Permissions and access
This page is for workspace owners and admins deciding who can do what. It lists:
- the built-in permission sets;
- every permission they are made of;
- the access levels of a share.
Two things decide what a member of a workspace can do:
- their permission sets decide what they can do in the workspace;
- shares decide where: which folders, lists and views they can reach (Share a folder or a list).
A member needs both, except members whose sets include See all or Edit all. A Worker who can edit tasks still sees only the folders, lists and views shared with them, plus the views at the top of the workspace, which every member can open. For how the two fit together, see Sharing along the hierarchy.
Built-in permission sets
Every workspace has these sets. A new member starts with Worker.
| Permission set | Can do | Guide |
|---|---|---|
| Worker | Work on tasks, comments, time logs, relations and recurring tasks in whatever is shared with them. Read folders, lists, views, tags, templates and automations. Vote in Scrum Poker | Invite a member |
| List/Folder manager | Everything a Worker can do, plus create, change, delete and share folders, lists and views | Grant permission sets |
| Admin | Every permission except Manage permission sets, See all and Edit all | Grant permission sets |
| Super Admin | Every permission | Grant permission sets |
The owner has every permission
The workspace owner has every permission through ownership, so permission sets change nothing for them.
Sets are given in Workspace settings, under Members or Permission Sets; see Grant permission sets.
Who can give sets
Only the owner and members with Manage permission sets (Super Admin) can give sets or build new ones. Admin can't.
Rules:
- Sets add up. A member can hold several sets, and gets every permission in any of them.
- Built-in sets are fixed. To adjust one, build your own set in Permission Sets (Custom sets). A set you build keeps exactly the permissions you tick.
Example. A contractor who works on one client's tasks gets Worker and a Read share on the folder Client A. They can open and comment on its tasks but not change them, and they see nothing else except the views at the top of the workspace. Changing the share to Edit lets them update tasks and log time.
Permissions by set
Permissions come in blocks, one block per kind of thing. The table shows which built-in sets include each block's permissions.
| Block | Permission | Worker | List/Folder manager | Admin | Super Admin | Guide |
|---|---|---|---|---|---|---|
| Workspace | Manage general settings, Manage members, Import data | — | — | ✓ | ✓ | Invite members and grant permissions |
| Workspace | Manage permission sets | — | — | — | ✓ | Invite members and grant permissions |
| Folders, Lists, Views | Read | ✓ | ✓ | ✓ | ✓ | Share a folder or a list |
| Folders, Lists, Views | Create, Update, Delete, Share | — | ✓ | ✓ | ✓ | Organize folders and lists |
| Folders, Lists, Views | See all, Edit all | — | — | — | ✓ | Share a folder or a list |
| Tasks | Create, Read, Update, Delete, Manage watchers | ✓ | ✓ | ✓ | ✓ | Create and edit tasks |
| Task fields | Title, Description, Status, Assignee, Dates, Priority, Tags, Story points, Time tracking | ✓ | ✓ | ✓ | ✓ | Create and edit tasks |
| Comments | Create, Read, Update, Delete, React | ✓ | ✓ | ✓ | ✓ | Comment and mention people |
| Time logs | Create, Read, Update, Delete | ✓ | ✓ | ✓ | ✓ | Track time on a task |
| Relations | Create, Read, Update, Delete | ✓ | ✓ | ✓ | ✓ | Link related tasks |
| Recurring jobs | Create, Read, Update, Delete | ✓ | ✓ | ✓ | ✓ | Set up a recurring task |
| Scrum poker | Read, Vote | ✓ | ✓ | ✓ | ✓ | Estimate with Scrum Poker |
| Scrum poker | Create, Facilitate | — | — | ✓ | ✓ | Estimate with Scrum Poker |
| Automations | Read | ✓ | ✓ | ✓ | ✓ | Create an automation |
| Automations | Create, Update, Delete | — | — | ✓ | ✓ | Create an automation |
| Tags, Tag sets | Read | ✓ | ✓ | ✓ | ✓ | Tag tasks |
| Tags, Tag sets | Create, Update, Delete | — | — | ✓ | ✓ | Tag tasks |
| Status templates, Relation templates, Templates | Read | ✓ | ✓ | ✓ | ✓ | Set up a list |
| Status templates, Relation templates, Templates | Create, Update, Delete | — | — | ✓ | ✓ | Set up a list |
Permissions with special rules
| Permission | Effect | Guide |
|---|---|---|
| Read on folders, lists or views | Without it, those items don't show for the member even where they are shared | Share a folder or a list |
| See all | Sees every folder, list or view of that kind, shared or not. Each kind has its own key: full visibility needs all three | Share a folder or a list |
| Edit all | Edits every folder, list or view of that kind, shared or not | Share a folder or a list |
| Share | Adds Share… to that kind of item's menu, where the member gives and removes access and turns Inherit access on or off. Without it, Share… is not in the menu | Share a folder or a list |
| Task fields | A field left off stays visible, but the member can't change it. Changing any field also needs Update in Tasks | Create and edit tasks |
| Manage watchers | Adds and removes other people as watchers. Watching a task yourself doesn't need it | Assign and watch tasks |
| Update, Delete in Comments | Apply to your own comments only: nobody edits a colleague's comment | Comment and mention people |
| Update, Delete in Recurring jobs | Needed for every change. On a series you created, the permission is enough. On someone else's, you also need an Edit share on the list the series creates tasks in, and deleting it needs Update as well | Set up a recurring task |
Share access levels
A share gives one member access to one folder, list or view. Open it from the item's menu with Share… (Share with a member).
Members only
Shares reach only members of the workspace: to give someone outside access, invite them first.
| Access | Allows | Guide |
|---|---|---|
| Read | Seeing the item and its tasks, commenting and reacting, and watching a task yourself | Share a folder or a list |
| Edit | Everything Read allows, plus changing the item and its tasks, logging time and adding other watchers, as far as the member's permission sets allow. A relation needs Edit on at least one of the two tasks | Share a folder or a list |
Inheritance and private items
Rules, with the example in Access down the tree:
- A folder share covers what is inside — folders, lists, views and tasks — except items marked Private and what they contain.
- A list share covers its views, except private ones.
- The dialog names the source. A direct share reads Provided by and the workspace owner's name; an inherited one reads Via and the folder it comes from.
| Case | Who sees it | Guide |
|---|---|---|
| Inherit access on (the default) | Everyone with access to the parent folder or list, plus anyone shared directly | Share a folder or a list |
| Inherit access off: the item shows a Private badge | Only its creator, anyone shared directly, the workspace owner, and members with See all or Edit all for that kind of item | Private branches |
| A view at the top of the workspace | Every member can open it. Changing it needs an Edit share and Update in Views (List/Folder manager and above) | Share a folder or a list |
| A list's default view | Everyone with access to the list, always | Set up a list |
Turn Inherit access off in the item's Share… dialog, or when you create a list or view.