Help Center · Settings security
Roles and permissions
Grant or take away exactly the capabilities each role in your workspace holds, or build a custom role that covers only the slice of the product one group of people should touch.
Who this is for
Owners only. Viewing and changing roles both need the permission that manages the organisation. A manager can't open this page at all, even a manager who can do a lot elsewhere.
Before you start
Every workspace starts with three built-in roles: Owner, Manager, and Member. All three are locked (shown with a padlock): you can't rename them, delete them, or tick their boxes, because system roles can't be edited. Owner holds every permission there is. Manager holds exactly five: View team members, Edit capture policy, Edit & approve time, View projects, and Manage projects. Notably, that does *not* include Manage members & invites, so a manager cannot invite, edit, or remove people, and it does not include Manage organisation settings, so a manager cannot reach this page or most of Settings. Member holds no permissions at all. If a manager needs to do something outside that list (say, changing notification delivery, which needs Manage members & invites even though its own screen says "manager or owner" can change it), the fix is to either grant Manage members & invites to Manager, or build a custom role for it.
Steps
- Open Roles & permissions. You'll see the Permissions grid: one column per role, one row per capability, grouped under headings like Organisation, Time & projects, Insights & records, Pay, Billing, and Automation & developers.
- Grant or revoke a capability: select the tick cell where a capability row meets a role column. Owner, Manager, and Member are locked and can't be ticked; only a custom role's column is clickable. Changes are staged. Nothing is saved until you say so.
- Once you've ticked or unticked anything, a save bar appears at the bottom. Select Save 1 role (or Save N roles if you changed more than one) to apply the changes, or Discard to drop them and revert to what's saved.
- To create a custom role, select New role, give it a name, tick the capabilities it should grant, and select Create role. A role can be created with no permissions ticked, though it grants nothing until you add some.
- To rename a role or change its grants, find it under Custom roles and select Edit, adjust the name and/or ticks in the dialog, then select Save role.
- To delete a custom role, select Delete next to it and confirm. If anyone still holds that role, the confirmation says so and the delete is refused until you move them to another role first.
- The count under each role's name in the grid reads Unassigned or N assignment(s), and the same count appears next to each custom role in the list below. That's how many people currently hold it.
What happens next
A capability change takes effect for everyone holding that role as soon as you save it. There's no separate rollout step. Deleting a role removes it outright; anyone who loses their only role keeps their account but loses whatever that role granted.
If it doesn't work
- If you can't reach this page at all, you'll see "Only an owner can manage roles", *"Ask an owner to change what a role can do, or sign in as one."*
- If you try to save without owner access, you'll see "Only an owner can change roles."
- If you try to delete a role that's still assigned to someone, the delete is refused with a message naming exactly who's still holding it and how many. Reassign them first, then delete.
- Trying to tick a cell for Owner, Manager, or Member does nothing. Hovering it explains why: *"[role name] is a system role and can't be edited."*
Related
- Workspace settings
- Single sign-on