Roles, permissions and apps in a workspace
A workspace has four roles — owner, admin, member and guest. Owners and admins can do everything; what members and guests can do is set per app: view, create, edit, delete and approve are decided separately for each module.
- Owner: full control, including transferring ownership and deleting the workspace.
- Admin: every app and every action, plus managing the team.
- Member: the normal working role, governed by each app's permissions.
- Guest: view-only access to projects, tasks, files, notes and the calendar — no members list and no editing. Use it for an accountant, a contractor or a client-side contact.
People join by invitation with the role you choose, and they see the workspace only after accepting. Only admins can change roles or remove people, and the owner cannot be removed.
Apps
The core apps are installed automatically: projects, tasks, files, notes, calendar, members, activity, clients, the public page and meetings. CRM, inventory, HR and finance are optional — owners and admins add or remove them in workspace settings under Manage apps.
Adding an app does not open it to everybody. Each app comes with its own role defaults — switching on HR or finance gives members view-only access until you change it. Check the defaults when you add something sensitive.
HR permission controls the hiring pipeline: applications to your job posts, with candidate details, are visible to owners, admins and people with HR permission.