Currently, when configuring a Change Security Step in a DocuSign CLM Workflow, it’s not possible to easily restrict or modify access for roles (permission profiles) — only for individual users.
Folders inherit a general “CLM User” permission profile by default. To apply more granular or restricted access (e.g., remove visibility from general users), we have to use the roles property in the API endpoint POST /tasks/changesecuritytasks.
However, this capability is not currently exposed or configurable via the CLM Workflow UI directly with step update security.
Improvement request:
Please add the ability in the Workflow designer to:
-
Configure folder security updates based on roles, not only users.
-
Easily remove or limit the default “general CLM user permission profile” access from workflow steps.
-
Align UI behavior with what’s supported by the API.
This would greatly simplify permission automation and improve security management within workflows.
Back to Docusign.com

