> ## Documentation Index
> Fetch the complete documentation index at: https://learn.biq.li/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure advanced workspace permissions

> Grant scoped access to Biqli resource categories and actions.

Advanced permissions let a custom role control access by resource category. Categories include members, links, Biolinks, QR codes, folders, custom domains, tracking pixels, and tags.

Read access allows the member to view the relevant resource data. Write access allows supported creation and modification actions and normally includes the read access needed to perform them. Sensitive administrative actions can require separate workspace authority.

Test a new role with a noncritical member before assigning it broadly.

## Resource categories

Advanced roles can control members, links, Biolinks, QR codes, folders, custom
domains, tracking pixels, and tags. Read allows supported viewing. Write allows
the supported creation and modification actions for that category and includes
the reading needed for them.

## Related-resource access

A person editing a link can also need access to a selected folder, tag, pixel,
or custom domain. If a workflow fails while the primary resource is writable,
check the permissions for every referenced resource.

## Apply least privilege

Give analysts read access without unnecessary write access. Give content teams
write access only to the resources they maintain. Keep member administration,
billing, ownership, security, and developer credentials limited to appropriate
administrators.

Test create, view, edit, attach, detach, and delete behavior before considering
a custom role complete.

## Frequently asked questions

### Does Write include Read?

Yes for the resource model described by Biqli. The person still needs access to
related resource categories used by the operation.

### Why can someone edit a link but not choose a tag?

The role can have Links Write without Tags Read. Add only the related read
permission required for that workflow.
