> option for individual documents and object records through the <strong>All Actions</strong> menu. You must also have the appropriate role-based permissions to perform this action.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      Audit Trail: Export
    </td>
    <td style="width: 454px; height: 72px;">
      Grants ability to export a document or object record audit trail. You must also have the <strong>Audit Trail > View</strong> permission before you can export.
    </td>
  </tr>

  <tr style="height: 96px;">
    <td style="width: 164px; height: 96px;">
      File Staging: Access
    </td>
    <td style="width: 454px; height: 96px;">
      Grants ability to connect to file staging and download files extracted using Vault Loader (document source files and renditions). This permission does not grant the ability to upload files to the server or view directories created by other users. Users must have both this permission and <em>API: Access API</em> to download files.
    </td>
  </tr>
  <tr style="height: 96px;">
    <td style="width: 164px; height: 96px;">
      File Staging: Access via Vault File Manager
    </td>
    <td style="width: 454px; height: 96px;">
      Grants ability to connect to file staging and upload files and folders using Vault File Manager. This permission does not grant the ability to upload files to the server or view directories created by other users.
    </td>
  </tr>
  <tr style="height: 96px;">
    <td style="width: 164px; height: 96px;">
      File Staging: Access Root Folder
    </td>
    <td style="width: 454px; height: 96px;">
      Grants ability to access the file staging server's root folder. By default, this permission is enabled in the standard <em>Vault Owner</em> and <em>System Administrator</em> permission sets.
    </td>
  </tr>
  <tr style="height: 72px;">
    <td style="width: 164px; height: 72px;">
      EDL Matching: Run
    </td>
    <td style="width: 454px; height: 72px;">
      Ability to access the <strong>Start Now</strong> action on scheduled batch matching job or the <strong>Match Documents</strong> action on an individual EDL item
    </td>
  </tr>
  <tr style="height: 48px;">
    <td style="width: 164px; height: 48px;">
      EDL Matching: Edit Match Fields
    </td>
    <td style="width: 454px; height: 48px;">
      Ability to edit the <em>EDL Matching Field</em> picklist on an <em>EDL</em> record
    </td>
  </tr>
  <tr style="height: 96px;">
    <td style="width: 164px; height: 96px;">
      EDL Matching: Edit Document Matches
    </td>
    <td style="width: 454px; height: 96px;">
      Ability to lock the document version matched with an <em>EDL Item</em> record, exclude or include matched documents in summary fields, and manually match/unmatch documents from an <em>EDL Item</em>
    </td>
  </tr>
  <tr style="height: 96px;">
    <td style="width: 164px; height: 96px;">
      Create Button: Show Create Button
    </td>
    <td style="width: 454px; height: 96px;">
      Ability to see the <strong>Create</strong> button on all tabs. This option is turned on by default on all existing standard and custom permission sets and turned off by default on all new custom permission sets.
    </td>
  </tr>
</table>

### Vault Owner Actions {#vault-owner-actions}

These permissions control actions that are available to users with the standard <a href="/en/gr/31186/">_Vault Owner_</a> security profile.

|Permission|Access Details|
|--- |--- |
|Vault Owner Actions: Re-render|Grants ability to save page rotations, re-render a document that already has a viewable rendition, and delete a viewable rendition; see <a href="/en/gr/1403/">related article</a>.|
|Vault Owner Actions: Power Delete|Grants ability to delete documents that otherwise could not be deleted, for example, documents in steady state; see <a href="/en/gr/3292/">related article</a>.|
|Vault Owner Actions: Vault Loader|Grants ability to see and use the _Loader_ tab. Users must have both this permission and _Application: API: Access API_ to download files.|
|Vault Owner Actions  Record Migration|Grants ability to load object records (through Vault Loader or Vault API only) in a lifecycle state other than _Starting State_.|
|Vault Owner Actions: Document Migration|Grants ability to apply Document Migration Mode only to a batch of new documents upon creation through Vault Loader or Vault API; see <a href="/en/gr/54028/">related article</a>.|
|All Documents: All Document Actions|Grants all permissions in 'All Documents'; see details for individual permissions below.|
|All Documents: All Document Read|Grants view access to all documents, regardless of the document's Sharing Settings.|
|All Documents: All Document Create|Grants access to create documents or binders for any document type, regardless of document type **Create** settings|
|All Object Records: All Object Records Actions|Grants access to all permissions in 'All Object Records'; see details for individual permissions below.|
|All Object Records: All Object Record Read|Grants view access to all object records, regardless of the record's Sharing Settings.|
|All Object Records: All Object Record Edit|Grants edit access (same as Owner role) to all object records, regardless of the record's Sharing Settings.|
|All Object Records: All Object Record Delete|Grants delete access to all object records, regardless of the record's Sharing Settings.|
|Legal Hold: Apply|Grants ability to apply/edit a legal hold to a single document or as a bulk action.|
|Legal Hold: Remove|Grants ability to remove a legal hold from a single document or as a bulk action.|
|Connections: Manage Connections|Grants the ability to view and manage connections in the **Connections** tab in Vault Admin.|
|Integrations: Manage Integrations|Grants the ability to view and manage integration configuration such as user exception messages, integration rules, and Spark message processors in the **Connections** tab in Vault Admin.|

