Roles and Access Rights

⚠️ Who can manage roles and rights?

To manage users' roles and access rights, you must be the Admin or Manager level user.

  • Roles and permissions apply per workspace. You must invite users to each workspace separately.

User roles

For each workspace, every user is assigned a role and given a defined set of access rights, which determine the capabilities a user has within the workspace and what they can see and change.

Every user has one role per workspace: Admin, Manager, User or Guest. Admins and Managers can do everything with the workspace content; what a User or Guest can do depends on their access rights.

What the role can do Admin Manager User Guest
See and change all items, incl. budget, expenses and hidden cost rates ✓ ✓ by access rights by access rights, Read at most
Track time, create to-dos ✓ ✓ ✓
Invite users and guests, manage groups and access rights (Users, Access tab) ✓ ✓
Lock and unlock items ✓ ✓
Workspace settings: general settings, customization (tags, cost categories, activity types), reporting periods, plan versions ✓ ✓
Make another user Admin ✓
Create API keys, transfer workspace ownership ✓

Owner: one per workspace, usually the person who created it. The owner is also an Admin, manages the subscription and billing, and is the only one who can delete the workspace.

Guests are external people with limited access: they can have at most Read rights, and they can comment but not track time or create to-dos. See Adding guest users.

💡 Good to know: 

Access rights of Regular Users

Non-admin and non-manager role-level users are regular users. For them, you can define the access rights per sections (Workspaces & Activities, Participants, Documents, Budget, Expenses) and per specific items in these sections.

The following access rights options are available per each section and item:

  • Manage: The user has full access to the data – can see, edit, and manage (add, move, or delete) workspace items.
  • Edit: The user can see and edit workspace items, but cannot manage them.
  • Read: The user can see workspace items, add comments and attachments, but cannot edit and manage items.
  • Off: The user has no access to workspace items.

💡 Good to know:

  • To view budget or expense data, a user needs at least Read access to the related project or activity and participant.
  • What each right allows for activities, participants, folders and their budget items, expenses and documents, and how rights work between parent items and sub-items, is explained in What access rights mean for activities, participants and folders.

Using groups to set user access rights

Instead of assigning access rights to each user individually, you can organize workspace users into groups and manage their rights collectively. By assigning access rights to a group, all users in that group automatically receive those rights. When a user joins or leaves a group, their access rights are updated accordingly.

Groups can only be assigned the Regular User role. You cannot assign Admin, Manager, or Owner roles to groups.

⚠️  For important or sensitive access configurations, we recommend using restricted groups rather than open groups. In restricted groups, a designated Group Manager controls group membership.

🔍 Important notes on group-based access rights: 

When users belong to multiple groups or have both individual and group access rights, users can have different access right sets, the system applies the strongest access right available across individual rights and group rights across multiple groups.

  • An access right set at the item level overrides section-level rights for that item.
  • When several rights apply to the same item from different sources (individual settings, multiple groups), the strongest one wins: Off < Read < Edit < Manage. To see a user's effective right on an item, check the item's Access tab.

For example:

A user has:

  • Read rights to the “Workplan” section (individually assigned)
  • Off rights to the specific item WP1 (individually assigned)
  • Is a member of a group with Edit rights to the entire “Workplan” section

Result:

The user will have Edit access to all items in the “Workplan” section, except WP1, because the Off setting at the item level overrides the section-level Edit rights.

⚠️ "Off" does not block access — the strongest right always wins

Setting a group's access right to Off only removes the rights granted through that group. It does not take away rights a user holds from other sources — their individual access rights or membership in other groups.

For example: A group has Off rights to a folder, but its members have individual Manage rights to the "Documents" section. The members can still fully access the folder, because their individual Manage right is the strongest right available to them.

To restrict a user's access to an item, make sure Off is the strongest right that user has for this item: set the item to Off in the user's individual access rights, either via "Refine" in the Users section or directly in the item's "Access" tab, where you can review the effective rights of every user.

💡 Tip: To check which groups a user belongs to and where their rights come from:

  1. Go to the Users section in the workspace.
  2. Enter the user’s email address in the search field.
  3. You’ll see the user and all groups they are part of.

Now you can easily review all rights the user has — both from individual settings and from group membership.

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.