Allowed vs Denied vs Inherited Permissions in Joomla
Joomla permission screens commonly present Allowed, Denied, and Inherited. These values are not three equal states. They participate in Joomla's ACL hierarchy, and the effective result depends on the user's applicable groups and the permission rules above the current asset.
Allowed
Allowed explicitly grants the selected action to the selected group at that level, provided an applicable Denied rule does not override it. Joomla's official permission help warns that an Allowed setting lower in the hierarchy does not take effect when the same action is Denied higher up.
Denied
Denied explicitly refuses the action. Joomla treats Denied as dominant: a Denied rule found for an applicable user group in the asset hierarchy prevents the action even if another applicable rule says Allowed. Use Denied deliberately because it can affect child groups and lower-level configuration.
Inherited
Inherited means the current level does not explicitly set Allowed or Denied for that group/action. Joomla evaluates the applicable rules inherited from parent groups and higher assets. The final effective value may therefore be Allowed or Denied depending on the rest of the ACL configuration.
Use Calculated Setting to see the result
After changing a permission, select Save. Joomla permission screens refresh the Calculated Setting column to show the effective permission for that group and action. This is more useful than reading the selected dropdown value in isolation.
A practical decision rule
- Use Allowed when the role genuinely needs the action and no applicable Denied rule should block it.
- Leave a rule Inherited when the parent/higher-level policy already produces the correct result.
- Use Denied when the action must remain unavailable throughout the applicable inherited path and you understand the effect on child groups/lower assets.
When an Allowed setting still shows Denied
Inspect the group's parents and the permission hierarchy above the current component/category/item. An explicit Denied at any applicable level can explain the result. Also inspect the user's other groups: Joomla evaluates all groups that apply to the user, not just the group you were viewing when you changed the setting.
Do not confuse permissions with visibility
Allowed, Denied, and Inherited here govern ACL actions. Viewing access levels determine whether groups may see items assigned to those levels. If the problem is “the user cannot see this item,” inspect its Access level separately from action permissions.
Need More Help with Joomla?
Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.
Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.
QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.