Tines Academy › Lesson
Control spaces and access
Access in Tines 3B comes from grants: a person or group, a role, and a resource. Learn how access flows from spaces and groups, and how to choose a setup that fits how a team works.
Objective: Explain how access flows from spaces, roles, and groups, and choose an access setup that fits a team.
Decide who can do what, once
Every team that builds needs somewhere to build, and every workflow raises the same questions. Who can see it? Who can change it? Who can run it?
Answering those questions workflow by workflow doesn't scale. Tines 3B is designed so you answer them once, in the right place, and access flows from there.
By the end of this lesson, you'll be able to explain how access works in Tines 3B and choose a setup that fits how a team actually works.
Introducing: grants
Every access decision in Tines 3B comes down to one thing: a grant. A grant answers one question: can this person or group, in this role, act on this resource?
Who is this? A member (one person) or a group (a named set of members).
What can they do? A role, such as Space viewer or Space editor for a space, or Connector user for a connector.
Where can they do it? The resource the grant applies to, such as a space or a connector.
Follow how marketing's access to the review request tracker is set up, and notice how little of it is about the workflow itself.
How access flows
Space types
Open your Tines 3B tenant.
Open a space you belong to in your Tines 3B tenant.
Open the space's settings.
Look at who has access: which members and groups are added, and which role each one has.
Check whether the space is discoverable, and if so, which default role people get when they join.
For one member, work out their access: what they're granted directly, plus what their groups are granted.
If you can't open the settings, that's access control working: managing a space takes the Space manager role. Follow along with a colleague who manages a space, or use what you've learned to predict what you'd find.
After you choose, check yourself against the three parts of a grant. In the setup you picked, who gets access to the Marketing space, and with which role? If a colleague asks why they can't see the Marketing space, could you explain what to check?
What to do if something still feels fuzzy
Access comes from grants on a space, and groups keep it manageable as teams grow. When someone can't find something, check their access first. One thing to carry forward: who can see or edit a workflow is a different question from who can reach what that workflow serves, and this course comes back to it when a workflow goes live. Next, you'll apply the same thinking to connectors.