Skip to content
User Guide

Settings → User Access → Permissions

Read-only catalog of every permission MisterShell defines. Use it to look up what a permission string means, what action category it belongs to, and which roles currently grant it.

You cannot create, edit, or delete permissions here — they are defined in code. Use the Roles tab to assign permissions to roles, and the Users tab to assign roles to users.

Table columns

ColumnNotes
PermissionThe exact permission string (e.g. app.resources.read) — the value that appears in role definitions.
ModuleTop-level category — resources, credentials, ai, settings, workers, etc.
ActionColor-coded chip: read (green), write (orange), delete (red); other verbs (execute, session, …) are grey.
DescriptionOne-line meaning of the permission.
RolesChips listing the roles that currently include this permission. No roles assigned means the permission exists in the catalog but no role grants it yet.

The catalog also contains the special full-access entry (*.*.*) granted by roles created with Admin Rights — see Roles.

Common tasks

Find every role that can do X

  1. Search or scroll for the relevant permission.
  2. The Roles column lists the roles. Open the Roles tab to adjust any of them.

Audit a role’s surface area

Open the Roles tab instead — each row shows its full permission count and an Edit dialog with the per-permission checklist.

Discover what a permission unlocks before granting it

Check the Description column and skim the Module / Action columns for context. The Action chip color tells you at a glance whether granting the permission lets the holder read, modify, or destroy something.

Permissions

  • Read / list: app.permissions.read.