Knowledge base permissions give admins control over which teams can work with which knowledge base assets. Access runs through the tags you already apply to your assets.
If you don't configure anything, your knowledge base works exactly as it does today.
How it works
Tags are the unit of access. Every asset in your knowledge base carries at least one tag, and a team's assigned tags determine which assets its members can work with.
Admins assign tags to teams from the Knowledge tab on a team's detail page.
Staff and data managers can apply only the tags assigned to their teams.
Staff and data managers still see every asset in the knowledge base list view, but they can't view or modify an asset they don't have access to. That includes refreshing and deleting.
Testers have no tag management permissions and can't reach the knowledge base at all.
Only admins can create new tags. When creating a tag, you assign it to teams in the same step.
Users on more than one team can work with the combined set of tags across all their teams.
What happens when permissions turn on
All existing tags are granted to your school-wide team. Because every user starts on that team, tagging continues to work as it does today until an admin changes something. Nothing is restricted until you restrict it.
For admins: setting up knowledge base permissions
Step 1: Review your tags
Click Knowledge in the left sidebar and look at the Tags column. For each tag, decide which team should own the assets that carry it. See Knowledge base tags for how tags work.
Step 2: Confirm who's on each team
Go to Permissions in the left sidebar and open a team. Everyone who tags assets today should be on a team that will hold the tags they use. This is the step that prevents surprises later.
Step 3: Assign tags to teams
From the team's detail page, open the Knowledge tab, assign the tags that team needs, and save. Repeat for each team.
Step 4: Narrow the school-wide team
Once each team has the tags it needs, remove tags from your school-wide team so access matches how your staff actually work.
⚠️ Do this last. Removing a tag from the school-wide team takes access away from everyone whose other teams don't carry that tag. Finish step 2 first, and check that each person who tags assets is covered by a team that holds their tags.
Step 5: Create new tags as you need them
Admins can create a tag at any time and assign it to teams during creation.
Access at a glance
Knowledge base access by role, once permissions are configured.
Role | Sees the asset list | Can open and modify assets | Can apply tags | Can create tags |
Admin | Yes | All assets | All tags | Yes |
Data manager | Yes | Assets carrying their teams' tags | Their teams' tags | No |
Staff | Yes | Assets carrying their teams' tags | Their teams' tags | No |
Tester | No | No access | No | No |


