Skip to content

Permissions and access ​

This page is for workspace owners and admins deciding who can do what. It lists:

  • the built-in permission sets;
  • every permission they are made of;
  • the access levels of a share.

Two things decide what a member of a workspace can do:

  • their permission sets decide what they can do in the workspace;
  • shares decide where: which folders, lists and views they can reach (Share a folder or a list).

A member needs both, except members whose sets include See all or Edit all. A Worker who can edit tasks still sees only the folders, lists and views shared with them, plus the views at the top of the workspace, which every member can open. For how the two fit together, see Sharing along the hierarchy.

Built-in permission sets ​

Every workspace has these sets. A new member starts with Worker.

Permission setCan doGuide
WorkerWork on tasks, comments, time logs, relations and recurring tasks in whatever is shared with them. Read folders, lists, views, tags, templates and automations. Vote in Scrum PokerInvite a member
List/Folder managerEverything a Worker can do, plus create, change, delete and share folders, lists and viewsGrant permission sets
AdminEvery permission except Manage permission sets, See all and Edit allGrant permission sets
Super AdminEvery permissionGrant permission sets

The owner has every permission

The workspace owner has every permission through ownership, so permission sets change nothing for them.

Sets are given in Workspace settings, under Members or Permission Sets; see Grant permission sets.

Who can give sets

Only the owner and members with Manage permission sets (Super Admin) can give sets or build new ones. Admin can't.

Rules:

  • Sets add up. A member can hold several sets, and gets every permission in any of them.
  • Built-in sets are fixed. To adjust one, build your own set in Permission Sets (Custom sets). A set you build keeps exactly the permissions you tick.

Example. A contractor who works on one client's tasks gets Worker and a Read share on the folder Client A. They can open and comment on its tasks but not change them, and they see nothing else except the views at the top of the workspace. Changing the share to Edit lets them update tasks and log time.

Permissions by set ​

Permissions come in blocks, one block per kind of thing. The table shows which built-in sets include each block's permissions.

BlockPermissionWorkerList/Folder managerAdminSuper AdminGuide
WorkspaceManage general settings, Manage members, Import data——✓✓Invite members and grant permissions
WorkspaceManage permission sets———✓Invite members and grant permissions
Folders, Lists, ViewsRead✓✓✓✓Share a folder or a list
Folders, Lists, ViewsCreate, Update, Delete, Share—✓✓✓Organize folders and lists
Folders, Lists, ViewsSee all, Edit all———✓Share a folder or a list
TasksCreate, Read, Update, Delete, Manage watchers✓✓✓✓Create and edit tasks
Task fieldsTitle, Description, Status, Assignee, Dates, Priority, Tags, Story points, Time tracking✓✓✓✓Create and edit tasks
CommentsCreate, Read, Update, Delete, React✓✓✓✓Comment and mention people
Time logsCreate, Read, Update, Delete✓✓✓✓Track time on a task
RelationsCreate, Read, Update, Delete✓✓✓✓Link related tasks
Recurring jobsCreate, Read, Update, Delete✓✓✓✓Set up a recurring task
Scrum pokerRead, Vote✓✓✓✓Estimate with Scrum Poker
Scrum pokerCreate, Facilitate——✓✓Estimate with Scrum Poker
AutomationsRead✓✓✓✓Create an automation
AutomationsCreate, Update, Delete——✓✓Create an automation
Tags, Tag setsRead✓✓✓✓Tag tasks
Tags, Tag setsCreate, Update, Delete——✓✓Tag tasks
Status templates, Relation templates, TemplatesRead✓✓✓✓Set up a list
Status templates, Relation templates, TemplatesCreate, Update, Delete——✓✓Set up a list

Permissions with special rules ​

PermissionEffectGuide
Read on folders, lists or viewsWithout it, those items don't show for the member even where they are sharedShare a folder or a list
See allSees every folder, list or view of that kind, shared or not. Each kind has its own key: full visibility needs all threeShare a folder or a list
Edit allEdits every folder, list or view of that kind, shared or notShare a folder or a list
ShareAdds Share… to that kind of item's menu, where the member gives and removes access and turns Inherit access on or off. Without it, Share… is not in the menuShare a folder or a list
Task fieldsA field left off stays visible, but the member can't change it. Changing any field also needs Update in TasksCreate and edit tasks
Manage watchersAdds and removes other people as watchers. Watching a task yourself doesn't need itAssign and watch tasks
Update, Delete in CommentsApply to your own comments only: nobody edits a colleague's commentComment and mention people
Update, Delete in Recurring jobsNeeded for every change. On a series you created, the permission is enough. On someone else's, you also need an Edit share on the list the series creates tasks in, and deleting it needs Update as wellSet up a recurring task

Share access levels ​

A share gives one member access to one folder, list or view. Open it from the item's menu with Share… (Share with a member).

Members only

Shares reach only members of the workspace: to give someone outside access, invite them first.

AccessAllowsGuide
ReadSeeing the item and its tasks, commenting and reacting, and watching a task yourselfShare a folder or a list
EditEverything Read allows, plus changing the item and its tasks, logging time and adding other watchers, as far as the member's permission sets allow. A relation needs Edit on at least one of the two tasksShare a folder or a list

Inheritance and private items ​

Rules, with the example in Access down the tree:

  • A folder share covers what is inside — folders, lists, views and tasks — except items marked Private and what they contain.
  • A list share covers its views, except private ones.
  • The dialog names the source. A direct share reads Provided by and the workspace owner's name; an inherited one reads Via and the folder it comes from.
CaseWho sees itGuide
Inherit access on (the default)Everyone with access to the parent folder or list, plus anyone shared directlyShare a folder or a list
Inherit access off: the item shows a Private badgeOnly its creator, anyone shared directly, the workspace owner, and members with See all or Edit all for that kind of itemPrivate branches
A view at the top of the workspaceEvery member can open it. Changing it needs an Edit share and Update in Views (List/Folder manager and above)Share a folder or a list
A list's default viewEveryone with access to the list, alwaysSet up a list

Turn Inherit access off in the item's Share… dialog, or when you create a list or view.