Skip to main content
All guides
Governance

The right hands on the right content

As more people touch the website, the questions from legal, security, and leadership get sharper: who can change the home page, who approved this, and what exactly changed last Tuesday? Root.js answers them with clear roles, publishing controls, and a full activity log.

The sharing settings in the Root.js CMS, granting people and a whole email domain Admin, Editor, or Viewer roles, with a group whose role is limited to specific collections.

Four simple roles

  • Viewer: can see content and previews, but not change anything. Good for stakeholders and reviewers.

  • Contributor: can create and edit drafts, but not publish. Good for writers, agencies, and freelancers.

  • Editor: can edit and publish content, and manage releases.

  • Admin: can do everything, including managing people and project settings.

Roles can be given to individuals, or to everyone at a company domain — for example, every @yourcompany.com account as a Viewer. These rules are enforced by the database itself, not only by the CMS interface.

Groups and per-collection access

Admins can also organize people into groups, such as “Agency partners” or “Legal reviewers”, and give each group a role across the whole project or for selected collections only. Access stays easy to manage as teams and partners change.

Publishing locks

During a code freeze, a legal review, or a big launch, publishing can be locked on a doc, with a reason and an optional end date. The lock is visible to everyone, and lifts automatically when the date passes.

A record of every change

The activity log records who did what, and when: saves, publishes, releases, translation imports, data syncs, publishing locks, and sharing changes. Combined with version history, teams can always answer what changed, who changed it, and what it looked like before.

The Action Logs page in the Root.js CMS, an audit trail of who saved, published, scheduled, synced, and re-shared what and when, with links to each change.
The activity log, with each action, the person who took it, and when.

Sign-in and data ownership

People sign in with their Google accounts, so access follows your organization’s existing account policies. Content is stored in your own Google Cloud project, and nobody outside your organization has access unless you grant it.

Frequently asked questions

Can freelancers or agencies work without publishing access?
Yes. Give them the Contributor role: they can edit drafts, and an Editor publishes.
Can we see who published a change and when?
Yes. The activity log and each doc’s version history show who saved and published, with timestamps and publish messages.
Can we restrict who edits legal or pricing content?
Yes. Use groups to give people a role for selected collections only, and lock publishing on docs when needed.
How do people sign in?
With their Google accounts.
Next guideIntegrations and extensibility
1
2
3
4
5
6
7
8
9
10
11
12
Breakpoint: