Skip to content
Start free trial

How to Fix Permission Denied Errors

You see Permission denied or Access denied when your role does not allow that action on that record. The record belongs to a team. Your teams’ roles must grant View / Edit / Delete / Create / Reassign at a reach that covers it.

Verizon’s 2024 DBIR found the human element in 68% of breaches (Verizon 2024 DBIR). A denied click is often the system working. The fix is to grant the right on the team, not to turn everyone into an administrator.

  1. Your role has no View (or no Edit) on this record type. Roles live under Settings → Access → Roles.
  2. The reach is too narrow. You can edit records your teams own, but this one is held by another team.
  3. You can edit but cannot move it. Change team and Make private need Reassign, which the Editor starting point does not include.
  4. The record is private. It sits on someone’s personal team. Teammates will not find it; who can see what explains who still can.
  5. You are not on the team that holds it, and your role does not reach the whole business unit or workspace.
  6. The record is archived. Archived rows have tighter edit rules.

If the record “does not exist” when you open a link, you may simply be out of scope — HARi hides rows you cannot view rather than advertising them.

  1. Note the exact message, the record type, and the action (view, edit, delete, export, reassign).
  2. Ask an administrator to open Settings → Access → Access Inspector, pick you, and read what you can actually reach.
  3. On Settings → Access → Roles, open the role attached to your team. Check the row for that record type.
  4. If you can see some rows but not others, the reach is Records their teams own and this row is on a different team. Either join that team, widen the role to the business unit, or ask someone with Reassign to Change team.
  5. If Export CSV is missing, the role needs the Export records capability as well as View. See export monitoring.
  6. After a role change, try again. If the sidebar still looks wrong, sign out and back in.

There is no Settings → Profiles screen. If an older guide pointed there, use Settings → Access → Roles.

If the Inspector says you should have access and the app still refuses, sign out and back in to refresh the permission cache. If it still fails, ask the administrator to confirm you are on the team they think you are on — teams and roles.