Skip to main content
PUT
Add permissions to a user
Adds one or more permissions to a user’s existing permissions list. Only admin-level users can perform this action.

Request

Headers

Request Body

Request Body Schema

Permission Format

Permissions follow the pattern: compass.module.action
  • Use * as wildcard (e.g., compass.dashboard.*)
  • Specific actions (e.g., compass.dashboard.overview)
  • Module-level access (e.g., compass.emailmeter)

Response

200 OK - Successfully added permissions

400 Bad Request

401 Unauthorized

403 Forbidden

404 Not Found

500 Internal Server Error

Example

Notes

  • This is an admin-only endpoint - requires administrative privileges
  • Permissions are added to the user’s existing permissions (not replaced)
  • Duplicate permissions are automatically ignored
  • The user ID must be a valid MongoDB ObjectId
  • Permission strings must follow the defined pattern
  • Changes take effect immediately for the user’s next request
  • Use the /user/remove-permissions endpoint to remove permissions
  • Permission changes are logged for audit purposes

Available Permissions

Common permission patterns:
  • compass.dashboard.* - Full dashboard access
  • compass.dashboard.overview - Dashboard overview only
  • compass.emailmeter.* - Full Email Meter access
  • compass.emailmeter.stats - Email Meter statistics only
  • compass.hubspot.* - Full HubSpot access
  • compass.users.* - User management access
  • compass.departments.* - Department management access

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
payload
object
required

Response

Successfully added permissions

message
string
Example:

"Successfully added permissions for this user."

data
object
Example: