How can I customize permission levels of an app in Cakewalk?

Last updated: August 17, 2026

Permission levels define the kinds of access an app grants, for example Viewer, Editor or Admin. Admins and App Owners define them per app, so requests, approvals and access reviews use your own vocabulary instead of a generic list.

Where to find them

Go to App Governance, select the app, open the App governance tab and scroll to Permissions.

The Permissions section only appears for apps with Managed status. Apps that are Discovered, Restricted or Ignored are not governed, so they have no permission levels. Set the app to Managed first.

Add a permission

  1. In the Permissions section, click the + button.

  2. Enter a Name. Required, up to 256 characters.

  3. Enter a Description. Optional, up to 1024 characters. Write what the level actually allows, because approvers read this when they decide on a request.

  4. Set the toggles you need (below).

  5. Click Save.

A permission that repeats the name and description of an existing one is rejected.

Edit or delete a permission

Open the menu on a permission card and choose Edit permission or Delete permission.

The two toggles

  • Set as default. Cakewalk assigns this level automatically to new and unassigned users. Everyone who already holds a different level keeps it.

  • Set as privileged. Marks the level as high risk. Requests for it are highlighted in approvals and access reviews, and custom policies can assign tasks based on who holds it.

Match the names used in the app itself

If the app runs on auto provisioning, the permission name in Cakewalk has to match the name in the third party app, spelling included. A mismatch makes provisioning runs fail. Check the Provisioning tab for failed runs, then correct the name here and recreate the configuration.

What you cannot change

  • Cakewalk's own permissions. They are fixed. To change what someone can do inside Cakewalk, edit the user instead.

  • The name of a permission synced from an integration. It comes from the connected app, so the field is locked. The description and both toggles stay editable. Synced permissions cannot be deleted.

  • A permission that auto provisioning depends on. Update the provisioning settings first, then delete it.

What happens when you delete a permission

  1. If users hold the level, you assign each of them a different one in the same flow.

  2. If user groups point to the level, you assign those groups a new default.

  3. Open requests and onboardings tied to the level are cancelled. Cakewalk shows you the count and asks you to confirm before anything is removed.

Renaming a level leaves every assignment in place. Only deletion forces reassignment.

Changing the level one person holds

That is a separate action. Open the app's Users tab and change the value in the Permission column. It affects that person only and leaves the app's permission list untouched. The field is read only when the app runs on auto provisioning, because the configuration sets the level.

Why this matters: permission levels are what approvals, policies and access reviews act on. Naming them the way the app names them, marking the right one as default and flagging the risky ones as privileged is what keeps least privilege enforceable instead of aspirational.