Privilege Matrix

Every gated action in Leed names a privilege. Before the action runs, Leed compares the privilege’s minimum role against your base role, and — if that fails — against any access override you hold on the resource in play. This page is the complete list of those privileges, plus the role-by-role summary most people actually come here for. If you have not met the six roles themselves yet, start with Roles and Permissions; this page assumes them.

Privileges are plan-independent. Nothing on this page changes when you change tier.

How to read this table

Roles are cumulative, so minimum role means that role and every stronger one. A privilege whose minimum is Content Writer is satisfied by Content Writer, Content Approver, Content Publisher and Administrator alike.

An override on a page type, a label or a page satisfies these same checks — see Resource-Level Access Overrides for the stronger-of rule, which is the only place the two systems meet.

And when a check fails, the 403 body names the privilege verbatim:

Unauthorized: missing page:publish

So the fastest route through this page is to search it for the string in the error you are holding.

All 58 privileges

Groups are the product’s own; the order below is the order they are declared in.

GroupPrivilegeMinimum roleWhat it gatesEnforced?
Pagepage:readRead OnlyViewing a page and its content✓
Pagepage:writeContent WriterEditing a page’s content and metadata, including moving it into the APPROVED state✓
Pagepage:approveContent ApproverNothing — declared for page approval and never checked†
Pagepage:createContent PublisherCreating a page, including creating one from Markdown✓
Pagepage:publishContent PublisherPublishing, scheduling, revising, reverting and deleting a page✓
Labellabel:readRead OnlyViewing labels and their members✓
Labellabel:writeContent PublisherCreating and editing labels✓
Labellabel:publishContent PublisherNothing — labels reach the site through the deployment flow†
Page Typespagetype:readRead OnlyViewing page types✓
Page Typespagetype:writeContent WriterEditing a page type and its configuration✓
Page Typespagetype:publishContent PublisherNothing — page types reach the site through the deployment flow†
Billingbilling:writeAdministratorThe Billing and plan settings screen and every billing action✓
Settingssettings:readRead OnlyNothing — each settings area is gated by its own privilege instead†
Settingssettings:writeAdministratorNothing — each settings area is gated by its own privilege instead†
Useruser:readRead OnlyReading one member and their overrides; also gates the Team members card in Settings✓
Useruser:writeContent PublisherEditing another member’s profile, role and site profile fields; writing access overrides✓
Useruser:createAdministratorInviting a member, and creating one directly through the API✓
Useruser:deleteAdministratorRemoving a member from the workspace✓
Useruser:publishContent PublisherNothing — the member list is published through the deployment flow†
RBACrbac:readRead OnlyReading the “what can I do here” capabilities payload✓
RBACrbac:writeContent PublisherThe role dropdown and the Billing/Developer checkboxes on Team Members, and the override editors on Labels and Page Types — in the interface only‡
Assetasset:readRead OnlyViewing the asset library and individual assets✓
Assetasset:updateContent WriterChanging an existing asset’s metadata or file✓
Assetasset:createContent WriterUploading a new asset✓
Assetasset:deleteContent PublisherDeleting an asset✓
Companycompany:readRead OnlyViewing the company profile and General settings✓
Companycompany:writeContent PublisherEditing the company profile and site-wide settings✓
Companycompany:publishContent PublisherNothing — company settings reach the site through the deployment flow†
Journeyjourney:readRead OnlyViewing journey stages✓
Journeyjourney:writeContent PublisherCreating and editing journey stages✓
Journeyjourney:publishContent PublisherNothing†
Developerdeveloper:writeContent PublisherEvery developer surface — the developer settings entry point and eleven backend routes behind it✓
Contactcontact:readRead OnlyReading contacts, leads and email records✓
Contactcontact:writeContent PublisherCreating and editing contacts, lead batches and emails✓
Contactcontact:publishContent PublisherSending contact-facing work live, including campaign deliverable approval✓
Contactcontact:deleteContent PublisherDeleting contacts✓
AIai:writeContent WriterAI authoring actions that write content✓
Analyticsanalytics:readRead OnlyThe Know dashboard and the analytics endpoints behind it✓
Menumenu:readRead OnlyViewing menus, including the documentation left navigation✓
Menumenu:writeContent WriterEditing a menu draft✓
Menumenu:publishContent PublisherPublishing a menu✓
Notificationsnotifications:readRead OnlyNothing — notifications are not permission-gated†
Pathpath:readRead OnlyViewing URL paths and redirects✓
Pathpath:writeContent WriterCreating and editing a path or redirect✓
Pathpath:deleteContent WriterDeleting a path or redirect✓
Formform:readRead OnlyViewing forms and their submissions✓
Formform:writeContent WriterCreating and editing a form✓
Formform:publishContent PublisherNothing — forms reach the site through the deployment flow†
Autolinksautolinks:readRead OnlyViewing auto-linking rules✓
Autolinksautolinks:writeContent WriterCreating and editing auto-linking rules✓
Dynamic CTAsdynamiccta:readRead OnlyViewing dynamic CTAs and recommendation settings✓
Dynamic CTAsdynamiccta:writeContent WriterCreating and editing a dynamic CTA✓
Dynamic CTAsdynamiccta:publishContent PublisherPublishing a dynamic CTA✓
Deploymentsdeployment:readRead OnlyViewing the Deploy screen and deployment history✓
Deploymentsdeployment:publishContent PublisherStarting a publish✓
Deploymentsdeployment:promoteContent PublisherPromoting a preview deployment to live✓
Shortcodeshortcode:readRead OnlyViewing short URLs✓
Shortcodeshortcode:publishContent PublisherCreating a short URL✓

✓ enforced — this privilege is checked somewhere in the product. † defined but never checked; see the next section. ‡ checked in the interface only; the server gates the same actions on user:write.

