Granting Admin Permissions 🔑
Table of Contents:
- Global Admin Roles (Workspace-Wide)
- Granting and Revoking Global Permissions
- Group Owner Roles (Group-Specific)
- How to Grant Group Ownership
- Page Level Editors (Highly-Specific)
Global Admin Roles (Workspace-Wide) (00:44)
These roles grant permissions that impact the entire workspace. They are managed in the Admin Console and are best used for your core project and management teams.
To Grant Global Permissions (02:10):
-
Go to your Account Dropdown and select Admin Console.
-
Click Manage Roles on the left.
-
For the role you want to assign, click the three-dot button.
-
Select Manage Members and add or remove individuals as needed.
- Click Save.
Global Admin Roles Breakdown:
- Workspace Admin: The ultimate super-admin. Sees and does everything across the workspace. Reserve this for a very small, core group (HR, IT, Internal Comms).
- People Admin: Accesses the Manage People page to invite or disable users. Best for teams not using SSO/SCIM integrations.
- Post Admin: Can manage posts across all groups. Perfect for Internal Communications professionals.
- Resource Admin: Can manage pages across all groups. Great for Knowledge Management or Ops roles.
- Events Admin: Can manage events across all groups. Ideal for Workplace Experience or Events teams.
- Access Control Admin: Manages SSO and user provisioning settings. Generally reserved for IT.
- Recognition Admin: Manages badges and shoutouts. Best for People Experience or L&D teams
Granting and Revoking Global Permissions
Only Workspace Admins or Access Control Admins can assign roles.
| Action | Instructions | Timestamp |
| Grant Permission | 1. Go to your Account Dropdown and select Admin Console. 2. Click Manage Roles on the left. 3. Click the three-dot button next to the role and select Manage Members (02:10). 4. Use the search bar to find the user and add them. Click Save. | 02:10 |
| Revoke Permission | 1. Follow steps 1-3 above. 2. In the Manage Role Members modal, click the X next to the member whose role you'd like to revoke. Click Save. (Image below) | (In Manage Members modal) |
Group Owner Roles (Group-Specific) (06:02)
This is the most common permissioning model. Group Owners are granted access on a group-by-group basis and can edit all content within that specific group. Use this for subject matter experts who manage a department's hub.
How to Grant Group Ownership (07:34):
-
Navigate to the Group you want to manage. In the upper right hand corner of the group, choose the drop down arrow (located in the banner). Select Settings.
-
On the left hand side, click "Members".
-
Using the search bar at the top or by scrolling, locate the individual you'd like to make a group owner. Choose the three dots [...] to the right of that person's name, and click "Make Owner" (or revoke the privilege).
-
As a final step, be sure to review the Group Settings to configure who is allowed to create and edit content (Posts, Pages, Events) within that group. The most common setting is Workspace Admins and Group Owners.
How to Audit Group Owners: Need to see who manages what? Go to the Manage Groups tab in your Admin Console and click the export button. This will download a full list of all Group Owners across your workspace so you can easily review access.
Bucket 3: Page-Level Editors (Highly Specific)
Have a massive "All Hands" group shared by HR, IT, and Legal? You can use Page-Level Editors to give individuals editing rights to a single page without giving them the keys to the entire group.
How to Grant Page-Level Access:
- Go to the Group's Settings menu.
- Scroll to the Permissions section and find the Manage Editors area.
- Here, you can assign an editor to a specific page one-by-one.
Note: Current behavior is single-page only. It does not automatically grant access to sub-pages nestled underneath it. You must assign access page-by-page.
Best Practices
- Start with the 3-Bucket Model: Always ask yourself if the user needs access to the whole workspace, a single group, or just one page. Always default to the lowest level of access needed.
- Don't Rely on External Identity Tools for Admins: Tools like Okta are great for syncing group membership, but Haystack's admin permissions are too granular to map from external systems. Admin roles must be assigned manually in Haystack.
- Review Group Owners Carefully: Group owners can edit all content in a group. If you just want someone to be able to publish a post, adjust the group's publishing settings rather than making them a full owner.
- Train Your Group Owners: For larger teams, create a shared Slack channel or a dedicated Haystack group just for Group Owners so they can ask governance questions and share tips!
Need More Help? We’re here for you! If you have questions about permissions or need help setting up page-level editors for a complex group:
- Chat: Click the chat icon in the bottom right of the screen.
- Email: support@haystackteam.com
Keywords: Haystack, admin permissions, admin console, manage roles, group owner, workspace admin, people admin, resource admin, post admin, events admin, access control, tutorial, guide, user roles, revoking admins