
A permission set is a named bundle of access rules. It is the mechanism that determines what a member can see and do in Mergepoint. Roles describe identity — permission sets govern access.
Each permission set defines access across two independent layers:
Feature permissions — which product areas a member can reach, and at what level:
Product area | What it covers |
|---|---|
Workflow Builder | Creating and editing automated workflows |
Form Studio | Building and publishing forms |
Analytics | Viewing reports and task metrics |
Knowledge Base | Reading and writing to connected data tables |
System permissions — which admin capabilities a member has (covered in detail in System Permissions: Admin Capabilities).
Each product area in a permission set carries one of three access levels:
Level | What it means |
|---|---|
Full access | View, create, edit, and delete content in that area |
Read only | View content; cannot create, edit, or delete anything |
No access | The area is completely hidden — the tab does not appear in the sidebar |
There is no locked or greyed-out tab. If a member has no access to a product area, it simply does not exist in their navigation.
A member can belong to more than one permission set. Their effective access is the broadest combination across all their sets. If one set grants read-only Analytics and another grants full access to the Workflow Builder, the member gets both.
This means you can compose access by combining sets rather than creating a single large set for every variation. See Assigning Members to Permission Sets for how to add or remove a member from a set.
One special permission set type exists above all others: the System set. Members in a System-type set have unconditional full access to every feature and admin capability — no individual rules apply. Use this only for workspace owners and designated super-admins. See System Permissions: Admin Capabilities for details.