Default Author / Editor Setup
This page explains the default configuration for authors and editors in Bloomreach Content. It focuses on the permissions and capabilities of users assigned to the author or editor roles. For information on default authorization from a security perspective, see Default Authorization Setup. For guidance on creating custom author or editor roles, refer to Custom Authors / Editors Setup.
Overview of Author and Editor Capabilities
Users in the author and editor groups primarily work with documents in the CMS. Authors and editors have similar permissions, with one key difference: authors cannot directly change the published state of documents. Specifically:
- Authors cannot publish documents or take them offline.
- Authors can request publication or request to take a document offline.
- Editors can publish documents and take them offline directly.
Info: Authors do not have permission to directly change the published status (liveness) of documents.
Starting with brXM 14.0.0, authors and editors share most capabilities. Both can create folders, create new documents, move, rename, and copy documents. In earlier versions, authors had more restricted permissions and could not delete, rename, or copy offline documents, except by requesting deletion. Version 14.0.0 expanded author capabilities to make the role more practical.
By default, authors and editors do not have the jcr:write privilege on folders or document variants. This is important when configuring custom author or editor groups. On folders and documents, these users typically have only the hippo:author or hippo:editor privilege. Actions such as creating or modifying documents are performed through an internal workflow session, which executes and validates the actual JCR changes.
The exception is for draft documents that a user is currently editing. In this case, the user receives the jcr:write privilege on any draft document where they are the holder. This is configured in the domain at /hippo:configuration/hippo:domains/draft-document-holder-readwrite.
Advanced note: The domain grants jcr:write privilege to descendant nodes of the draft document through logic in the HippoAccessManager. This behavior is not visible in the domain configuration itself.
Info: The jcr:write privilege on a document variant is inherited by all readable descendant nodes for the current JCR session.
This inheritance allows authors and editors to modify readable child nodes of document variants they have write access to. To review the effective privileges for a user on a JCR node, see View Permissions of a User in the Console.
Authorization and User Roles
Authors and editors receive default read access as members of the everybody group, which grants read access to certain repository areas. This section outlines the key permissions and user roles assigned by default.
Default Author Group
The author group is bootstrapped with the user role xm.default-user.author. This role inherits the following user roles:
- xm.cms.user
- xm.dashboard.user
- xm.content.author
- xm.channel.viewer
- xm.project.viewer
A user in the author group receives:
- Access to the CMS application.
- Read access to specific JCR nodes under
/hippo:configurationvia xm.frontend-config.reader. - Access to the dashboard perspective.
- The hippo:author privilege on all descendants of
/contentvia xm.content.author, enabling author workflow actions on folders and documents. - Access to the Experience Manager and permission to view channels via xm.channel.viewer.
- Read access to
/webfilesvia xm.channel.viewer. - Access to the Projects Dashboard and the jcr:read and hippo:project-author privileges on
/hippowpm:hippowpm/hippowpm:projectsand its descendants.
Default Editor Group
The editor group is bootstrapped with the user role xm.default-user.editor. This role inherits the following user roles:
- xm.cms.user
- xm.dashboard.user
- xm.content.editor
- xm.channel.viewer
- xm.project.editor
A user in the editor group receives:
- Access to the CMS application.
- Read access to specific JCR nodes under
/hippo:configurationvia xm.frontend-config.reader. - Access to the dashboard perspective.
- The hippo:editor privilege on all descendants of
/contentvia xm.content.editor, enabling editor workflow actions on folders and documents. - Access to the Experience Manager and permission to view channels via xm.channel.viewer.
- Editors cannot modify channels by default.
- Read access to
/webfilesvia xm.channel.viewer. - Access to the Projects Dashboard and the jcr:read, jcr:write, and hippo:project-editor privileges on
/hippowpm:hippowpm/hippowpm:projectsand its descendants.
Channel Webmaster Role
By default, both authors and editors have the xm.channel.viewer role, which allows them to access the Experience Manager and view channels. To grant a user permission to modify channels, assign the xm.channel.webmaster user role. You can do this by:
- Assigning xm.channel.webmaster directly to the user.
- Assigning xm.channel.webmaster to a group the user belongs to.
- Adding the user to the default webmaster group.
Alternatively, you can assign xm.default-user.webmaster, but be aware that this role may grant additional privileges beyond channel modification.
Reporting Dashboard Access
By default, no users or groups—including authors and editors—have access to the Reporting Dashboard. Access to the Reporting Dashboard is implementation-specific and is not enabled by default.
To grant access to the Reporting Dashboard for authors, editors, or other users or groups, assign the xm.report.user user role using the CMS UI (Setup > System application). If you make this change locally with auto-export enabled, it can be included in your YAML bootstrap configuration.
User roles and group memberships are categorized as system by default (see .meta:add-new-system-values), so you can safely apply these changes directly in production, and they will be preserved during updates and upgrades.