Access and cache
Admin › Access is a read-only answer to “who can do what”: every ContextWorks Admin, every domain manager with the domains they manage, and any assignment that isn’t actually granting anything. Clear Cache sits in the rail below it.
Read the access overview
- Admins hold the ContextWorks Admin permission set.
- Domain managers hold ContextWorks Domain Manager, listed with the domains that back the grant. No domains assigned means the permission set grants nothing yet.
- On a domain, without a permission set appears only when a domain names a user who holds neither set — an assignment that currently does nothing. Assign the permission set in Setup, or remove them from the roster.
A banner warns when delegated administration is off — the manager permission set is inert while it stays off.
Check that domain scoping is in force
The page reports three things you cannot see anywhere else:
| It says | Meaning |
|---|---|
| Domain scoping is in force | Entity Domain is Private. Users read the domains shared to them |
| Domain scoping is NOT in force | Entity Domain is Public Read/Write, so every user holds every domain. Fix it in Setup → Sharing Settings |
| Owned by users with a role | Those domains can be inherited through the role hierarchy without being granted. Reassign the owner, or clear Grant Access Using Hierarchies |
It also names any entity on no domain roster. Those reach nobody — either roster them or leave them retired deliberately. → Sharing setup
Change access
This page doesn’t edit. Grant or revoke the permission sets in Setup; edit domain rosters on the Domains page in the Studio tab, where the Users and Managers buttons also grant access to a domain. Consumers — users calling the actions through an agent or MCP — hold ContextWorks User, which isn’t listed here; see Domain access.
Clear the cache
Click Clear Cache in the rail and confirm. Settings, resolved field lists, and currency rates are wiped and rebuild on the next request. No configuration is touched. Use it when a change doesn’t seem to be taking effect — normal saves clear the relevant caches themselves, so this is a just-in-case, not a routine.