## Object Permissions {#objectpermissions}

From the **Objects** tab, you can assign permission to view, create, edit, and delete object records at the object level. For example, a user could have full permissions to _Study Site_ object records, **Edit** permission to _Study_ records, **Read** access to _Product_ records, and no access to _Country_ records. From this tab, you can also set up <a href="/en/gr/39108/">field-level security</a>, <a href="/en/gr/43127/#action_level_security">action-level security</a>, and [object control-level security][1] on objects.

For each object, you can grant or remove the following permissions:

* **Read**: Allows you to view records for the object; see [details][0]
* **Create**: Allows you to create new object record or to copy an existing record; allows you to access **Business Admin > Objects**. With this permission, Vault automatically grants **Edit** permission.
* **Edit**: Allows you to edit an existing object record, including adding/deleting/versioning attachments; allows you to access **Business Admin > Objects**
* **Delete**: Allows you to delete an existing object record

Granting these permissions for **All Objects** means that the permission set will automatically include the permissions for any object created in the future.

### Object Control Permissions {#object-control-permissions}

You can also modify permissions for object controls from the **Objects** tab. Object controls are used to control whether users are able to view certain UI elements. Object controls associated with a given object or available to all objects appear under the _Object Control Permissions_ heading.

Unlike object fields or actions, the only permission that you can assign for object controls is **View**. You can assign this permission on a single control or select **All Object Controls**. If the object control is associated with an object type, you can only grant _View_ permissions across all object types. You cannot grant _View_ permissions per control per object type.

### Dynamic Access Control

<a href="/en/gr/33946/">Dynamic Access Control</a> interacts with these settings to prevent users from viewing, editing, or deleting specific object records. If an object uses DAC, users must have both the appropriate permission through their security profile and access through the individual object record's sharing settings. When creating a record, Vault only considers the user's permission sets.

## Tab Permissions {#tab-permissions}

From the **Tabs** section, you can control what tabs and tab collections a user can view. All standard tabs, custom tabs, and custom tab collections can be configured here. By default, users with the **View** permission on **All** tabs can view newly created tabs, and users with the **View** permission on **All Tab Collections** can view newly created tab collections.

### About the Read Permission {#object_read}

Users must have the **Read** permission on an object to:

* View a custom object tab
* View an object tab in **Business Admin**
* See object record details in a hovercard
* Select an object record when editing document or object fields
* Create a report using a report type that includes the object
* View results for a report using a report type that includes the object

Users without this permission can still view object record labels throughout Vault. For example, they can still search for documents using object fields for an object they cannot view.

## Pages Permissions

From the **Pages** section, you can control which application-specific _Pages_ a user can access.

## Mobile Permissions

From the **Mobile** section, you can control which tabs a user can view in <a href="/en/gr/71324/">Veeva Vault Mobile</a>.

## API Permissions

From the API section, you can see which Web API Groups a user can access. Learn more about Web APIs in the <a class="external-link " href="https://developer.veevavault.com/sdk/#Custom_API" target="_blank" rel="noopener">Vault Java SDK documentation<i class="fa fa-external-link" aria-hidden="true"></i></a>.

## Hidden or Missing Permissions

When you open a permission set, some of the permissions listed above will not appear. If a permission does not appear:

* The permission is specific to another Vault application or another application family. For example, the permission is specific to RIM and you are in a Clinical Operations Vault.
* The permission is related to a feature that is not enabled on your Vault. Sometimes, permissions are hidden when the related feature is not enabled.

 [0]: #object_read
 [1]: #object-control-permissions
