The Permissions tab appears only when your organization has it enabled. To use it you need to be a People admin — either the Admin base role or a People area grant. If you don’t see the tab, it isn’t turned on for your account yet.
How access is built
A person’s access is the combination of four things. Reading them together tells you exactly what they can do.
A person’s effective access in any area is the higher of their base role and any per-area grant. Per-area access can only raise what someone can do — it never takes access away.
Base role
Everyone has one base role that applies across the whole platform.The Permissions view lists people up to Owner. Internal and service accounts above that level aren’t shown or edited here.
Per-area admin access
Instead of making someone a full Admin, you can give them admin access in one area only — for example, someone who manages all your content but nothing else. Each area is a checkbox on the person’s detail page. Ticking it grants admin access in that area; unticking removes the grant.Named roles
Named roles switch on a specific set of capabilities. Two can be assigned here:- IT admin — manage security settings, SSO, and automated user provisioning.
- Buyer — approve learning requests and manage credits, payments, and the catalog.
Individually granted features
Some people have extra features switched on just for them. These appear on the detail page as read-only chips under Individually granted features. They’re managed by Juno support and can’t be changed from this view.Permission areas
Per-area admin access covers 10 areas. This is what each one unlocks:Nine of these areas can be granted directly on a person’s detail page. Feedback is shown for context but can’t be granted here — it follows the person’s base role.
The permissions table
Each row is one person. The table supports server-side search, filter, and sort.
Above the table, a row of summary chips shows every permission configured across your whole organization with a count of how many people hold it. Select a chip to filter the table to those people.
The “Manages” column
The Manages column summarizes who a person oversees:- Direct — people who report to them directly.
- In hierarchy — everyone further down their reporting line.
- Groups — permission-granting groups they administer.
Search, filter, and export
- Search matches on name and email.
- Filters narrow by base role, area, and named role.
- Export downloads the current filtered view. Exports are capped at 10,000 rows — if you hit the cap, narrow the filters and export again.
The person detail page
Select any row to open that person’s full breakdown.- What this person can do — a checklist of every area and named role. Areas already covered by the person’s base role show as checked and disabled, labelled From their base role (an Admin already administers every area, so there’s nothing extra to grant).
- Who they manage — the people they oversee, tagged by reason: Direct report, Reporting line, or Managed via . Long lists show the first 200 people, but the counts always reflect everyone.
- Individually granted features — read-only chips, shown only when the person has them.
Changing someone’s access
You need the Admin base role to change access. There are two ways to make a change.Change the base role
Pick a new base role from the dropdown. Before anything is saved, a confirmation dialog shows exactly what will change — the base role itself, any area whose effective access changes, and any named roles added or removed. Confirm to apply.Grant an area or named role
Tick or untick an area or named role in the checklist. These changes apply immediately — there’s no confirmation step.You can’t set someone above your own level or edit someone who’s above you. If a change isn’t allowed, it isn’t applied and you’ll see a message that you may not have permission to make it.
Who can see and change permissions
- See the Permissions tab — People admins (the Admin base role or a People area grant), once your organization has the feature enabled.
- Change access — the Admin base role, within the limits above.

