Skip to content
Workspace & team

Roles and permissions

Three roles inside a workspace, and one entirely separate axis for the vendor.

Last updated 1 min readFor workspace admins

The general rule: reads open, writes gated

The product's default is that everything inside a workspace is readable — feeds, engagements, documents, the catalogue. A firm that hides information from itself is a firm with no memory.

What is restricted is writing, in two forms: some writes require membership of that engagement's team, and some require the workspace admin role.

There are two exceptions to "reads are open", and both are deliberate: meetings, and restricted documents.

Who does what

MemberWorkspace adminOwner
Read feeds, engagements, documents
Write on their own engagements
Review a document
Edit the catalogue and stage labels
Invite and manage users
See the settings area
Control what the assistant may do
Change other people's roles
Hand over ownership

A workspace owner does not work for us

There is a second, entirely separate axis: platform staff, the team that operates the installation.

The two never merge: a workspace owner has no access to any other workspace, and platform staff with no membership see no content from yours.

Why buttons are sometimes absent

The interface does not decide for itself what to show; it asks the server what this user can do to this record, and puts the button there or leaves it out accordingly.

The result is that you never see a button that errors when pressed — and if a button is missing, the reason is permission rather than a fault.

Still stuck?

If the answer wasn't here, write to us. It is a real inbox and it gets answered.

Talk to us