Overview
Use PermissionMatrix when administrators must compare and edit the same capabilities across multiple governed resources.
Workspace role
| Resource | Read | Edit | Delete |
|---|---|---|---|
| ProjectsPortfolio records | Inherited | ||
| BillingInvoices and plans | — |
Anatomy
A semantic matrix relates resource rows to capability columns and distinguishes direct, inherited, and unavailable cells.
- 1Resource header
Names the row dimension.
- 2Capability headers
Names permission columns.
- 3Resource identity
Labels each governed object.
- 4Grant cell
Shows and changes access.
- 5Unavailable cell
Explains an invalid pairing.
When to use
PermissionMatrix is best when role and policy decisions need direct side-by-side comparison.
Recommended
- Configure roles
Compare capabilities across resources.
- Review inherited access
Keep policy grants visible.
- Identify exceptions
Reveal direct and unavailable combinations.
When not to use
Avoid this component for single booleans or conversational history.
Avoid
- Do not use for one-off permission
Use Checkbox for isolated toggles.
- Do not hide policy origin
Keep inherited state visible.
- Do not replace event history
Use AuditLog for evidence timelines.
Variants
Outlined
Default bordered grid.
Filled
Tonal policy surface.
Raised
Independent floating block.
Density
Three row heights.
States
Track direct grants, inherited access, unavailable pairs, and read-only mode states.
| State | Trigger | Visual response | Interaction |
|---|---|---|---|
| Granted | Direct grant | Checked | Can revoke |
| Not granted | No grant | Unchecked | Can grant |
| Inherited | Parent policy | Checked and labeled | Cannot edit here |
| Unavailable | Invalid pairing | Dash | No control |
| Read-only | Review mode | Resolved grants | No changes |
Behavior
Direct grants
Controlled value stores editable grants.
Inheritance
Resource metadata resolves policy.
Bulk rows
Toggle all editable permissions in one resource.
Bulk columns
Toggle one permission across resources.
Accessibility
| Key | Action |
|---|---|
| Tab | Moves through editable grants and bulk controls. |
| Space | Toggles the focused checkbox. |
| Enter | Activates bulk operations. |
- Use table, caption, row headers, and column headers.
- Name every checkbox by capability and resource.
- State inherited status in text.
- Represent unavailable pairs without hidden controls.
Content guidelines
Use concise governance language that maps to policy and product structure.
Use capability verbs
Name the allowed operation.
Read, Edit, Delete
Use resource nouns
Use product objects consistently.
Projects, Billing
Name policy origin
Explain inherited grants.
Inherited from Workspace admin
Examples
Use inherited grants to show which permissions are inherited versus directly assigned.
Read-only inherited grant
Props / API
PermissionMatrix extends div attributes.
Props