> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.patronum.io/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How do I give someone access to Patronum

Granting Patronum access requires two steps: enabling the app in Google Admin Console and assigning a role within Patronum. Both are required—Google Workspace permissions alone won't grant access to Patronum features.

|| Before you begin: You need Google Workspace Super Admin access to complete both steps.

## Step 1: Enable Patronum in Google Admin Console

Patronum must be enabled for all users at your organization's root level due to Google API requirements.

1. Go to Google Admin Console > Apps > Google Workspace Marketplace apps.
2. Find Patronum in the list.
3. Click User access.
4. Select ON for everyone at the root organizational unit.
5. Click Save.

Enabling Patronum for a subset of users or specific organizational units will cause API failures. The app must be enabled at the root level. For a more detailed article [on the correct configuration of Patronum](https://help.patronum.io/en/article/getting-unauthorizedclient-client-is-unauthorized-to-retrieve-access-token-error-wnuf21/).

## Step 2: Assign a Patronum role

After enabling the app, assign specific permissions within Patronum to control what users can access.

1. Log in to Patronum.
2. Go to Roles in the left sidebar.
3. Click + to create a new role (or select an existing one).
4. Name the role and add the user(s) who need access.
5. Under PRIVILEGES, expand Admin Custom privileges.
6. Select the sections the user should access (Users, Groups, Email Signatures, Drive, etc.).
7. Click Save.

Users must log out and log back in to Patronum for role changes to take effect. The interface syncs permissions hourly.

## Google Admin privileges vs. Patronum roles

Understanding which Google Workspace role is required for specific Patronum sections helps you delegate access appropriately:
| Patronum Section | Google Admin Privilege Required | Notes |
| ---- |
| Users (view/edit profiles) | Super Admin or API access via app enablement | Non-admins can view if granted Patronum role |
| Users (update custom attributes) | Super Admin + "Update Custom Attributes" scope | Requires additional API permission |
| Groups | Super Admin or API access via app enablement | Create/manage requires Patronum role |
| Email Signatures | Super Admin or API access via app enablement | Deploy/manage requires Patronum role |
| Google Drive (sharing/ownership) | Super Admin or API access via app enablement | Limited for non-admins due to Google API restrictions |
| Contacts | Super Admin or API access via app enablement | Sharing requires Patronum role |
| Automations | Super Admin or API access via app enablement | Create/edit requires Patronum role |
Google Workspace Super Admins automatically have full access to all Patronum features without needing a custom role assignment.

## Common issues
User sees a blank screen or "unauthorized" error: The user doesn't have a Patronum role assigned. Follow Step 2 above to grant access.
Role changes aren't showing: Users must log out and log back in. Patronum syncs permissions every hour.
App isn't working for anyone: Verify Patronum is enabled at the root organizational unit in Google Admin Console, not just for specific users or OUs.

## Related articles
For detailed guidance on creating custom roles, see [Custom Permissions and Role Management](https://help.patronum.io/en/article/custom-permissions-and-role-management-1vq9yns/)  and [How to create administrative roles within Patronum](/en/article/how-to-create-administrative-roles-within-patronum-1ql96j9/).