You do not have permission to perform this action
Avvi refuses a blocked action in two different ways. One names the feature and one deliberately does not, and they need different responses.
Avvi blocks an action and says you do not have permission. Nothing is broken.
Almost every capability in Avvi ships switched off. For your own team it is turned on per access group, and for a client’s staff per user group. The usual cause is a permission nobody has enabled yet.
Two different refusals produce this, and they look similar. Reading which one you got turns a dead end into a request your administrator can act on.
Symptom
A user told to contact their administrator has hit the first of these two refusals. They cannot see which permission is missing, so ask what they were trying to do.
An action stops and Avvi replies with one of two messages.
The first is:
“You do not have permission to perform this action. Please contact your administrator for access.”
The second names the capability, for example:
“Send As permission feature is not enabled for your organization. Please contact your MSP administrator.”
Other people in the same organisation may be able to do the same thing without any trouble.
Cause
The first message means the person asking is not permitted.
Access is granted per group rather than per person. For your own administrators that is an access group; for a client’s staff it is their user group. A colleague in a different group can do things you cannot.
The second message means the capability itself is switched off for that client.
Naming the capability makes it the more actionable of the two.
The capability-level refusal applies to a client’s own staff rather than to your administrators. An MSP administrator seeing this message has usually been forwarded it by somebody at the client rather than having triggered it.
Avvi deliberately does not name the missing permission in the first message.
The message hides the internal permission name, which is why it tells you to contact an administrator without saying what to ask for.
Fix
You need MSP admin access to change either one, and the screen depends on who was blocked.
For a colleague on your own team, open Settings, then Users & Roles, and find the access group they belong to.
For somebody who works at a client:
- In the left sidebar, click My Clients.
- Open the client the blocked person belongs to.
- Go to User Access Control.
- Find the user group the person belongs to.
- Turn on the capability that covers what they were trying to do.
The group’s permission list appears with your change saved. Ask the person to try the same request again.
If something doesn’t look right
If a control is greyed out, your account is not allowed to change it. The setting is not broken and nothing is missing from the page.
If a setting is absent rather than greyed, the feature is switched off for your whole organisation rather than for you.
If the control works and saving fails, Avvi replies “Master admin access required”. That is the same permission problem, reported when you save rather than before.
Check that the person is actually in the group you changed.
Group membership comes from your security groups. A recent change there has to reach Avvi before it takes effect.
If the message named a capability rather than being generic, the fix is the feature switch for that client rather than a group permission.
A group change will do nothing in that case.
If the permission is on, the person is in the right group, and the same message comes back, open a support conversation from the Help drawer.
Include the client name, the person’s email address, the group you changed, and the exact message they saw.
What to do next
If you are the person who was refused rather than the administrator, describe the action you were trying to take.
Avvi does not tell you which permission is missing. Naming the outcome you wanted is more useful than quoting the message.
FAQ
Q: The setting is greyed out and I cannot change it.
A: Your account is not allowed to change that setting. Ask an administrator with full access to change it for you, or to add your group to the permission.
Q: Who do I ask to get access?
A: Any administrator with full access in Avvi. Tell them which setting you were trying to reach and what you needed to change.
Q: Why does Avvi not tell me which permission is missing?
A: The message deliberately hides the internal permission name. Describe what you were trying to do instead.
Q: My colleague can do this and I cannot. Is that a fault?
A: No. Capabilities are granted per group, so two people in one organisation can have different access.
Q: I turned the permission on and nothing changed.
A: Check whether the message named a capability. A capability switched off for the client is not fixed by a group permission.