Admins and Managers can define which workflow elements restricted roles are allowed to use. These access controls help enforce governance, protect sensitive data, and simplify the building experience.
With Custom Roles, restrictions apply to the built-in Builder role and to any custom role that has Enforce step restrictions enabled. Custom authoring roles without that permission are not subject to these deny lists.
Capabilities
With Workflow Access Controls, you can now restrict access to:
- Workflow step types (e.g., Sign, Conditional Logic)
- Integrations (e.g., Salesforce, Slack)
- Sign field types (e.g., Date Signed, Signature, Title)
These restrictions can be applied at both the account and project levels. Users in restricted roles can only add or edit items explicitly allowed by the current settings.
Who Can Use It
Admins can manage access settings for all projects across the account.
Managers can override account defaults at the individual project level.
Users in restricted roles (the built-in Builder role, or any custom role with Enforce step restrictions enabled) are limited to using only the allowed elements. Restricted items appear with a lock icon in the workflow builder.
Admins and Managers retain full access to all steps, integrations, and Sign fields, even when those items are restricted for other roles.
Custom roles can also be granted permission to view or manage step access controls:
- View org step access controls / Manage org step access controls — view or edit account-wide defaults
- View project step access controls / Manage project step access controls — view or edit project-level overrides
A user needs the corresponding manage permission to change settings, and Edit project to open project-level Settings. Built-in Admins retain full access without needing these permissions explicitly assigned.
Who Restrictions Apply To
| Role | Subject to step access controls? |
| Admin (system role) | No — full access regardless of deny lists |
| Manager (system role) | No — full access regardless of deny lists |
| Builder (system role) | Yes — always subject to account and project deny lists |
| Custom role with Enforce step restrictions enabled | Yes — same deny lists as Builder |
| Custom role without Enforce step restrictions | No — deny lists do not apply; access is limited only by other permissions on the role (e.g., Create workflows, Edit workflows) |
| Operator (system role) | Not applicable — cannot use the workflow builder |
Custom authoring roles are unrestricted by default. To apply step access controls to a custom role, enable Enforce step restrictions when creating or editing the role in Roles & Permissions.
How It Works
1. Set Defaults at the Account Level
From the Projects page, Admins (or users with Manage org step access controls) can open the Access Control Settings Panel to set default restrictions for all projects.
Toggle access to specific step types, integrations, or Sign field types. These defaults apply to all projects unless overridden at the project level.
2. Override or adjust Settings on a Per-Project Basis
From within a project, Admins and Managers (or users with Manage project step access controls and Edit project) can override account defaults.
Enable or disable specific steps, integrations, or sign fields for just that project.
Note: This is useful for testing or for projects with unique needs.
3. Opt a Custom Role Into Restrictions
To apply step access controls to a custom role:
- Go to Roles & Permissions.
- Create or edit a custom role.
- Under Projects and workflows, enable Enforce step restrictions.
- Save the role and assign it to users.
Users with that role are subject to the same account and project deny lists as the built-in Builder role.
Example: A "Workflow Editor" role with Edit workflows but without Enforce step restrictions can use all step types permitted by its other permissions, regardless of deny lists.
A "Governed Builder" role with Edit workflows and Enforce step restrictions enabled follows the same restrictions as the built-in Builder.
4. Restricted Role Experience
When Builders try to use a restricted item:
- It will appear in the UI with a lock icon or greyed out.
- They cannot add or edit the restricted item unless it was already added by an Admin, Manager, or other unrestricted user before the restriction was applied.
Note: Newly released Intellistack workflow steps, integrations, and Sign field types are available by default and must be disabled by an Admin or Manager (or a user with the appropriate manage permission) if not desired.
Limitations
- These controls do not currently apply to form fields in the Form Builder.
- Workflow steps added before a restriction is applied remain in place but cannot be edited by users in restricted roles.
- Restrictions use a shared deny list at the account and project level. You cannot define different allowed step types per custom role in a single project — all restricted roles share the same lists.
- Groups control project membership and visibility; they do not control which step types a role can use. Step access is controlled by these settings and the Enforce step restrictions permission on custom roles.
Comments
0 comments
Article is closed for comments.