Security

Rockumentation uses the same security inheritance pattern found throughout Rock. Security flows from the top-level container to the items beneath it unless you break inheritance and apply more specific rules.

  • Book: The top-level security boundary for the documentation set.
  • Version: Inherits from the book unless you change its security.
  • Root article: Inherits from the version.
  • Child articles: Inherit from their parent article.

This lets you secure a whole book, a single version, an individual article, or an entire article tree. You can also lock a version after publication so finalized content stays read-only for editors.

Common Permission Tasks

  • Create a book: Requires Administrate access to the DocumentationBook entity type.
  • Create a version: Requires Administrate access to the book that will contain the version.
  • Edit article content: Requires Edit access to the article.
  • Change article settings or security: Requires Administrate access to the article.
  • Publish or lock a version: Requires Administrate access to that version.

Default Security

When you install the plugin, Rockumentation creates two default security roles for you.

The first is RSR - Documentation Administrator. This role can create, edit, publish, lock, and administrate documentation. In most cases, people in this role can manage books, versions, and articles without restriction.

The second is RSR - Documentation Editor. This role is more limited. In most cases, people in this role can edit existing article content, but they cannot create new books, versions, or articles.

AI Assistance and Permissions

If you use AI assistance while working with Rockumentation, it follows the same permissions that apply to you. It cannot reveal articles you cannot view, create content where you do not have the needed rights, or bypass the normal security inheritance between books, versions, and articles.

This is especially important when working with versioned books. Unpublished versions are useful for drafting and review, while locked versions protect finalized content from further edits, whether those edits come from a person directly or from an AI-assisted workflow.

Important

Treat AI as an assistant, not as a security shortcut. If you would not normally be allowed to view, edit, publish, or lock a piece of content, AI assistance will not change that.

Security Model

The sections below describe how security applies to each type of Rockumentation item so you can design roles and permissions with fewer surprises.

In all cases, view access follows the normal View security permissions.

Books

To create new books, you must have Administrate access to the DocumentationBook entity type (this can be set under Security, Entity Administration).

In order to delete existing books, you will need Administrate access to the book you are attempting to delete.

If you want to edit an existing book, you also need Administrate access to the book in question.

Important

This is a deviation from the normal need of Edit access. This is done because editing a book is considered an administrative change, and also to allow for easier security inheritance

Versions

To add a new version of a book, you must have Administrate access to the book that will contain the version.

Deleting an existing version of a book requires Administrate access to the specific version you are deleting.

In order to edit an existing version, you also need Administrate access to the version in question.

Important

This is a deviation from the normal need of Edit access. This is done because editing a version is considered an administrative change, and also to allow for easier security inheritance.

Articles

Creating a new article requires Administrate permission on the parent article that will be the parent of the new article.

If you attempt to delete an article, you will need to have Administrate permission on the article to be deleted.

In order to edit the contents of an article, the user must have Edit access. In addition, to edit other aspects of the article (such as title), the user must have Administrate access to the article.