- Home
- Guides
- Troubleshooting
- Permissions and Access Troubleshooting
Permissions and Access Troubleshooting
2 min read
Use this guide when an action is missing, a page is read-only, or access does not look the way you expect.
A Button or Action Is Missing
Section titled “A Button or Action Is Missing”Missing actions usually mean your current workspace or project role does not include that permission.
Check:
- You are in the correct workspace.
- You are in the correct project.
- Your workspace role allows workspace-level actions.
- Your project role allows project-level actions.
- The item is not in a read-only state.
Ask a workspace or project administrator to review your role if needed.
A Page Is Read-Only
Section titled “A Page Is Read-Only”A page may be read-only because:
- Your role allows viewing but not editing.
- The item is completed, archived, deprecated, or otherwise protected.
- You are viewing workspace-level shared configuration from a project page.
- The role is a built-in system role.
Project Access Looks Wrong
Section titled “Project Access Looks Wrong”Project access can come from:
- Direct project role assignment.
- Group-based project access.
- Workspace-level access that allows visibility into workspace settings.
If direct access is removed but the user still sees a project, check group membership and group project assignments.
User Cannot Access a Workspace
Section titled “User Cannot Access a Workspace”Confirm that:
- The user has accepted the workspace invitation.
- The user was not removed from the workspace.
- Their account email matches the invited email.
- Their workspace membership is active.
A Workspace Asks for Single Sign-On
Section titled “A Workspace Asks for Single Sign-On”A workspace can require that people on its verified email domains sign in through the company’s identity provider. Opening it with a password session asks first — on the workspaces page it opens a confirmation, and reaching it by URL lands on a screen with the same question. Nothing leaves Hawzu until it is answered, and it comes straight back to where you were going.
On the workspaces page those workspaces are listed under Requires single sign-on, so it is clear before clicking which ones will ask. A workspace that needs signing in to is never opened automatically, even when it is your default one: signing in with a password stops at the workspaces list instead.
If it keeps asking:
- Check the identity provider still assigns the application to that person.
- Check their address is on a domain the workspace has verified. Guests on other domains are exempt and keep using a password.
- AI clients connected over MCP with a password-based session must be reconnected once single sign-on is required.
If it says the provider signed in a different account, the browser has a session open there for somebody else — on a shared machine, or a colleague who never signed out. Hawzu refuses rather than swapping one person’s session for another’s. Choose Use a different account, which asks the provider to authenticate again.
See Security & Access.
A Directory Removed Someone
Section titled “A Directory Removed Someone”Where a workspace provisions people over SCIM, deactivating somebody in the directory removes their workspace access here, along with project access, group membership, pending invitations and connected AI clients. Signing in again does not undo it — they are added back by the directory, or by hand.
See Directory Provisioning Setup.
Access Tokens Have Different Rules
Section titled “Access Tokens Have Different Rules”Access tokens use workspace or project scopes and role pickers. They are not the same as a person signing in.
If automation fails, check token status, expiry, scope, and assigned roles.