Everything about access, every space you can open, every connector you can use, every member of a group, comes down to grants. If you understand grants, you understand how permission works across the whole product.
Principal, role, scope
A grant answers one precise question: can this principal, in this role, act on this thing? So every grant ties together three parts:
Put together, a single grant says something like "this group has the editor role on this space." Access is always expressed as grants of exactly this shape, nothing looser and nothing more complicated.
Read about how access control works here.
What you don't have to grant
Grants are designed so you set them in as few places as possible.
Child resources inherit. A workflow doesn't get its own grants; it takes them from the space it lives in. Grant access to the space and everything inside follows.
Personal spaces are fixed. Everyone's private space comes with the right grants built in, and they can't be edited.
Creators are covered automatically. When you make a resource, you're granted the roles to run and manage it, so you're never locked out of your own work.
