Permissions & access

Two things decide what someone can reach: their workspace role and the projects they have been given access to. They are separate on purpose.

The one rule to remember

Managing the workspace is not the same as seeing its work. An Admin runs the workspace — people, billing, settings — and still only opens the projects they were invited to. Being an Admin does not quietly hand someone every project.

Workspace roles

RoleCan manageCan see
OwnerEverything, including billing and rolesEvery project. The only role that can.
AdminPeople, billing, workspace settingsOnly the projects they were invited to
MemberProjects they create or manageOnly the projects they were invited to

An Owner can change anyone's role from Members. Nobody can change their own, and an Admin cannot promote anyone — a role change is how access is granted, so it stays with the Owner.

Project access

Every project has a Who can access setting, in the project's Access dialog. It is the whole answer to "who can open this":

  • Only people invited — the default. Private. Nobody sees it until you add them.
  • Everyone in the workspace — can view — anyone in your workspace can find it and read the threads.
  • Everyone in the workspace — can edit — anyone in your workspace can also comment and resolve.

New projects start private. Connected GitHub repositories are different: a repo you connect is shared with the workspace by definition, so its threads are visible to your members.

Inviting someone to one project

Open the project's Access dialog and add them with one of three levels:

  • Can view — read threads and comments
  • Can edit — comment, reply and resolve
  • Can manage — also rename the project, add repos and invite others to it

Note

Can manage applies to that project only. It is how you let someone run one project without giving them anything else in the workspace. It is not the same as a workspace Admin.

Checking who can actually see a project

The Access dialog lists everyone you invited, and underneath, an Also has access section for anyone who can open the project without an invitation — the workspace Owner, the person who created it, or everyone in the workspace if you shared it that way. If that section is empty and the list shows one name, exactly one person can open it.

Common questions

I invited someone to one project and they can see everything.

Check their workspace role under Members. Owners can open every project. If they are an Owner or Admin and should not be, change them to Member — the invitation you gave them keeps working, and they will only see that project.

Someone cannot see a project I invited them to.

They need to be in the workspace first, then invited to the project. Being in the workspace alone does not give access to a private project.

Can I let someone manage a project without giving them the whole workspace?

Yes — that is exactly what Can manage on the project is for. Leave their workspace role as Member.

Ready to start reviewing on the real product?

Install the free Chrome Extension, connect your tools, and start shipping faster — in under a minute.

No seat fees. Every team member is free — designers, developers, PMs, stakeholders.