Skip to content

Permissions and Access Troubleshooting

2 min read

Use this guide when an action is missing, a page is read-only, or access does not look the way you expect.


Missing actions usually mean your current workspace or project role does not include that permission.

Check:

  • You are in the correct workspace.
  • You are in the correct project.
  • Your workspace role allows workspace-level actions.
  • Your project role allows project-level actions.
  • The item is not in a read-only state.

Ask a workspace or project administrator to review your role if needed.


A page may be read-only because:

  • Your role allows viewing but not editing.
  • The item is completed, archived, deprecated, or otherwise protected.
  • You are viewing workspace-level shared configuration from a project page.
  • The role is a built-in system role.

Project access can come from:

  • Direct project role assignment.
  • Group-based project access.
  • Workspace-level access that allows visibility into workspace settings.

If direct access is removed but the user still sees a project, check group membership and group project assignments.


Confirm that:

  • The user has accepted the workspace invitation.
  • The user was not removed from the workspace.
  • Their account email matches the invited email.
  • Their workspace membership is active.

A workspace can require that people on its verified email domains sign in through the company’s identity provider. Opening it with a password session asks first — on the workspaces page it opens a confirmation, and reaching it by URL lands on a screen with the same question. Nothing leaves Hawzu until it is answered, and it comes straight back to where you were going.

On the workspaces page those workspaces are listed under Requires single sign-on, so it is clear before clicking which ones will ask. A workspace that needs signing in to is never opened automatically, even when it is your default one: signing in with a password stops at the workspaces list instead.

If it keeps asking:

  • Check the identity provider still assigns the application to that person.
  • Check their address is on a domain the workspace has verified. Guests on other domains are exempt and keep using a password.
  • AI clients connected over MCP with a password-based session must be reconnected once single sign-on is required.

If it says the provider signed in a different account, the browser has a session open there for somebody else — on a shared machine, or a colleague who never signed out. Hawzu refuses rather than swapping one person’s session for another’s. Choose Use a different account, which asks the provider to authenticate again.

See Security & Access.


Where a workspace provisions people over SCIM, deactivating somebody in the directory removes their workspace access here, along with project access, group membership, pending invitations and connected AI clients. Signing in again does not undo it — they are added back by the directory, or by hand.

See Directory Provisioning Setup.


Access tokens use workspace or project scopes and role pickers. They are not the same as a person signing in.

If automation fails, check token status, expiry, scope, and assigned roles.