Workspace roles and permissions
What Owner, Admin, and VA / Team Member can each do, and which roles are retired.
Every workspace member holds one role. It decides what they can see and change across the whole workspace.
There are three live roles. Two older ones are retired and can no longer be assigned.
Owner
The person who created the workspace and pays for it. One per workspace.
Full control:
- Billing, and the number of seats
- Changing anyone's role
- Inviting and removing members
- Every project in the workspace
- Team dashboards, timesheets, and reports
- Turning time tracking on or off per member
- Deleting the workspace
The Owner's role cannot be changed, the Owner cannot be removed, and the Owner cannot leave. To step away, delete the workspace.
Admin
Runs the workspace day to day, without control of the money.
Can:
- See every project in the workspace
- Create, rename, and delete projects
- Assign members to projects
- Invite and remove members
- Run team dashboards, timesheets, and reports
- Turn time tracking on or off per member
- Track their own time
Cannot:
- Change anyone's role: Owner only
- Manage billing or seats: Owner only
- Delete the workspace
Uses one paid seat.
VA / Team Member
The working role, for the people delivering client work.
Can:
- See and work on the projects they are assigned to
- Add, edit, and complete tasks on those projects
- Comment
- Track their own time, and see their own history
Cannot:
- See projects they are not assigned to
- Create or delete projects
- Invite, remove, or reassign anyone
- See other people's time, timesheets, or reports
Uses one paid seat.
Side by side
| Owner | Admin | VA / Team Member | |
|---|---|---|---|
| See every workspace project | Yes | Yes | Assigned only |
| Create and delete projects | Yes | Yes | No |
| Assign members to projects | Yes | Yes | No |
| Invite and remove members | Yes | Yes | No |
| Change member roles | Yes | No | No |
| Manage billing and seats | Yes | No | No |
| Team dashboard and analytics | Yes | Yes | No |
| Team timesheets and reports | Yes | Yes | No |
| Toggle a member's time tracking | Yes | Yes | No |
| Track their own time | Yes | Yes | Yes |
| Delete the workspace | Yes | No | No |
| Uses a paid seat | Yes | Yes | Yes |
Retired roles
Two roles existed previously and can no longer be assigned. They are shown marked (legacy) wherever an old record still uses one.
Manager (legacy)
Existing members keep the access they have. To retire the record, change them to Admin or VA / Team Member.
Client Guest (legacy)
Also retired. Clients now reach their work through per-project sharing rather than a workspace seat.
Moving a legacy Client Guest onto a live role turns it into a paid seat, so a seat must be free first.
Role vs project assignment
Two separate questions:
- Your role decides what you can do across the workspace.
- Project assignment decides which projects a VA / Team Member can see at
all.
An unassigned team member has a role but no projects. Owners and Admins bypass assignment and see everything.
See Workspace projects.
Enforced on the server
The interface hides controls you cannot use, but that is presentation. Every one of these rules is checked again on our servers before anything changes.
