Advanced Permissions - Least Privilege by Default, Across Every Contract
Advanced Permissions is a ContractControl power module offering role-, attribute-, and entity-based access controls that scale from 10 to 10,000 users, with clause-level redactions, approval-gated reads, and a full audit trail. Most teams default to broad access because scoping is too hard - Advanced Permissions makes least privilege the easy path, not the exception.
Advanced Permissions is part of the ContractControl CLM platform. Explore all power modules or book a demo to see it in action.
Permissions modelled the way your company works
Express role, attribute, and entity rules as policies instead of relying on all-or-nothing access. Compose policies in plain English across entity, region, value, and purpose, create unlimited roles and groups with metadata-level control, and apply clause-level redactions and watermarks per role. Workspaces and folders inherit policy, and you can override per resource, so sales never sees salary contracts and reviewers never wait days for IT to grant access.
Six permission dimensions, one policy engine
Advanced Permissions works across six dimensions - role, attribute, entity, region, time, and purpose - handling up to 20,000 users per tenant. A live policy evaluator and full audit trail per user, per document mean every read, write, and sign is captured, with zero untracked accesses.
Key features
- RBAC + ABAC: Role and attribute-based controls in one policy engine. No either/or.
- Clause-level redaction: Hide salary, pricing, and IP clauses per role - same document, different views.
- Approval-gated reads: Sensitive folders require a named approver before opening, logged with a reason.
- Granular roles and groups: Create unlimited custom roles and groups with precise access levels (Read, Write, Sign, or None) mapped directly to your metadata and workflows.
- Audit and separation of duties: Separation-of-duties enforced at policy time, not after the fact.
- Residency controls: Restrict access by IP, region, or device posture per workspace.
Frequently asked questions
What is the difference between RBAC and ABAC in ContractControl?
Advanced Permissions combines role-based access control (RBAC) and attribute-based access control (ABAC) in one policy engine, with no either/or. You can define roles with inherited base permissions and layer on rules based on entity, region, value, time, and purpose, so access is modelled the way your company actually works.
Can I hide specific clauses from certain users?
Yes. Clause-level redactions let you hide salary, pricing, or IP clauses per role, so the same document shows different views to different people. Sensitive folders can also require a named approver before they open, and that access is logged with a reason.
How many users and roles does Advanced Permissions support?
Advanced Permissions scales from 10 to 10,000 users per tenant and lets you create unlimited custom roles and groups with precise access levels such as Read, Write, Sign, or None, mapped directly to your metadata and workflows. Workspaces and folders inherit policy, and you can override per resource as needed.
Is every access to a contract logged?
Yes. 100% of reads, writes, and signs are audit-logged, with zero untracked accesses. Separation of duties is enforced at policy time rather than after the fact, giving you a full compliance trail across every contract, folder, and workspace.