Skip to content
Open app

administrationReference

Roles and permissions

Choose roles, manage access, and troubleshoot missing permissions.

A role controls what someone can do. A seat controls whether they can enter the workspace. Check both when someone cannot reach a feature.

Open Settings → Roles to review the available roles. Workspace administrators can manage access; custom roles require Business or Enterprise.

The Roles page listing the built-in roles and the custom-role plan requirement.

RolePurpose
OwnerFull workspace control, including ownership responsibilities.
AdminFull workspace administration.
MemberEveryday workspace work, such as creating boards and reviewing feedback.
ParticipantParticipation-related access. A Participant without a seat cannot enter the workspace.
Team AdminFull control within a team.
Team MemberWork on team boards, reports, and actions.
Team WatcherView team reports.
InternalReserved for the ScatterSpoke team. Do not use it for ordinary team members.

Built-in roles have a System badge. You can view them, but cannot edit or delete them.

An Organization role applies across the workspace. A Team role applies to one team’s membership. A person’s team role does not make them a workspace administrator.

  1. Open Settings → Users.
  2. Find the person and open their details.
  3. Choose the appropriate workspace role.
  4. Confirm the change and check the resulting role in the user list.

The user menu also offers admin-role actions where allowed. You cannot change your own role or use this flow to change the workspace owner’s role. Other administrators can have their roles changed by someone with the required permission. If a control is unavailable, ask the workspace owner to review the change.

Use a custom role when the built-in choices grant too much or too little access.

  1. Open Settings → Roles and select Create Role.
  2. Enter a name and a short description of who should use it.
  3. Choose Organization or Team scope.
  4. Select the permissions the role needs. At least one is required.
  5. Save the role, then assign it to the intended people.

For example, an analyst may need to view reports without inviting users or changing billing. Review the permission descriptions in the editor rather than selecting every category.

A permission does not unlock a feature excluded from your plan. If a person has the right role but sees an upgrade prompt, check Plans and tiers.

You can change its name, description, and permissions. Its scope cannot change after creation; create another role if you need a different scope.

Names must be unique within each scope. Before deleting a role, move its users to a suitable replacement. Deleting it removes the permissions it gave them.

  • Cannot enter the workspace: check that the person has accepted a Seat Holder invitation.
  • Cannot find settings: most workspace settings require admin access. Personal security lives under Profile.
  • Can view but cannot edit: inspect the person’s role and team membership.
  • Sees an upgrade prompt: review the workspace plan, even if the role includes that permission.

See Invite users and seats for invitations and Core concepts for the difference between people, seats, and workspaces.