What is your developer-dependent CMS actually costing you? Calculate your costs and get a full report
What is your developer-dependent CMS actually costing you? Calculate your costs and get a full report
User Management
Least-privilege role setups for agencies, regional teams, freelancers, reviewers and automation or AI accounts, built from Agility's roles, Teams, Custom Roles and item-level permissions.
These recipes show how to combine Agility's roles, Teams, Custom Roles and Item-level Permissions for common situations. Each one follows the same least-privilege rule that User Permissions recommends: start with the minimum and add only what the job needs.
For what each built-in role can do, see the Roles and Permissions Matrix.
Some recipes use Teams or Custom Roles, which need an Enterprise subscription. Where that matters, the recipe gives an alternative.
Goal: an outside agency works in one or more of your instances, and you can remove them all at once.
Without Teams, assign the same roles per person in Settings > User Access, and keep a list of who to remove.
Goal: a regional team edits its own content without changing other regions'.
The documented controls are the instance role, item-level permissions on pages and content lists, and folder security on assets. None of the documented settings is per locale. Choose a structure that maps regions onto those controls:
If regions share content lists and differ only by locale, these controls cannot keep one region out of another's locale. Use a review step instead: turn on approvals and keep Approve or Publish with a central team.
Goal: a short-term writer creates content and someone on staff reviews it.
Goal: people who need to look at content, sign it off, or read reports, without changing it.
| Need | Role | Notes |
|---|---|---|
| View content, pages and assets only | Reader | Cannot save. Good for stakeholders and for piloting AI assistants read-only. |
| Approve or decline requests | Approver | Approver also has Editor permissions, so it can change content too. |
| Approve without editing | A Custom Role (Enterprise) with Read and Approve | Test it in your instance before you roll it out. |
| Approve and publish | Approver plus Publisher, Manager, or a Custom Role with Approve and Publish | Manager also brings models and settings. |
| Reports only | Report Viewer, or a Custom Role with View Reports | See the note on Report Viewer in the matrix. |
To make reviewers part of the process, turn on approvals for the pages and content lists they review. See Approvals and Workflows.
Goal: a script, pipeline or AI agent changes content, and you can see and limit what it does.
Agility has no separate service-account type. Automation runs as an Agility user, and every permission rule on this page applies to it.
The full rollout guidance, including levels of autonomy, confirmation prompts and logging, is in Governing AI Access to Agility CMS.