Team member permissions
See what each role can and cannot do, and invite teammates and outside collaborators safely.
Roles in one line each
- Owner — every permission in the project. Can manage members and delete the project.
- Admin — almost identical to owner. Can invite members, change roles, and edit project settings; only deleting the project is owner-only.
- Member — can read and edit tasks, documents, databases, and chat. Cannot change project settings or delete the project.
- Viewer (view-only) — can only look at content. A good fit for inviting outside reviewers.
Those four are project roles. A team (organization) has its own roles with the same names but a different meaning — the next section separates them.
Team roles and project roles are two different axes
- Project roles — set in Project settings → Manage members. They decide only what someone can do inside that one project (owner · admin · member · viewer).
- Team roles — set in Settings → Team. They decide team administration: the member roster, invites, seats, billing, and ownership (owner · admin · member · viewer · guest).
- Joining a team does not open the team's projects. The only team roles that open projects automatically are team owner and team admin, and what they get there is the project admin role — never project owner, which holds deletion and ownership transfer.
- Team members, team viewers, and guests have to be invited to each project separately. Before that invite the project does not appear in their list, and typing the URL directly does not open it either.
- One person carries both axes at once. Someone can be a plain member of the team and the owner of a specific project; their effective permission in a project is the higher of the role they were invited with and the role derived from their team role.
- Assigning a team owner or team admin the viewer role in a project does not narrow their access — they can edit the member list at any time, so that assignment is not a security boundary. Keep genuinely separate material in a different team (or in a personal project).
Getting this wrong fails quietly. The team admin believes the invite is done while the invited person stares at an empty screen — no error, no notification. Add the people you invite to the team to the relevant projects as well.
Permission matrix by role
| owner | admin | member | viewer | |
|---|---|---|---|---|
| Project settingsOnly the owner can delete a project | Allowed | Allowed | Not allowed | Not allowed |
| Invite members, change rolesCreating invite links and changing roles requires admin or above | Allowed | Allowed | Not allowed | Not allowed |
| Create, edit, and move tasks | Allowed | Allowed | Allowed | Not allowed |
| Write and edit Wiki pages | Allowed | Allowed | Allowed | Not allowed |
| Write commentsTasks, pages, databases | Allowed | Allowed | Allowed | Not allowed |
| Chat messages and pollsChat is deliberately open. Viewers can post in channels and create polls | Allowed | Allowed | Allowed | Allowed |
| Change database items and fields | Allowed | Allowed | Allowed | Not allowed |
| Publish a page publiclyMembers need a paid plan — Starter, Pro, or Lifetime | Allowed | Allowed | Allowed | Not allowed |
| Read (view) | Allowed | Allowed | Allowed | Allowed |
✓ = allowed, ✗ = not allowed. When you change a role, the new permissions apply from that person's next action onward.
Team roles and seats
| owner | admin | member | viewer | guest | |
|---|---|---|---|---|---|
| Team settings, invites, role changesAn admin can appoint new admins too. Only the owner can demote or deactivate another admin | Allowed | Allowed | Not allowed | Not allowed | Not allowed |
| Billing amounts, ownership transfer, deleting the teamTeam admins see seat usage only | Allowed | Not allowed | Not allowed | Not allowed | Not allowed |
| See the team roster and the team's project listGuests see only the projects they were invited to, never the team as a whole | Allowed | Allowed | Allowed | Allowed | Not allowed |
| Automatic access to the team's projectsEvery other role has to be invited to each project separately | Allowed | Allowed | Not allowed | Not allowed | Not allowed |
| Consumes a seat (the billable slot)Guests are the only role that does not take a seat | Allowed | Allowed | Allowed | Allowed | Not allowed |
- A seat is a slot your team pays for. Both the seat usage shown in settings and the quantity you are billed for count people who have actually joined the team and consume a seat (guests excluded). Invites that have not been accepted are not in that number — sending an invite does not by itself add to your bill.
- Sending an invite is the one place that also counts the invites still waiting, to check there is room. A team whose seats are full cannot send new ones — if every outstanding invite were accepted, the seats would overflow. Whether a seat is actually taken is decided again the moment the invite is accepted, so it can go through if someone leaves in the meantime, or be turned down if someone joins.
- ⚠️ Team members and team viewers consume a seat while having zero project access. If you add them to the team but not to any project, the team is billed for them while they see nothing at all.
- Guests do not take a seat, and in exchange their reach is narrow — only the projects they were invited to, never the team roster or the team's project list.
- A team that has never bought seats starts with 3 trial seats. That is enough to try team features out, but plan limits still follow each person's own plan.
- If the team contract expires or seat payments fall behind, the team goes read-only and every role in the team's projects drops to view-only. Reading and exporting keep working — your data is never locked away.
✓ = allowed, ✗ = not allowed. Team roles are changed in Settings → Team. Note that the columns differ from the project table — guest exists only on the team axis.
Changing a role
Project → Settings → Manage members
Open to owners and admins. The role dropdown sits next to each member in the list.
Pick a role
Switch freely between owner, member, and viewer. Note that handing your owner role to another member means you are no longer an owner.
What happens next
Permission changes take effect immediately. Affected users act under the new permissions on their next action.
Permissions are enforced, not just displayed
- Users who are not logged in cannot reach a private project.
- View-only users can see content but cannot change it.
- Only admins can change project settings or delete the project.
- A document shared through a public link can be viewed without being a project member, but not edited.
Permissions apply to the actual requests your client makes, not only to what the screen shows.
Working around the limits — safe outside collaboration
- Outside reviewer → invite as viewer → tasks, Wiki, and databases are read-only, and comments are blocked too. Chat is open, though, so it is fine to collect their feedback in a channel (if the point is to leave no trace in the documents, leave them out of the channel invite)
- Outside vendor → invite as a team guest → only the projects you name open for them, and they take no seat (the team roster and the team's project list stay hidden)
- Temporary collaborator → invite as member → demote to viewer when the work ends (instead of removing them, which preserves their authorship history)
- Public pages → see the
publish-pagesguide (paid plans — Starter, Pro, Lifetime — publish to a separate external URL) - Collecting outside responses → use a public form to take requests and feedback (no login required)