Skip to main content

Permissions

What this page is — all 60 Orbit Papers permissions, by the names the role editor shows, grouped as the role editor groups them, with what each one actually unlocks.

What it is for — so a role grants exactly what a person's job needs, picked straight off the list.

The problem it solves — "give them Papers access" spans eleven permission groups. Without a map, roles end up with too much, or with screens that only half work.

Route: Organisation Settings → Roles · Permission: the role-management permission


1. What it is​

Papers permissions fall into two scopes and three kinds.

Organisation-wideProject
Applies toThe whole organisationDocuments and types in a project the person belongs to
Typical holdersAdministrators, records managers, complianceAuthors, approvers, template owners
GroupsPapers Records, Papers SettingsDocuments, Type Designer, Repository, Obligations, Analytics, Capture Inbox, Knowledge Graph, Reports, Project Settings
KindExampleEffect
MenuShow the Documents sidebar entry.Shows the sidebar entry — nothing more
View / manageView this project's documents.Opens the screen and its data
Feature rightFeature right: download rendered/finalized artifacts and redacted exports (export/print).One capability, independent of screens

A permission is never enough on its own. Papers must be on the organisation's plan, and for project permissions the person must be a member of the project.


2. Why you would use it​

  • Least privilege without guesswork. An author gets authoring. They do not also get voiding signature requests or re-opening sealed documents.
  • Separation of duties you can show an auditor. Writing, approving, finalizing and forcing a state change are separate grants, held by different people.
  • Fewer "the button is missing" tickets. Menu and view are separate, and some actions need a second right. Knowing that removes most access confusion before it starts.

3. Step by step — building a role​

  1. Start with the menu + view pair for each area the person should see.
  2. Add the action permissions their job needs, from §4.
  3. Add organisation-wide permissions only for administrators, records and compliance staff.
  4. Assign the role, and make sure the person is a member of the projects they work in.
  5. Test as that person: the screens they need are present, and the buttons they need appear.

4. Field reference — all 60 permissions​

Papers Documents (project, 16)​

PermissionWhat it unlocks
Show the Documents sidebar entry.The sidebar entry
View this project's documents.The documents list, each document, version history and diffs
Create documents from a type.New Document
Edit draft documents / data values.Editing fields in editable states, and Submit
Delete drafts (finalized documents are immutable).No visible action at present — documents cannot currently be deleted. Revoke or rename instead
Finalize (number + seal) a document.Finalize
Act on approval steps (approve/reject/return).Approval decisions, including on unrouted documents
Manage counterparty access and redlines.Adding counterparties, portal invites, accepting and rejecting redlines
Distribute documents externally.Email Document and Create Share Link
Send signature requests/envelopes.Send for Signature, remind and reassign
Place/edit signature fields.Placing fields through the API — the screen uses the template's signature anchors instead
Void an in-flight signing ceremony.Void on a signature request
Force transitions / re-open (audited).Moving a document to any state, with a reason
Feature right: download rendered/finalized artifacts and redacted exports (export/print).Downloads and exports
Redaction-aware right: download the CLEAN sealed artifact even when the document has an active external redaction layer.The unredacted file — grant sparingly
Use AI drafting/extraction/Q&A for documents.Every AI action, and the AI advisor in the approvals inbox

Papers Type Designer (project, 6)​

PermissionWhat it unlocks
Show the Type Designer sidebar entry.The sidebar entry
View this project's document types.Reading types and their zones
Create/edit/retire project types and template versions.Building, publishing and retiring types, including zones
View this project's clause library.Reading clauses
Create/edit/approve project clauses and fallbacks.Writing clauses and fallback positions
Manage project letterheads, seals and numbering.Project branding and sequences

Papers Repository, Obligations, Analytics, Capture Inbox, Knowledge Graph (project, 9)​

PermissionWhat it unlocks
Show the Repository sidebar entry.The sidebar entry
Manage folders, tags, move/file and bulk operations.Filing and bulk actions
Show the Obligations sidebar entry.The sidebar entry
View obligation register and renewal calendar.The register and calendar feeds
Manage obligations and reminders.Adding, completing and renewing obligations; reminders
Show the Analytics sidebar entry.The sidebar entry
View cycle-time / win-rate / bottleneck analytics.The analytics dashboard
Show the Capture Inbox sidebar entry.The sidebar entry
Show the Knowledge Graph sidebar entry.The sidebar entry

Papers Reports (project, 3)​

PermissionWhat it unlocks
Show the Papers Reports sidebar entry.The sidebar entry
Open the Papers report builder, run reports, drill down and export results.Running and exporting reports
Create, update, delete and share saved Papers report definitions.Saving and sharing reports

