Skip to content

HCM Permissions Catalog (HCM Administration) ​

This page documents the shipped HCM Permissions screen (hcm-admin-console) — a real governance catalog of every permission in HCM, layered on top of (never replacing) the platform's own real authorization engine. Not for plugin developers.

Not the same thing as HCM Roles & Permissions. That screen is where you actually grant permissions to roles — this one is a documentation/governance catalog of what permissions exist, what they depend on, and which roles use them. Think of this as the reference library; the Roles screen is where the real granting happens.

What you see ​

Search and filter a real, live catalog of permission entries — Module, Resource, Action are all sortable/filterable grid columns.

A permission's detail view ​

Four tabs:

  • Overview — the permission's own definition.
  • Dependencies — other permissions this one depends on; add or remove a dependency directly here.
  • Roles — which roles actually use this permission.
  • Audit History — a real, live change log for this specific permission entry.

Lifecycle ​

A permission entry moves through Activate, Deprecate, and Deactivate — each a real status change you can confirm persisted by reopening the record.

Import/Export ​

Bulk import and export reuse the same Data Export & Data Import screens — this entity is on their allow-list, not a separate mechanism.

Known gaps ​

  • No interactive permission-tree visualization — module/resource/ action are grid columns you can sort and filter by, not a visual tree.
  • Dependency-cycle prevention only catches direct self-reference, not a longer chain (A depends on B depends on C depends on A) — the underlying engine has no general graph-cycle check.
  • No multi-row bulk activate/deactivate — use the single-record lifecycle buttons in the detail drawer instead.
  • The grid doesn't always visually refresh right after a lifecycle action — the underlying change is always real and correct (confirmed immediately in the detail drawer itself), but the grid row may need a manual page reload to show it; a live-refresh convenience gap, not a data-correctness one.