Privileges that exist but are never checked

Ten of the fifty-eight are declared with a minimum role and then never consulted. They are not secretly enforcing anything, and a member who “lacks” one of them will never see a 403 naming it.

PrivilegeMinimum role it claimsWhat actually gates the action
page:approveContent Approverpage:write (Content Writer) — the APPROVED state is set through the ordinary page update
label:publishContent PublisherThe deployment flow: deployment:publish (Content Publisher)
pagetype:publishContent PublisherThe deployment flow: deployment:publish (Content Publisher)
settings:readRead OnlyEach settings card carries its own read privilege — company:read, user:read, label:read, and so on
settings:writeAdministratorEach settings area carries its own write privilege — company:write, user:write, and so on
user:publishContent PublisherThe deployment flow: deployment:publish (Content Publisher)
company:publishContent PublisherThe deployment flow: deployment:publish (Content Publisher)
journey:publishContent PublisherNothing separate — journey stages are saved under journey:write
notifications:readRead OnlyNothing — notification reads are not permission-gated
form:publishContent PublisherThe deployment flow: deployment:publish (Content Publisher)

There is an eleventh case, of a different kind. rbac:write is a front-end gate only. It disables five controls across three screens: the role dropdown and the Billing and Developer checkboxes on Settings → Team Members, and the access-override editors on Settings → Labels and Settings → Page Types. The server does not check it at all: changing a role or writing an override is gated on user:write, and creating a page-type or label override is additionally entitlement-gated on contentRbac — removing one is not. rbac:write and user:write share a minimum role of Content Publisher, so a reader gets the same answer either way, but an integrator reading the API will never find rbac:write in a response, an error or a route. It is also the first thing to check when the Content Manager, Approver and Contributor pickers described in Resource-Level Access Overrides are visible but inert: that is this gate, not an expired plan.

What each role can do

The table below is built from routes that are actually enforced. Read a row as: this role can do this if its column says so.

Capability (route-verified)Minimum roleAdministratorContent PublisherContent ApproverContent WriterRead OnlyRestricted
View pagesRead Only✓✓✓✓✓override only
Edit page content and metadataContent Writer✓✓✓✓—override only
Create a pageContent Publisher✓✓————
Publish, schedule, revise, revert or delete a pageContent Publisher✓✓———override only
View page typesRead Only✓✓✓✓✓override only
Edit a page typeContent Writer✓✓✓✓—override only
View labelsRead Only✓✓✓✓✓override only
Create and edit labelsContent Publisher✓✓———override only
View team members ※ungated✓✓✓✓✓✓
Read one member and their overridesRead Only✓✓✓✓✓—
Edit another member’s profile or roleContent Publisher✓✓————
Edit your own profileyourself✓✓✓✓✓✓
Create a member (API only)Administrator✓—————
Remove a memberAdministrator✓—————
Create or delete an access overrideContent Publisher✓✓————
Read access overridesRead Only✓✓✓✓✓override only
Billing settingsAdministrator✓————billing override
Developer settingsContent Publisher✓✓———developer override
View assetsRead Only✓✓✓✓✓—
Upload and update assetsContent Writer✓✓✓✓——
Delete an assetContent Publisher✓✓————
View deploymentsRead Only✓✓✓✓✓—
Publish and promoteContent Publisher✓✓————
Edit menus, forms, paths, autolinks and dynamic CTAsContent Writer✓✓✓✓——
Read contacts and emailsRead Only✓✓✓✓✓—
Write, approve or delete contacts and emailsContent Publisher✓✓————
Edit the company profileContent Publisher✓✓————
AI authoringContent Writer✓✓✓✓——
AnalyticsRead Only✓✓✓✓✓—
View short URLsRead Only✓✓✓✓✓—
Create a short URLContent Publisher✓✓————

※ The endpoint that lists members carries no permission check at all, so any signed-in member of the workspace can retrieve the list. The Team members card in Settings is gated on user:read, so a Restricted member has no way to reach the screen through navigation — but the data is not protected by a role.

“override only” means the base role does not satisfy the check, and an access override on the resource in play can. On the two settings rows it names the specific override: the Billing checkbox for billing, the Developer checkbox for developer. Billing and Developer Access covers those two, which are the only privileges you can grant with a checkbox.

Content Approver has no column entry that Content Writer lacks. That is not an omission in the table — it is the state of the product, and Roles and Permissions explains what the role is genuinely for.

Where the checks happen

A privilege is checked in two places, and they are not the same check.

On the server, a route declares rbacValidator("<privilege>") and the request is refused with a 403 if it fails. That is the enforcement, and nothing gets past it. In the interface, a control asks checkAuth({ privilege, resourceFilters }) and disables or hides itself. That is a courtesy, and it can be wrong in both directions.

It can be wrong by showing you a control you cannot use: the Delete item in a team member’s ⋮ menu is drawn for every viewer and fails server-side for anyone who is not an Administrator. And it can be wrong the other way, by hiding a screen from someone whose data is not actually protected — the member list is readable by any signed-in member even though the card that links to it is gated. Whether a screen appears at all is a separate question from whether its data is protected, and it is answered in Who Can See What.

An AI client can ask for a machine-readable version of exactly this table, resolved for the signed-in user — role, every privilege with its minimum role and whether it is granted, and the overrides that apply. See MCP Tools: Analytics and Introspection for how to call it. Note what it cannot do: those tools read permissions and never grant them.

ESC