# Problems with Staff Priviledges

**URL:** <https://forum.ghost.org/t/problems-with-staff-priviledges/39001>\
**Category:** Bugs\
**Created:** [June 7, 2023, 7:03am UTC](https://forum.ghost.org/t/problems-with-staff-priviledges/39001 "2023-06-07T07:03:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![GhostDog](https://avatars.discourse-cdn.com/v4/letter/g/85f322/32.png) [@GhostDog](https://forum.ghost.org/u/GhostDog)\
**Post date:** [June 7, 2023, 7:03am UTC](https://forum.ghost.org/t/problems-with-staff-priviledges/39001/1 "2023-06-07T07:03:37Z")

</div>

I’m hoping a ghost dev can address this:

> <https://github.com/TryGhost/Ghost/issues/16876>
>
> \### Issue Summary
> 
> "Invite a new staff user" -\> only lists priviledges related… to posts, and there exist no page permissions in Ghost as far as I can see. Is this not essential for headless CMS functionality? If only the administrator can create pages, then each contributor, author, and editor needs to expressly ask the administrator to create the page they want to contribute before they can do anything.
> 
> It seems like relatively easy functionality for Ghost to add in the \`Invite a new staff user\` flow: to perhaps select if the permission applies to only posts (default) or pages as well (the point of this issue report).
> 
> \### Steps to Reproduce
> 
> Invite anyone under a non-administrator permission. They add page. Then they experience the error: "Permission error, cannot save page. You do not have permission to add posts"
> 
> The second half of the error is incorrect because they are trying to add a page, not a post. The first half also kind of doesn't make sense because why can get create a page and then not be able to save it?
> 
> \### Ghost Version
> 
> 4.49 Docker Image
> 
> \### Node.js Version
> 
> N/A
> 
> \### How did you install Ghost?
> 
> Linux / Docker
> 
> \### Database type
> 
> SQLite3
> 
> \### Browser & OS version
> 
> \_No response\_
> 
> \### Relevant log / error output
> 
> \`\`\`shell
> "Permission error, cannot save page. You do not have permission to add posts"
> \`\`\`
> 
> 
> \### Code of Conduct
> 
> \- \[X\] I agree to be friendly and polite to people in this repository

1. is Ghost never planning to support anyone besides admin creating pages?
2. why doesn’t Ghost allow staff to see published pages that they can otherwise see on the internet - so they can compy its settings when they go to make their own similar pages?

It seems like the entire user system in Ghost is designed to work differently than I expected: needing a lot more help from the admin, and back-and-forth between the admin and the contributors, authors, and editors.

Another issue with #2 is you need to add a contributor’s or author’s name to a page in order for them to see it - even if they just need it as a reference for their own page. However, that causes another problem; they’re able to edit this page and it isn’t like the admin gets notifications about edited and unpublished pages.

---

<div class="post-metadata">

**Author:** ![markstos](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/markstos/32/18182_2.png) [@markstos](https://forum.ghost.org/u/markstos)\
**Post date:** [June 14, 2023, 6:52pm UTC](https://forum.ghost.org/t/problems-with-staff-priviledges/39001/2 "2023-06-14T18:52:26Z")

</div>

This appears to be not a bug but a feature request.

Ghost is documented that Contributors and Authors can only edit “posts”.

> **[Users & Permissions – Manage your team](https://ghost.org/docs/staff/)**
>
> Ghost has built-in staff user permissions to allow teams to collaborate effectively. Learn all about user permissions in Ghost.

---

<div class="post-metadata">

**Author:** ![GhostDog](https://avatars.discourse-cdn.com/v4/letter/g/85f322/32.png) [@GhostDog](https://forum.ghost.org/u/GhostDog)\
**Post date:** [June 15, 2023, 5:39am UTC](https://forum.ghost.org/t/problems-with-staff-priviledges/39001/3 "2023-06-15T05:39:17Z")

</div>

Why do you think it is acceptable to show a button that opens a page that is impossible to use - because all types of staff do not have access? There are so many reasons a headless CMS should be able to have users that can create pages. If “only admins can create pages” were the intention, then why would the implementation show the create page button to staff?

---

<div class="post-metadata">

**Author:** ![markstos](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/markstos/32/18182_2.png) [@markstos](https://forum.ghost.org/u/markstos)\
**Post date:** [June 15, 2023, 1:56pm UTC](https://forum.ghost.org/t/problems-with-staff-priviledges/39001/4 "2023-06-15T13:56:55Z")

</div>

As I mentioned in the related Github issues: I agree with you. Either the “Add Page” UX shouldn’t be there if you can’t create pages, or those who can create posts should be able to create pages, too.

---

<div class="post-metadata">

**Author:** ![GhostDog](https://avatars.discourse-cdn.com/v4/letter/g/85f322/32.png) [@GhostDog](https://forum.ghost.org/u/GhostDog)\
**Post date:** [June 28, 2023, 8:34am UTC](https://forum.ghost.org/t/problems-with-staff-priviledges/39001/5 "2023-06-28T08:34:04Z")

</div>

Well the obvious issue got shut down on github: [Staff should be available as authors before first login · Issue #16875 · TryGhost/Ghost · GitHub](https://github.com/TryGhost/Ghost/issues/16875)

Amazing that they see no issue with staff being able to create pages and not save them. If all pages must be created by an admin before staff can do anything with them, then disable it all together. But that is probably just coping with the fact that some staff should be able to create pages / having an incoherent priv model.

---

<div class="post-metadata">

**Author:** ![markstos](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/markstos/32/18182_2.png) [@markstos](https://forum.ghost.org/u/markstos)\
**Post date:** [June 28, 2023, 11:04am UTC](https://forum.ghost.org/t/problems-with-staff-priviledges/39001/6 "2023-06-28T11:04:18Z")

</div>

The GitHub issue doesn’t say they are against the change, only that they want to track it as a feature request.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/ghost2/original/2X/b/ba9ce5100b8bb264586f4f572545596b2ce3f081.png) [@system](https://forum.ghost.org/u/system)\
**Post date:** [September 26, 2023, 11:05am UTC](https://forum.ghost.org/t/problems-with-staff-priviledges/39001/7 "2023-09-26T11:05:12Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
