Settings → User Access → Permissions
Read-only catalog of every permission MisterShell defines. Use it to look up what a permission string means, what action category it belongs to, and which roles currently grant it.
You cannot create, edit, or delete permissions here — they are defined in code. Use the Roles tab to assign permissions to roles, and the Users tab to assign roles to users.
Table columns
| Column | Notes |
|---|---|
| Permission | The exact permission string (e.g. app.resources.read) — the value that appears in role definitions. |
| Module | Top-level category — resources, credentials, ai, settings, workers, etc. |
| Action | Color-coded chip: read (green), write (orange), delete (red); other verbs (execute, session, …) are grey. |
| Description | One-line meaning of the permission. |
| Roles | Chips listing the roles that currently include this permission. No roles assigned means the permission exists in the catalog but no role grants it yet. |
The catalog also contains the special full-access entry (*.*.*) granted by roles created with Admin Rights — see Roles.
Common tasks
Find every role that can do X
- Search or scroll for the relevant permission.
- The Roles column lists the roles. Open the Roles tab to adjust any of them.
Audit a role’s surface area
Open the Roles tab instead — each row shows its full permission count and an Edit dialog with the per-permission checklist.
Discover what a permission unlocks before granting it
Check the Description column and skim the Module / Action columns for context. The Action chip color tells you at a glance whether granting the permission lets the holder read, modify, or destroy something.
Permissions
- Read / list:
app.permissions.read.