Welcome to Zuora Product Documentation

Explore our rich library of product information

Workflow role access privileges in Revenue

Access to Workflow from the Revenue user interface is controlled through Revenue UI privileges and Platform Workflow access permissions. These controls serve different purposes.

Revenue UI privileges

In Revenue role management, Extension Studio is the parent privilege, and the entries beneath it are child privileges.

The relevant privileges are:

Revenue privilegeControls
Extension StudioAccess to the Extension Studio area in the Revenue UI.
Extension Studio > WorkflowVisibility and access to Workflow from Extension Studio.

To give a Revenue user access to Workflow, assign the Extension Studio > Workflow privilege to the Revenue role used by that user.

Assign only the Extension Studio child privileges required for the user’s job responsibilities.

If a user has no Extension Studio child privilege, Extension Studio and its child entries are not displayed to that user.

Privileges are additive. Granting access to Workflow does not automatically grant access to Notifications and Events or Custom Objects.

Platform Workflow permissions

Revenue UI navigation access is separate from the permissions that control Workflow capabilities.

A Platform Administrator manages these permissions through Platform roles.

Platform Workflow permissionUser capability
Workflow View AccessView workflow definitions, versions, tasks, run history, and metrics. Users cannot run or manage workflows.
Workflow Run AccessRun workflow definitions and tasks. This permission also supports rerunning or updating task runs where the operation allows it.
Workflow Manage AccessCreate, update, delete, and manage workflow definitions and versions.
Workflow Manage Global Settings AccessManage Workflow-wide settings, such as Zuora Login, External SMTP, and other global Workflow configuration.

Use the least-privilege combination that matches the user’s responsibilities:

  • Viewer: Extension Studio > Workflow plus Workflow View Access.
  • Operator: Extension Studio > Workflow plus Workflow View Access and Workflow Run Access.
  • Workflow designer: Extension Studio > Workflow plus Workflow View Access, Workflow Run Access, and Workflow Manage Access.
  • Workflow administrator: Extension Studio > Workflow plus the permissions required for design and operation, and Workflow Manage Global Settings Access when the user must administer global settings.

A user who can see Workflow in the Revenue UI may still be unable to run or edit a workflow if the corresponding Platform Workflow permission is not assigned.

Similarly, a user with Platform Workflow permissions may not see Workflow in the Revenue UI if the Revenue UI Extension Studio > Workflow privilege is not assigned.

Assign access to a user

A Platform Administrator or Revenue role administrator should use the following process:

  1. Identify the user’s job responsibility: view, operate, design, or administer Workflow.
  2. In Revenue role management, create or update the Revenue role assigned to the user.
  3. Enable Extension Studio > Workflow. Enable other Extension Studio child privileges only when needed.
  4. In Platform role management, create or update a custom Platform role with the required Workflow access permissions.
  5. Assign the Revenue role and Platform role to the user.
  6. Ask the user to sign in again, and verify that Extension Studio > Workflow is visible.
  7. Verify the user’s effective behavior by checking that they can perform only the intended operation: view, run, manage, or manage global settings.

For information about viewing a user’s Platform role, see View your workflow access permissions.

For information about creating and assigning Workflow permissions, see Manage access permissions for Workflow.

Troubleshoot access issues

Issue

Actions

Workflow is not visible under Extension Studio

Check the following:

  • The user has the Extension Studio > Workflow Revenue privilege.
  • The user has been assigned the updated Revenue role.
  • The user has signed out and signed back in after the role change.
  • The tenant has Revenue enabled, and Workflow support is available for the tenant release.

The user can view Workflow but cannot run a workflow

Assign Workflow Run Access through the user's Platform role. View access alone is read-only.

The user can run a workflow but cannot edit it

Assign Workflow Manage Access through the user's Platform role. Run access does not grant permission to create, update, delete, or manage workflow definitions and versions.

The user cannot change Workflow settings

Assign Workflow Manage Global Settings Access only to users who administer Workflow-wide configuration. This permission is separate from Revenue UI navigation access.

A Revenue task fails after access is configured

Confirm that the user has the required Revenue role privileges for the target operation and that the Revenue record is eligible for the action. Review the Workflow task run details, input payload, output payload, and Revenue error message before rerunning the task.