# Set default permissions?

**URL:** <https://discourse.getcockpit.com/t/set-default-permissions/1948>\
**Category:** Uncategorized\
**Created:** [May 25, 2021, 2:58pm UTC](https://discourse.getcockpit.com/t/set-default-permissions/1948 "2021-05-25T14:58:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jasonday](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@jasonday](https://discourse.getcockpit.com/u/jasonday)\
**Post date:** [May 25, 2021, 2:58pm UTC](https://discourse.getcockpit.com/t/set-default-permissions/1948/1 "2021-05-25T14:58:28Z")

</div>

Is it possible to set default permissions at the group level?

For example, if I create a new content type (collection or singleton) can the default permissions be set to a specific group.

My use case is that I want a specific group type to be able to automatically be able to view/edit any newly created content types.

---

<div class="post-metadata">

**Author:** ![ronaldaug](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/ronaldaug/32/260_2.png) [@ronaldaug](https://discourse.getcockpit.com/u/ronaldaug)\
**Post date:** [May 31, 2021, 4:52am UTC](https://discourse.getcockpit.com/t/set-default-permissions/1948/2 "2021-05-31T04:52:00Z")

</div>

Do you mean this tab?

 ![permi](https://canada1.discourse-cdn.com/flex030/uploads/getcockpit/original/1X/d911843afba8f43c41aa04f7f38fa229230b33b5.jpeg)

---

<div class="post-metadata">

**Author:** ![jasonday](https://avatars.discourse-cdn.com/v4/letter/j/67e7ee/32.png) [@jasonday](https://discourse.getcockpit.com/u/jasonday)\
**Post date:** [June 1, 2021, 1:58am UTC](https://discourse.getcockpit.com/t/set-default-permissions/1948/3 "2021-06-01T01:58:20Z")

</div>

@ronaldaug yes, I’d like to have preset/default definitions any time I create a content type (collection or singleton).

---

<div class="post-metadata">

**Author:** ![ronaldaug](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/ronaldaug/32/260_2.png) [@ronaldaug](https://discourse.getcockpit.com/u/ronaldaug)\
**Post date:** [June 21, 2021, 2:47am UTC](https://discourse.getcockpit.com/t/set-default-permissions/1948/4 "2021-06-21T02:47:02Z")

</div>

Sorry for late reply,  
There are 2 options for you  
**Option 1**  
you can manually create a specific role in config.yml as below and let a user that has `editor` role create a collection, so that the permissions will apply to it.

```auto
groups:
  editor:
    $admin: false
    cockpit:
      backend: true
      accounts: true
      finder: true
      rest: true
      info: true
    collections:
      create: false
      delete: false
      manage: true

```

**Option 2**  
I’d recommend you to use [cockpit\_GROUPS](https://github.com/serjoscha87/cockpit_GROUPS) .  
It’s quite easy to manage roles and permissions.

---

<div class="post-metadata">

**Author:** ![abernh](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/abernh/32/859_2.png) [@abernh](https://discourse.getcockpit.com/u/abernh)\
**Post date:** [July 7, 2021, 10:24am UTC](https://discourse.getcockpit.com/t/set-default-permissions/1948/5 "2021-07-07T10:24:01Z")

</div>

@jasonday

@Hackbard is currently [brain storming ideas for a similar issue with collections and group permissions](https://discourse.getcockpit.com/t/help-with-new-rules-addon-for-groups-collect-ideas-how-to-do/1995/2).

He had the brilliant idea to tap into the `collections.createcollection` and `singleton.save.after` events. (yes, the naming convention is a little off here)

You could use these events to trigger an auto-update of your `config.php`.  
You could automate the “Option 1” by @ronaldaug that way.

---

<div class="post-metadata">

**Author:** ![Hackbard](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.getcockpit.com/hackbard/32/854_2.png) [@Hackbard](https://discourse.getcockpit.com/u/Hackbard)\
**Post date:** [July 7, 2021, 11:38am UTC](https://discourse.getcockpit.com/t/set-default-permissions/1948/6 "2021-07-07T11:38:32Z")

</div>

Absolute! IMHO Best way
