# Global read permission cannot be restricted per namespace

**URL:** <https://community.bluespice.com/t/global-read-permission-cannot-be-restricted-per-namespace/366>\
**Category:** Configuration/Setup\
**Created:** [February 9, 2026, 7:00am UTC](https://community.bluespice.com/t/global-read-permission-cannot-be-restricted-per-namespace/366 "2026-02-09T07:00:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefanjo](https://avatars.discourse-cdn.com/v4/letter/s/7bcc69/32.png) [@stefanjo](https://community.bluespice.com/u/stefanjo)\
**Post date:** [February 9, 2026, 7:00am UTC](https://community.bluespice.com/t/global-read-permission-cannot-be-restricted-per-namespace/366/1 "2026-02-09T07:00:16Z")

</div>

Hi,

I’m using the BlueSpice Permission Manager and noticed that **global `read` permissions cannot be effectively restricted on a namespace level**.

If a group has global `read`, the namespace UI always shows  
_“Granted – inherited from global permissions”_, and there is **no way to explicitly deny `read`** for specific namespaces.  
“Not granted” does not override the global permission.

This makes it impossible to configure a group that can **read only one specific namespace** but not the rest of the wiki.

Is this behavior **by design** in BlueSpice / MediaWiki?  
If so, the wording _“unless explicitly blocked”_ in the UI seems misleading, since `read` cannot actually be blocked per namespace.

Thanks!

---

<div class="post-metadata">

**Author:** ![mlink-rodrigue](https://avatars.discourse-cdn.com/v4/letter/m/85e7bf/32.png) [@mlink-rodrigue](https://community.bluespice.com/u/mlink-rodrigue)\
**Post date:** [February 11, 2026, 1:23pm UTC](https://community.bluespice.com/t/global-read-permission-cannot-be-restricted-per-namespace/366/2 "2026-02-11T13:23:11Z")

</div>

Hi stefanjo,

welcome to the BlueSpice Support Forum.

The wiki uses the logic of a “default-allow” access model.

If you want to read-restrict a specific namespace, you need to give read permissions to one or more groups - all other groups are then excluded from read-permissions.

The Global permissions will still show as green, because you might have other namespaces for which that group has read-permissions - it simply means that you generally set read permissions globally for that group **on all namespaces that do not have explicitly set permissions**.

**Example:** You set “Authenticated users” to have “Reader” role in the wiki in Global permissions. But you need to restrict read permissions of the namespace “RT” to group “Intern”.

Select the group “Intern” and explicitly grant “Reader” role in namespace “RT”:

 ![image](https://europe1.discourse-cdn.com/flex017/uploads/bluespice/original/1X/3ea3136b3c0917b30c0a48fcc9f3edb738753742.png)

After that, click on group “Authenticated users” and review their permissions for the namespace “RT” - it will show that the read permissions are retracted, because the namespace is now “blocked” by group “Intern”:

 ![image](https://europe1.discourse-cdn.com/flex017/uploads/bluespice/original/1X/bc5a00a45383728f6b0d20430ddfb364d1236a92.png)

When you are done, don’t forget to click “Save” at the top of the page:

 ![image](https://europe1.discourse-cdn.com/flex017/uploads/bluespice/original/1X/3a1d24ab7315e0183d81fb16a07d2e6b887c7675.png)

**Advanced mode:**

I find it easier to use the “Advanced mode” (toggle switch at the top of custom settings) for setting explicit permissions, because the matrix view shows better what group has what role in each namespace.

Here, we clearly see when we click through the groups that they no longer have permissions for the “Intern” namespace. The checkbox background is greyed out. Hovering over the checkbox shows which group(s) block that namespace:

 ![image](https://europe1.discourse-cdn.com/flex017/uploads/bluespice/original/1X/c9644499f41e1614926a027b727f4ba3193e5b13.png)

The logic for “revoking” inherited/global permissions is documented here:

> **[Explicitely set namespace permissions - Permissions management - BlueSpice...](https://en.wiki.bluespice.com/wiki/Manual:Extension/BlueSpicePermissionManager#Explicitely_set_namespace_permissions)**
>
> The permission manager can be accessed from the Global actions menu under Administration \> Permissions. This link loads the page Special:PermissionManager.

Hope this helps!

Greetings,

Margit
