Roles and permissions
What admins, members and viewers can do, how to create your own role, and how to be stricter per workspace and per column.
Everyone in your organization has a role. The role decides what someone can do. On top of that, you can be stricter per workspace and per column.
The three default roles
- Admin: can do everything, including Administration. This is fixed, so someone can always fix everything.
- Member: works on boards as usual. By default a member can do everything except invite members. An admin can change that.
- Viewer: reads everything and only changes their own profile and notifications. Only Export to CSV can be set for a viewer.
You can see who the admins are in the profile menu under Organization. Contact them for permissions and invites.
Set what members can do
- Click your avatar in the top right and choose Administration.
- Open Permissions.
- Choose the Member role on the left.
- Turn permissions on or off. A change applies right away.
The permissions are grouped: Account, Boards, Items, Automations, Dashboards and Communication. Each one has a line of explanation. Examples are Invite members, Delete and archive all boards and Create and edit automations.
Create your own role
None of the default roles fits? Create a custom role.
- Go to Administration › Permissions and choose New role.
- Give the role a name and pick what it is Based on: Admin, Member or Viewer.
- Click Create role.
- Turn the permissions of the new role on or off.
- Give the role to someone in Administration › People.
A custom role starts with the permissions of the role it is based on. It can only do less, never more. Anything the base role cannot do is greyed out.
A role based on Admin is a limited admin. It has the regular permissions plus a checkbox for each part of Administration, such as View audit log or Departments. Changing roles and permissions stays with the admin.
You can rename, duplicate and delete a role. When you delete one, you see how many people have it and which role they get instead.
Permissions per workspace
A workspace is open by default: everyone in the organization can use it. Make it Closed and only the members and the admins see the workspace and everything in it.
- Click the name of the workspace in the sidebar.
- Open the Permissions tab.
- Choose Open or Closed and manage the members.
- Under Default workspace roles, set per permission what an Owner, Member and Non-member can do. Click Save.
The organization role always wins. A viewer stays a viewer, even as the owner of a workspace. Only an owner of the workspace or an admin can change this. To add people, see Inviting members.
Lock or hide columns
You can decide per column who can change it or see it. Open the column menu and choose Settings. Under Permissions you find:
- Restrict editing: others still see the cells but cannot change them.
- Restrict viewing: others do not see the column anywhere, not even in filters, search, exports or dashboards.
- Restrict managing labels (for status and dropdown columns): everyone can still pick an existing label, but only the people you choose can create or change labels.
For each one, choose Everyone (no restriction), Only admins or Only the people I choose: people and departments. Admins can always, and you are added automatically. Automations still fill in a locked column. Learn more about columns in Columns.