# Permissions and access

Three separate things have to agree before you can do something. Each fails differently,
and telling them apart is what sends you to the right person.

<figure className="gai-fig">
	<div className="gai-fig-head">Three gates, each narrowing the last</div>
	<div className="gai-fig-body">
		<ol className="gai-fig-steps">
			<li><b>Your roles</b><span>What you may do. Fails by the control not being there. An administrator fixes it.</span></li>
			<li><b>Your plan</b><span>What the workspace bought. Fails with a message. Only a plan change fixes it.</span></li>
			<li><b>The item's access</b><span>Who this one thing was shared with. Fails per item. Its owner fixes it.</span></li>
		</ol>
	</div>
</figure>

Each gate narrows. None can widen another.

## 1. Your roles

A role is a named list of things you may do. You hold one or more, and holding two
grants everything in both. Roles only add. No role takes something away.

**When this is what stopped you:** the screen or button is not there at all. The app
does not show a disabled control; it shows a shorter menu.

**Who fixes it:** an administrator, in seconds. See [users and
roles](/guide/admin/users-and-roles).

## 2. Your plan

Whole areas of the product belong to modules, and a workspace only holds the modules its
subscription includes.

**When this is what stopped you:** an explicit message saying your plan does not include
this.

**Who fixes it:** whoever owns billing, and only by changing the plan. No role change
opens it, because the entitlement belongs to the subscription rather than to you. See
[plans and modules](/guide/admin/plans-and-modules).

<Callout type="note">
	This gate is the one most often misdiagnosed. If you have asked an administrator for
	access three times and still cannot see something, check whether the message is about
	your plan rather than your permissions.
</Callout>

## 3. Who the item was shared with

Roles decide which **screens** you get. They do not decide which **items** you see
inside them. That is controlled by the access list on the item itself, **Who can use
this**.

A `Designer` can open the design editor. Whether they can open *your* design depends on
whether you restricted it.

**When this is what stopped you:** the screen works, but a particular item is missing or
read-only.

**Who fixes it:** whoever owns the item. See [sharing and
access](/guide/admin/sharing-and-access).

## Credits are a fourth limit

Credits are not a permission, but they stop work in the same way. When the workspace pool
is empty, AI features pause for everyone regardless of roles or plan. Ordinary work
continues.

**Who fixes it:** a top-up. See [usage and credits](/guide/admin/usage-and-credits).

## Which gate stopped you

| What you see | Which gate | What helps |
|---|---|---|
| The screen or control is not there | Roles | A role change |
| A message that your plan does not include it | Plan | A plan change |
| The screen works but an item is missing or read-only | Item access | Ask its owner |
| "You're out of credits" | Credits | A top-up |

## See your own permissions

If you have access to **Administration → Users**, open your own user record and read
**Combined permissions**: your roles plus any custom grants, after the plan has been
applied. That is what you actually hold, rather than what your roles imply.

<Callout type="note">
	Building against the API rather than using the app? The same three gates apply to API
	keys, with a fourth narrowing on top, the key's own scope. See [roles and
	permissions](/roles-and-permissions) in the developer documentation.
</Callout>
