Access & roles
Route: /governance · Settings section
What it is
The place that explains who may do what in the tenant — and why an action was refused. Covers your own access, tenant roles, built-in roles, and agent roles.
What it is for
- Understand permission errors (“why can’t I install a capa?”)
- Design roles before inviting many users
- Separate operator power from agent power
Where you are in the flow
★ Access & roles (design) → Users (assign people) → people use Office / My work
This is governance setup, not the live approval inbox (My work).
What you do here
- Check Your access if something is blocked.
- Review tenant / built-in roles.
- Adjust carefully; then assign people under Users.
Where work goes next
| Goal | Next |
|---|---|
| Assign a person | Users |
| Agent tool rights | Department Integrations + Agent Access tabs |
| Live approvals | My work |