Write access: let your team edit without letting them delete

Not everyone who needs to edit a contract should be able to delete it. That is exactly what the write access level is for: a step between read-only and full access, letting users edit contracts, contacts, tasks and documents without being able to remove anything permanently.


Write access covers everything full access allows, with one exception: deleting. The level is available both in the standard permission system and in the Advanced Permission Concept (APC), and it sits alongside the existing levels without changing any of your current roles.


What's in it for you


  • Editing without deletion risk. Your team works with contracts, tasks and contacts day to day — accidental or unauthorised deletion is off the table.
  • Less full access handed out by default. You no longer need to grant full access just so someone can maintain a few fields. That lowers risk and satisfies compliance requirements.
  • Clear accountability. Deleting stays deliberately with the roles that hold full access — and stays traceable in the change log.
  • A clean interface instead of error messages. Users with write access never see delete actions in the first place, so there is nothing that looks “forbidden” and nothing to raise a support ticket about.


How it works


1. Open the roles area


Go to Settings → Organisation → Roles.





Click “Add new role”, or open an existing role for editing — either way, the new level appears automatically as an additional option.






2. Choose the access level


Under access level you now have three options:


  • Full (read, write and delete) — unrestricted access, deletion included.
  • Write (read and edit, without delete) — the new level: editing yes, deleting no.
  • Read access — view, but change nothing.





In the Advanced Permission Concept (APC) you set the access level per rule — there, the contract category is one of the rule's conditions. In the standard system you set the level directly per contract category, and a no access option is available as well.


3. Save the role and assign it


Save the role, then assign it to the users you want under Settings → Organisation → Members. For how roles are built and managed in general, see How can I create new roles?


4. Done — deletion is hidden for these users


Users with write access can edit everything in the area shared with them. All delete actions are hidden from them — both individually and when selecting several entries at once.


Common questions


What exactly can users with write access do?
Everything full access allows, except deleting. They edit contracts, contacts, tasks and documents, maintain fields, add documents and update tasks. They cannot delete anything.


How do users know they are not allowed to delete?
Delete actions are hidden entirely. There is no error message — the option simply isn't there. The same applies to deleting several entries via multi-select in the contract list.


What do users with write access see in the recycle bin?
The recycle bin stays visible to them, but they can neither restore content nor delete it permanently. Both remain reserved for roles with full access and for organisation owners.


Does anything change about our existing roles?
No. Existing roles and permissions stay exactly as they are until an owner actively changes something. The new level simply shows up as an additional option whenever you create or edit a role.


Does this work in the Advanced Permission Concept (APC) too?
Yes. The level is available in the standard permission system and in APC — in APC you pick it per rule.


Can I grant write access differently per contract category?
Yes. In the standard system you set the level per category; in APC you do it through each rule's conditions — for example write access on supplier contracts and read access on employment contracts.


Who can still delete?
Users with full access in the relevant area, plus organisation owners.


Do we need to buy or enable anything for this?
No. Write access is a standard part of the permission system and is available to every customer automatically — new and existing — with no add-on and no activation.


Good to know


  • Where it sits: the level falls between read access and full access, where full access means reading, writing and deleting.
  • A core feature: write access belongs to the standard scope of the permission system and is rolled out to all customers automatically — no add-on, no activation needed.
  • Retrofit it any time: owners can assign the level to new and existing roles alike, so there is no need to rebuild your role structure for it.
  • Double protection: even when a user with full access deletes something, it lands in the recycle bin first and can be restored from there.
  • A tip for compliance: grant full access only where deleting is genuinely part of the job — for everyone else, write access is the safe choice. “Who can delete?” is a standard audit question, and with this level the answer is short.



Updated on: 09/04/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!