You can create user groups with defined permission levels in the Govstack CMS. Once you have created user groups, you can add users and assign them the permissions defined within a group.
You need to have access to the 'Users' tab in your Govstack dashboard in order to create user groups and add users to them.
Please note: In the CMS, events, and forms tools user accounts do not automatically appear in these applications when created in the admin portal. The user will need to login to each application using their credentials to generate an account. Following this initial login the user will appear in each application and can be assigned specific permissions and access.
Default user roles
When users are added to the Govstack platform, they will gain access to the Govstack CMS. The specific user type at the platform level will inform the permissions each user receives within the Govstack Content Management System (CMS).
There are two default user roles for the Govstack CMS. Explore each user type and find out what permissions they have.
Website Administrators
Website administrators have the following permissions in the Govstack CMS:
- Access to the Content, Media, Workflow and Users tabs
- Optional features on your website may also include the Members and Reports tab
- Create content templates
- Browse, create, publish, delete, unpublish and update all content pages
- Set up notifications for content pages
- Allow access to change permissions for a node
- Allow access to set up webpage publishing approvals with the Workflow tools
Editors
Anyone added as a Govstack platform User, will receive Editor permissions in the Govstack CMS. All Editors will have the following permissions:
- Access to the Content and Media tabs
- Create content templates
- Browse, create, publish, delete, unpublish and update all content pages
- Set up notifications for content pages
- Copy, move and sort content pages in the back office
Note that the default permissions for the Editor group can be modified as required.
Warning: Removing an admin account from the Website Administrators group or removing a user from the Editor group is temporary and will only last for a single session. The next time that the account logs in they are automatically returned to their original groups. This can give the impression that permissions change but this is normal and expected behavior. No other user groups are impacted my this default behavior. This default update cannot be modified or deactivated.
Watch our training video
Create a user group
To create a user group with a defined set of permissions in your Govstack CMS, you need to:
- Navigate to the Govstack CMS from your Govstack dashboard
- Select the 'Users' tab from the Govstack main menu. This will only be available to website administrators.
- Select 'Groups' at the top right of the interface
- Select 'Create Group'
- Enter a name for the user permission group
- Enter the permission details, including which sections of the CMS users in the group can access
View the details for setting different types of permissions in a user group.
Assign which sections of the CMS users can access
You can choose which sections of the CMS you want the user group to have access to. This will determine which tabs users in that group can view and access at the top of their Govstack CMS interface.
Note that access to a section does not provide any specific permission to edit or add content. This is provided by granular and default permissions.
Available section may including:
- Content
- Media
- Users
- Members
- Workflow
- Reports
To select which sections the user group can access:
- Navigate to the 'Sections' heading under 'Assign access'
- Select 'Add'
- Select all the sections of the CMS you want the group to have access to. You can only add sections to a group if you have access to them yourself.
- Click 'Submit'
To remove a section so that the group can no longer access it, select 'Remove' next to the section name in the list.
Assign which languages the CMS users can access
You can choose if users in your CMS have limited access to different languages. If a user does not have access to a given language they will not be able to edit fields or inputs marked as that language.
If your website uses a single language or if you would like users to have unrestricted use of all language-specific fields toggle on the 'Allow access to all languages' slider.
To allow a user group access to specific languages:
- Navigate to the 'Languages' heading under 'Assign access'
- Select 'Add'
- Select all required languages
- Click 'Submit'
To remove a language so that the group can no longer access it, select 'Remove' next to the language name in the list.
Assign the 'Content' start node
You can limit which pages/nodes a user group can access in the content tree. You must specify a start node in the content tree or the group will have no access to content.
A start node defines only what nodes a user can access in the content tree. To view or edit these nodes the group must also be assigned appropriate default or granular permissions.
To limit which content pages/nodes the user group can access:
- Navigate to the 'Content start node' heading under 'Assign access'
- Select 'Add'
- Select the node you want users to be able to access. This includes access to all nodes nested below the selected entry
You can select 'Remove' or 'Edit' next to the assigned node if you want to change which ones the user group can access.
A group can have only one content start node. If a user needs access to multiple start nodes on the same level you can do this by creating multiple user groups and assigning users to all required groups, or by moving the start node up in the file structure so that includes all required child nodes.
Assign the 'Media' start node
You can limit which media folders a user group can access in the 'Media' tab of the Govstack CMS back office. You must specify a start node in the media folder or the group will have no access to media.
To limit which media folders the user group can access:
- Navigate to the 'Media start node' heading under 'Assign access'
- Select 'Add'
- Select the folder you want users to be able to access
You can select 'Remove' or 'Edit' next to the assigned folder if you want to change which media folders the user group can access.
A group can have only one media start node. If a user needs access to multiple media nodes on the same level you can do this by creating multiple user groups and assigning users to all required groups.
Warning: Many organizations do not organize media content based on required access levels. If you need to limit user access to media files make sure you are planning how your media folders are organized early in your project. Reorganizing media files and folders after the fact can be frustrating and extremely time consuming.
Default permission vs. Granular permission
Permission come in two types, default and granular. They operate very differently and can have a major impact on your user access and the security of your site.