Papers Project Settings (project, 6)​

PermissionWhat it unlocks
Show Papers Project Settings in the header settings (gear) menu.The gear-menu entry
Manage the project's branding-asset overrides (requires open branding lock).Project branding, when the organisation allows it
Manage the project's numbering-sequence overrides (requires open numbering lock).Project sequences, when allowed
Manage the project's smart-field overrides (requires open smart-fields lock).Project smart fields, when allowed
Manage the project's legal-translation glossary overrides (requires open glossary lock).Project glossary, when allowed
Manage the project's regulation-rule overrides (requires open rules lock).Project regulation rules, when allowed

Papers Records (organisation, 3)​

PermissionWhat it unlocks
Show the Records Management sidebar entry.The sidebar entry
View file plans, record series, retention status, legal holds, disposition and vital-review queues.Every Records screen, read-only
Manage record series/file plans, apply/release legal holds, execute disposition and stamp vital reviews.Every Records action

Papers Settings (organisation, 17)​

PermissionWhat it unlocks
Papers module limits, defaults, integrations and signature-provider toggles.Module settings — and also embed tokens and publishing to the public library
View the org-canonical template-type library.Reading organisation types
Manage org-canonical types/templates (projects inherit).Organisation types, inherited by projects
View the org-canonical clause library.Reading organisation clauses
Manage org-canonical clauses, fallbacks and playbooks.Organisation clauses and playbooks
Manage org letterheads, seals, watermarks and numbering sequences.Organisation branding and sequences
Manage the authorized-signatory matrix.The signatory matrix
Set retention policies and legal-hold defaults.Retention defaults
Configure triggers/webhooks/auto-generation rules.Generation triggers
Configure intake-form bridges: map a marketing form to a Papers document type with a field mapping so each submission auto-generates a document (FB-238).Intake forms
Manage which customers can access the Papers document portal for a project (enroll by email, suspend/remove, send invitations).Customer enrolment
Browse & view Papers customer-portal pages.Portal pages in Experience Manager, read-only
Edit Papers customer-portal pages.Editing portal pages
Publish Papers customer-portal pages.Publishing portal pages
Use the page builder for Papers customer-portal pages.The page builder
Data & Privacy tools for Orbit Papers: export everything held about a counterparty email (GDPR subject access, FB-185) and request erasure with a legal-hold/retention withheld report (FB-186).Subject-access export and erasure
Cross-project compliance read; unlocks "All projects" mode in the Repository.Every project's documents in the Repository

5. Things the names do not tell you​

FactConsequence
Submitting needs Edit draft documents / data values., not an approval permissionAuthors submit their own work
Deciding an unrouted approval needs Act on approval steps (approve/reject/return). — and the submitter can never decide their ownSee submitting for approval
Self-approval for one-person organisations is an organisation setting, not a permissionNo role can grant it
API keys and webhook endpoints are managed with Manage Api Keys under DevelopersPapers permissions do not cover them
Public pages — verification, share links, portal, signing, library — need no permissionThe link or code is the credential

6. Worked example​

Gatiro's five-person legal department needs four roles in its Commercial project.

RoleHoldersGrants
Contract author2 paralegalsShow the Documents sidebar entry. · View this project's documents. · Create documents from a type. · Edit draft documents / data values. · Manage counterparty access and redlines. · Distribute documents externally. · Use AI drafting/extraction/Q&A for documents. · Show the Obligations sidebar entry. · View obligation register and renewal calendar.
Contract approverGeneral counselThe author's two Documents view permissions, plus Act on approval steps (approve/reject/return). · Finalize (number + seal) a document. · Send signature requests/envelopes. · Void an in-flight signing ceremony.
Template ownerSenior counselShow the Type Designer sidebar entry. · View this project's document types. · Create/edit/retire project types and template versions. · View this project's clause library. · Create/edit/approve project clauses and fallbacks.
Records & complianceCompliance officerThe three Papers Records permissions · Cross-project compliance read; unlocks "All projects" mode in the Repository. · Set retention policies and legal-hold defaults.

Force transitions / re-open (audited). goes only to the general counsel, in a separate Emergency override role that is reviewed quarterly. Nobody receives the clean-artifact redaction right.


7. The admin contract​

What must be trueOtherwise
Papers is on the planNo permission has any effect
The person is a project memberProject permissions show nothing
The permission groups are enabled for the organisation's packageThey do not appear in the role editor
Override locks are open, for the Project Settings permissionsThe screen stays greyed out whatever the role

8. Troubleshooting​

SymptomCause
Sidebar entry present, but the screen is refusedThe menu permission was granted without the view permission
The screen works, but has no sidebar entryThe view permission was granted without the menu permission
An approver cannot decide an unrouted documentThey submitted it, or they lack the approval permission
Cannot publish to the public library or mint embed tokensThese need Papers module limits, defaults, integrations and signature-provider toggles.
A project setting is greyed out despite the permissionThe organisation lock is closed
No delete button despite the delete permissionDocuments cannot currently be deleted — revoke, or rename a draft clearly
A person with every permission sees no documentsThey are not a member of the project