Knowledge base / Intranet Builder / Roles & permissions
Roles & permissions
Three everyday roles plus the teams that install and maintain the intranet. SharePoint permissions, applied by the provisioning engine, decide what can actually be read and changed.
| Capability | Employee | Author | Approver | Site owner |
|---|---|---|---|---|
| Browse, search, read news, events, documents, policies | ✓ | ✓ | ✓ | ✓ |
| Submit ideas, recognition, page feedback | ✓ | ✓ | ✓ | ✓ |
| Acknowledge policies; keep my links; follow onboarding | Own | Own | Own | Own |
| Add and edit content in module lists | — | ✓ | ✓ | ✓ |
| Approve and moderate ideas, recognition, content | — | — | ✓ | ✓ |
| Manage pages; see error resolutions | — | — | — | ✓ |
| Setup Center, Configuration Manager, Health Dashboard | — | — | — | Intranet team only |
| Run the PowerShell installer | — | — | — | Full Control + role (see Part 9) |
List permission profiles
The engine applies a profile per data source. Restricted stores are always created by the installer and cannot be mapped to customer lists; site owners can read every item, so the web parts query them for the signed-in person explicitly.
| Profile | Meaning | Used by |
|---|---|---|
| inherit | Site permissions | Announcements, events, FAQ, policies, documents, contacts, offices, jobs, status, figures, glossary, gallery |
| ownersWrite | Everyone reads, only owners edit | Settings, module instances, navigation, departments, directory, celebrations |
| contributeOwn | Add and edit own, with approval | Ideas, recognition |
| contributeOwn + item read security | Private to author | My links, onboarding progress |
| submitOnly | Add and read own only | Page feedback, policy acknowledgements |
Still need help?Our team answers product questions by email, and we can walk you through it on a call.
Open in the full guideContact support