Reference

How access works

Understand who gets access, which item it covers, and which actions it allows.

Five parts of access

PartExamples
WhoPerson, local group, external group, or service
ItemProduct area, type of item, or named item
ActionView, Search, Run, Create, Update, Work, Publish, or Delete
ResultAllow or Deny
TimeStart date and end date
The Pūnaha Permissions page
The Permissions page brings these parts together in one access record. Earlier development interface, captured 22 August 2026. Follow the current text for RC1. Open the full image.

How Pūnaha decides

Pūnaha combines access from roles, direct assignments, and groups. A matching Deny wins over an Allow.

The API checks the exact item and action for every request.

Administration is separate

Permission to manage access does not give permission to use the item. Permission to manage people is also separate.

Check one question

Use Check access for one person, item, and action. Use Effective access when you need to see all sources together.

Pūnaha Docs

Search the guides

Enter at least two characters.

    Product screen

    View the full screenshot