Role-Based Access Control in Leapwork Go Portal | Leapwork Docs

This article explains how role-based access control works in the Leapwork Go Portal.

This page covers the Go Portal only. It does not cover Admin Portal functions such as user invitation, role assignment.

Overview

Leapwork Go Portal permissions are applied by role and by portal area.

The current portal areas covered by RBAC are:

Permission legend:

Permission Meaning
Create Create new items or start new actions in that area
Read Open and view items in that area
Update Edit or change items in that area
Delete Remove items in that area

Current role model

In the current version of the Go Portal RBAC model, these roles are included in the portal permission matrix:

Permission matrix

Portal area Leapwork Admin Super Admin Admin User Viewer
Projects Create, Read, Update, Delete Create, Read, Update, Delete Create, Read, Update, Delete Read Read
Folders Create, Read, Update, Delete Create, Read, Update, Delete Create, Read, Update, Delete Create, Read, Update, Delete Read
Sequences Create, Read, Update, Delete Create, Read, Update, Delete Create, Read, Update, Delete Create, Read, Update, Delete Read
Timelines Create, Read, Update, Delete Create, Read, Update, Delete Create, Read, Update, Delete Create, Read, Update, Delete Read
Run results Create, Read, Update, Delete Create, Read, Update, Delete Create, Read, Update, Delete Create, Read, Update, Delete Read
Data items Create, Read, Update, Delete Create, Read, Update, Delete Create, Read, Update, Delete Create, Read, Update, Delete Read
Settings Create, Read, Update, Delete Create, Read, Update, Delete Create, Read, Update, Delete Read Read

What this means in practice

Leapwork Admin, Super Admin, and Admin

These three roles currently have the same level of access inside the Go Portal. They can create, view, edit, and delete content across all supported portal areas.

User

The User role can fully work with:

The User role has view-only access to:

Viewer

The Viewer role has view-only access across all supported portal areas. Viewers can open and inspect content, but they cannot create, edit, run, or delete content.

Portal behavior

When a role does not have access to an action, Leapwork Go Portal applies that restriction in the product experience.

Depending on the page and action, the portal may:

This means access control is enforced both in the user interface and in backend request handling.

Scope note

This article is intentionally limited to RBAC behavior inside the Leapwork Go Portal.