In Workiva, your ability to access and interact with a feature is set according to your role. Roles allow companies to scope an employee's access to only the tools necessary for their job. Once a role is assigned, access can be further restricted through the use of permissions — such as the ability to view or edit a particular file. Chains follows this same model, but includes a subset of permissions unique to Chains.
This guide will walk you through how to create user groups in Chains, assign appropriate roles, and set up the necessary permissions.
Step 1: Create the Chain Owners user group
To start, someone with the Chain Security Admin role will need to create new user groups and sort staff members into them. These groups will define the abilities that each person has in your software.
At minimum, you must create a Chain Owners group that permits users to view, run, edit, and create chains.
Here's how:
- From Workiva Home, click your profile icon at the top right.
- Select Workplace Settings from the pulldown menu.
- Select the Groups tab.
- Click Create Group on the right side.
- Name this group Chain Owners.
- Now add workspace members to this group by searching for or selecting individuals. Remember that users in this group will have the ability to view, run, edit, and create chains.
- Click Create Group to finish.
You'll set the permissions for this group in Step 4.
Note: Need more help? Click here to see our full article on setting up user groups.
Creating additional user groups
You've now set up a Chain Owner group that has complete access to chains. This is the only required group, but you may want to allow other users to access chains as well.
In this case, we recommend following the steps above to create two additional groups:
- Chain viewers: This group has view-only access to Chains.
- Chain runners: This group can view and run chains, but can't modify or create them.
Step 2: Bulk assign new user roles
Now that you've set up user groups for your staff members, you'll need to assign each person an updated role.
Here's what we recommend:
- Remove the Chain Owner role from all Chains users: This legacy role grants admin access to all Chains settings and objects. It is no longer necessary and may allow users unwanted access to your chains.
- Assign the Chain Builder role to all Chains users: The Chain Builder role grants access to the Chains platform itself, but grants no other abilities on its own.
- Assign the Chain Security Admin role to at least one person: This role allows the administrator to assign permissions to other users. At least one person must have this ability.
To update your members' roles, follow these steps:
- From Workiva Home, click your profile icon at the top right.
- Select Workplace Settings from the pulldown menu.
- Select the Members tab, and mark the checkbox next to each user whose roles you want to edit.
- Click Edit in the toolbar, and select Roles.
- In the Edit Roles dialog, mark or clear to apply or remove a role from all the selected users. A dash in a checkbox indicates that some of the selected members already have this role.
- Click Apply Changes in the toolbar to finish.
Alter individual user roles
- From Workiva Home, click your profile icon at the top right.
- Select Workplace Settings from the pulldown menu.
- Select the Members tab, double-click on the user whose roles you want to edit.
- In the Workspace Roles dropdown menu, click on each role that you want to add to the user. To remove a role, click the X next to that role in the user row.
- Click the blue checkmark icon to accept your assignments.
- Click Apply Changes in the toolbar to finish.
Note: Need more help? Click here to see our full article on changing roles.
Step 3: Set permissions for your new groups
At this point, your members should be assigned their new roles and groups. The final step is to assign unique permissions to each group; these permissions, in turn, will decide the level of access granted to each staff member.
Note: You will need to have the Chain Security Admin role assigned to you to complete this task.
Here's how to assign permissions:
- From Workiva Home, click Chains in the left nav menu.
- In the new Chains tab, click your profile icon at the top right.
- Select Chains admin from the pulldown menu, and select Workspace Settings from that.
- Select Users & Permissions in the navigation bar at the top,
- From the Permissions tab, select the Chain Owners group.
- Under Permissions on the right side, click the Creator checkbox to mark them. Your changes will save automatically.
At this point, you've finished applying permissions to the Chain Owners group. If you created other groups, such as Chain Viewers or Chain Runners, repeat this step and choose the appropriate permissions for that group.
Note: Once chains have been created, clicking Chain Permissions opens a window where you can assign or remove Read, Execute, Edit, and Admin permissions for individual chains.
Step 4: Remove permissions from the Default user group
All new Chains users are automatically placed in the Default user group. This user group is only visible in Chains and will not appear in the rest of Workiva. It cannot be deleted or removed.
Because this group includes everyone in your workspace, we recommend removing most of its permissions.
Note: Before proceeding with this step, make certain that all users are assigned to other groups with appropriate permissions. Removing permissions from the Default group removes them from all users who are assigned to only this group.
- In Chain Builder, click Settings at the top left.
- Select Users & Permissions in the navigation bar at the top,
- From the Permissions tab, select the Default user group in Chains Permissions.
- On the right side, uncheck the boxes to remove all permissions. Your changes will save automatically.
Understanding permission levels
Permission levels in Chains are leveled and correlated, meaning some permissions are automatically enabled when a higher-level permission is enabled. For instance, the Creator permission will automatically grant the Executor and Editor permission.
Please note that not all checkboxes can be selected within a workspace.
| Permission | Abilities granted |
| Viewer | Permission to view chains, but not run or edit them. (Not assignable here.) |
| Executor | Permission to view and run chains, but not edit or create them. |
| Editor | Permission to view, run, and edit chains, but not create new ones. |
| Creator | Permission to view, run, edit, and create chains. |
| Admin | Full admin access to chains in the Workspace. (Not assignable here.) |
Note: Viewer and Admin permissions cannot be assigned at the Workspace level. Viewer permission is a default permission given to all members of the workspace, and Admin permission is granted by the user's role.
FAQ
Can I assign permissions to individual chains?
Yes, but this does require Environment Security Admin rights in the chain's parent environment.