Default permissions
Default permission spread across nodes and user groups and are intended as administrator overrides. If a user group has a default permission any member of that group will have that access to any node or media section they can access through any user group they are part of. For example, a user group with delete permissions will allow a member to delete nodes in any section of the site they can access, even if that access is provided by a user group without delete access. As such default permissions are usually the exclusive domain of the Website Administrator user group. The vast majority of user groups should have no default permissions.
Granular Permissions
Granular permissions are isolated and do not impact access provided by other user groups or permissions. Most user groups will rely only on granular permission to provide access. Granular permissions will apply only to the specified node and its child nodes. To remove access to a node create a granular permission for that node and give it no permissions.
Default permission will override granular permission in all cases.
Assign CMS admin permissions
You can assign which admin permissions you want a user group to have within the CMS.
To do this, navigate to the 'Administration' heading under 'Default permissions'. Toggle on or off the administration capabilities you want the user group to have. Note that default permission spread to all user groups a user is part of. In almost all instances you should use granular permission instead.
Culture and hostnames
If you turn on this toggle, users in the group will be able to control the language settings for each page in the CMS as well as the CMS domain names.
Restrict public access
If you turn on this toggle, users in the group will be able to set and change access restrictions for specific pages in the CMS.
Rollback
If you turn on this toggle, users in the group will be able to roll back a page to a previous state.
Assign content permissions
You can assign which content page permissions you want a user group to have within the CMS. For example, you may want some users to be able to add content to a specific page, but not be able to publish the page.
To do this, navigate to the 'Content' heading under 'Default permissions'. Note that default permission spread to all user groups a user is part of. In almost all instances you should use granular permission instead.
Toggle on or off the content page capabilities you want the user group to have, including:
- Browse Node - the ability to open and view a page's content in the CMS. Required to edit page content. If you do not have Browse permission for a node it will not be visible in the content tree
- Create Content Template - the ability to create a content page template
- Delete - the ability to delete pages/nodes
- Create - the ability to create pages/nodes
- Notifications - the ability to set up notifications. This will send an email if the selected operation is performed on the target node or any of its child nodes
- Publish - the ability to publish a page. If your site has the Workflow option this is necessary to request page approvals
- Permissions - the ability to change permissions for a page
- Send to Publish - the ability to send a page for approval before publishing. If your site has the Workflow option this setting is no longer required (you will need the Publish permission instead). If you site uses the approval system (i.e. you have the Reports section) Send to Publish is required to request approvals
- Unpublish - the ability to unpublish a page
- Update - the ability to save changes to a page. Required to edit page content
Assign website structure and navigation permissions
You can assign which page structure permissions you want a user group to have within the CMS. Note that because menu manager
To do this, navigate to the 'Structure' heading under 'Default permissions'. Note that default permission spread to all user groups a user is part of. In almost all instances you should use granular permission instead.
Toggle on or off the page structure capabilities you want the user group to have, including:
- Copy - the ability to copy a page
- Move - the ability to move a page within the content tree
- Sort - the ability to change the order of the content under a page
Set granular permissions for specific pages
You can set the administrative, content and structure permissions for specific pages (and their child nodes) in the CMS if you want them to differ from your default settings. Note that default permission spread to all user groups a user is part of. In almost all instances you should use granular permission instead.
To do this, you need to:
- Navigate to the 'Nodes' heading under 'Granular permissions'
- Select 'Add'
- Select the page you want to set specific permissions for
- Toggle on or off the administrative, content and structure permissions you want the user group to have for that page and its child nodes
- Select 'Submit'
Note that granular permissions are effective only for nodes within a group's content and media start nodes. Nodes outside the start nodes will not be visible to the user group so their permissions are ignored.
Add and edit group users
After creating a user permissions group in your Govstack CMS, you can add users to that group to assign them the permissions defined by that group. You can also remove users if they no longer require the group permissions.
Users can be part of multiple user groups. Users who have permissions that overlap or conflict will have the highest level of access provided by any of their user groups. If users have default permissions in any user group they will apply to all user groups that user is part of.
Please note that all users are assigned to either the Editor or Website Administrator user group on login. Given this, you may want to modify the Editor permissions so that they don't interfere with any of your custom groups.
Before you can add a user to a group, they need to already be added as a CMS user. Learn how to add a Govstack CMS user before adding them to a user group.
To add a user to an existing user group, you need to:
- Navigate to the Govstack CMS from your Govstack dashboard
- Select the 'Users' tab from the Govstack main menu. This will only be available to website administrators.
- Select the 'Groups' tab at the upper right of the interface
- Select the name of the target user group
- Under 'Users' at the right of the interface, scroll to the bottom of the list of existing users and select 'Add'
- Select the name(s) of the user(s) you want to add, then click 'Submit'. A search option is provided to make the process easier
Edit user group permissions
To edit the permissions of a specific user group in your Govstack CMS, you need to:
- Navigate to the Govstack CMS from your Govstack dashboard
- Select the 'Users' tab from the Govstack main menu
- Select the 'Groups' tab at the upper right of the interface
- Select the name of the target user group
- Add, edit or remove the permissions you want
- Click 'Save' to complete the process