While I understand there is a checkbox in the settings to set permissions for users to access the workspaces. However, are there any options beyond access/no access?
For example, can I allow a user to access a workspace and only give rights to clone campaigns - or, if that is not possible, then just have "read only" access?
We are beginning to expand globally and entry level users are entering the instance. While we want them to be able to save time by cloning programs (especially email send programs and email nurtures), we do not want to allow the ability for the user to move, delete, or change the programs, campaigns, or assets in the workspace.
Yes -- the key is going to be how your Roles & Permissions are setup. It's probably going to be worthwhile to take a look at what roles you're currently using in your instance and their associated permissions, and decide whether you want to create additional roles to roll out (heh) to your new group of entry-level users, since the built-in roles from Marketo don't get to level of granularity you're looking for.
The Marketo Docs have this covered pretty well:
Managing User Roles and Permissions - Marketo Docs - Product Documentation
Descriptions of Role Permissions - Marketo Docs - Product Documentation