Permissions

Pestle uses Role-Based Access Control (RBAC) to manage what users can see and do within the system.

Permission Model

Permissions in Pestle are structured around:

  • Folders - Containers for organizing data (projects, departments, etc.)
  • Roles - Sets of permissions (Reader, Editor, Owner, etc.)
  • Role Assignments - Linking users/groups to folders with specific roles

Built-in Roles

Role Permissions
Reader View all data within the folder
Contributor Reader + Create and edit own items
Editor Contributor + Edit any item in the folder
Owner Editor + Manage folder settings and permissions
Administrator Full system access across all folders

Folder Structure

Organize your data hierarchically:

Organization (Root)
├── IT Security
│   ├── SOC 2 Assessment
│   └── Vulnerability Management
├── Privacy
│   ├── GDPR Compliance
│   └── CCPA Compliance
└── Operations
    └── Business Continuity

Permissions cascade down the folder hierarchy. Access to a parent folder grants access to child folders.

Assigning Permissions

To Individual Users

  1. Navigate to the folder
  2. Click Settings → Permissions
  3. Click Add User
  4. Select the user and role
  5. Save changes

To User Groups

  1. Navigate to the folder
  2. Click Settings → Permissions
  3. Click Add Group
  4. Select the group and role
  5. All group members receive the assigned role

Object-Level Permissions

Beyond folders, permissions can be set on specific objects:

Task Assignments

Users assigned to tasks can view and update those specific tasks even without broader folder access.

Assessment Participation

Users can be invited to specific assessments with limited scope.

Permission Inheritance

  • Child folders inherit parent permissions by default
  • Explicit permissions on child folders override inheritance
  • Users get the highest permission level from all their assignments

Viewing Effective Permissions

To see what a user can actually access:

  1. Go to Settings → Users
  2. Click on the user
  3. View the Effective Permissions tab
  4. Shows all folders and their access level

Best Practices

  1. Use groups over individuals - Easier to manage at scale
  2. Follow least privilege - Grant minimum necessary access
  3. Review regularly - Audit permissions quarterly
  4. Document decisions - Record why permissions were granted
  5. Use folder hierarchy - Organize by team or project for cleaner permissions

Troubleshooting Access Issues

If a user can't access something they should:

  1. Check their effective permissions
  2. Verify group memberships
  3. Check for explicit denies at lower folder levels
  4. Ensure the object exists in an accessible folder
© 2026 Pestle. All rights reserved.

Contact: sales@pestle.in | +91 897 702 5287

Trendz Pride 5th Floor, Plot No 20/127, Survey No.79, Road No 1, Patrika Nagar, Madhapur, Hyderabad, Telangana, India, 500081