Domain permissions
Use restricted write access when editors should own specific parts of the ontology instead of changing everything.
- Under Organization → Users, place editors into permission groups.
- In the project settings, change Write access from Open to Restricted.
- Grant each group write access to a domain. The grant includes its subdomains unless you add a None carve-out.
- Verify that an affected editor can change an allowed domain and sees disabled controls elsewhere.
Everyone keeps read access to the ontology. Admins always retain write access.
Permissions apply to writes attributed to a Cassis member, including Explorer and Assistant edits and CLI uploads authenticated as that member.
Domain grants do not gate GitHub merges or GitHub App imports. Enforce repository ownership with CODEOWNERS, required reviewers, and branch protection. If your own pipeline runs cassis ontology upload, the API key owner’s Cassis permissions apply.
For organization-wide capabilities, see Members and roles.