Create a Custom Workspace Permission Set

This article shows how Pro+ administrators can select individual permission keys when predefined roles are too broad or too narrow, then verify the effective frontend actions with a test account.

What you need to know

  • An explicit deny wins over allow, and no applicable allow means denied.
  • Frontend button visibility is only guidance. QCSB rechecks authorization server-side and rejects forged Workspace/location/item references.

How to do it

  1. Edit the Workspace and add/select the Joomla group that needs nonstandard access.
  2. Set its Workspace role to Custom Permissions. Custom permissions require Pro or higher.
  3. Configure the individual permission effects in the View/find, Add/receive, Download/transfer out, Modify, and Recovery groups.
  4. Use explicit denies sparingly: an explicit deny wins over an allow inherited from another applicable rule.
  5. Save and test the exact operations with a normal account in that Joomla group, including both source and destination sides of Copy/Move where relevant.

Verify the result

  • An allowed normal account can open the intended Workspace.
  • An account outside the allowed rules cannot use the Workspace/action.
  • Connection overrides and source/destination permissions behave exactly as configured.

Important limits and mistakes to avoid

  • A successful Super User test does not prove a normal Joomla group has correct Workspace access. Test with the real role.

Troubleshooting

  • If an action is missing/denied, check Joomla menu access, Workspace allowed group, Workspace role, custom denies, connection override, and plan gate separately.

Community Discussion

For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.