Keep your Workspace secure. Understand how permissions differ by user role, location, item, and plan. Learn how to control individual people's access to Workspace locations and items.
What you'll need
- On our Free Forever Plan, everyone who joins your Workspace can only have full access to create and edit items.
- On our paid plans, you can give members and guests specific permissions to Folders, Lists, tasks, Dashboards, Docs, Goals, and Goal Folders, and select views.
- Members and guests receive permissions based on the item and its location.
- On our Enterprise Plan, you can also set permissions on Spaces.
Types of permissions
Take a look at our article, Intro to permissions to understand the different types of Workspace and user role permissions.
How do permissions work?
Permissions are applied to locations in the Hierarchy and the items within those locations, like tasks and views.
The permissions you have to each specific item or location are determined in the following order:
Steps | Yes | No |
---|---|---|
1. Did you create the item? | You can access the item with full permissions. | Go to step 2. |
2. Do you have full, edit, comment, or view-only permissions to the item? | You can access the item with that level of permission. | Go to step 3. |
3. Are you in a Team with permission to the item? |
You can access the item with that level of permission. |
Go to step 4. |
4. Is the item private? |
You can't see or access the item. Private items are only available to the people and Teams with permission to the item. |
Go to step 5. |
5. Is the item a Space, and are you a guest? | You won't have access to this item because guests don't have access to Spaces. | Go to step 6. |
6. Do you have permission to the item based on your permissions throughout the Hierarchy? |
Your permissions to the item are inherited from the Hierarchy. For example: Each employee has a task in the Payroll List with their salary amount. Each task is shared with the employee, so they can only see their own salary. The Payroll List is private and only shared with the payroll team. The payroll team inherits full permissions to all of the Payroll List tasks because they have permissions to the Payroll List. |
You have full access to the item. For example: A task is created to fix a bug on the mobile app. No permissions are set on the task, the Bug List, the Mobile app team Folder, or the Engineering Space. The task, List, Folder, and Space are not private. Everyone (except for guests) has full access to the bug task.
If the Engineering Space is private, you'll only have access to the bug task if:
|
Conflicting permissions
It's possible to have different permissions for the same location. In this case, permissions set on the most specific level of the Hierarchy are applied. Here are some examples of how this works:
Permissions on tasks override Lists and permissions on Lists override Folders.
For example: You have full permissions for a List. You have view-only permissions for a task in that List. For that task only, the task's view only permissions are applied rather than the List's full permissions because the task permissions are more specific.
Permissions for individual people override permissions for Teams when permissions are given at the same level of the Hiearchy.
Here is the difference between the two types of permissions:
- Permissions for individual people: Permissions given to a person when an item or location is shared with them.
- Team permissions: Permissions given to an entire team when an item or location is shared with them.
For example: You have full permissions for a List and belong to a Team with comment permissions on that List. You have full permissions for the tasks in the List because your individual permissions override your Team permissions for that List.
If you were individually given comment permissions for one task in the List, you would have full permissions for the other tasks and comment permissions for that one. In this case, the task is more specific than the List.
Team permissions can override individual permissions if the Team permissions are at a more specific level of the Hiearchy than your individual permissions.
For example: You have comment permissions for a Folder and belong to a team with full permisions to a List in that Folder. You have full permissions for the tasks in the List, because your Team permissions are set at the List level. The List level is more spcific than your Folder level permissions.
For tasks in multiple Lists, full overrides edit, edit overrides comment, and comments overrides view-only permissions.
For example: A task is added to two separate Lists. You have view only permissions to one of the Lists, and comment permissions to the other List. You inherit the highest-level permission, and you can comment on the task.
How are permissions applied?
The view only, commment, edit, and full permissions are applied differently based on the item, location, and user role.
For example, the edit permissions on a Folder allow members to share that Folder. And guests can't share anything, even with edit permissions.
By default, creators of Spaces, Folders, Lists, and tasks cannot have these permissions edited by others.
Click the links in the following table for more detailed information on each location, item, and user role:
Location or item | User role |
---|---|
Tasks | Members Guests |
Folders | Members Guests |
Lists | Members Guests |
Spaces |
Members Space permissions for members is only available on the Enterprise Plan. |
Dashboards | Members Guests (always view only) |
Docs | Everyone |
Goals and Goal Folders | Everyone |
Protect and unprotect views | Everyone except guests |
Chat |
Everyone Some Chat Channels are location-based. These Channels and their locations share permissions and sharing. When someone is given access to a location, they are also given access to its Channel and vice versa. |
Chat view is only available if the Chat ClickApp is disabled. |
Everyone |
Embed view | Everyone except guests |
Form view | Everyone except guests |
Doc view | Everyone |
Tasks
What you can and can't do with tasks varies by user role.
Subtasks and nested subtasks inherit their primary parent task's permissions.
Members, owners, and admins
Member, owner, and admin permission level By default, members, owners, and admins have full permissions to all public items and locations. |
Description |
---|---|
Full |
Members with Full access can Can edit and delete a task. Can perform all of the following actions. |
Edit |
Members with Edit access can Can merge, move, print, convert to List, add to another List, add to Favorites, add to LineUp, use templates, and archive the task. Can share tasks with others, including guests. Can publicly share tasks. Can only give others edit, comment, or view-only permissions. Can add, change, and remove assignees. Can create and add tasks to Relationships. Can view Relationships linked to any tasks they have permission to access.
Members with Edit access can't Can't create or delete tasks or subtasks. |
Comment |
Members with Comment access can Can comment, copy task links and IDs, print, attach emails and files, and add to Favorites and LineUp. Can react with emoji, assign and resolve their own assigned comments, and complete assigned checklist items. Can share tasks with others, including guests. Can publicly share tasks. Can only give others comment- or view-only permissions. Assignees can change the task status, add other assignees, or remove themselves as the task assignee. Members with Comment access can't Can't create, edit, delete, or track time within tasks or subtasks. |
View only |
Members with View only access can Can view tasks, copy links and IDs, print, and add to Favorites and LineUp. Members with View only access can't Can't create, edit, or delete tasks or subtasks. Can't comment on or edit tasks. |
Guests
Guest Permission level | Description |
---|---|
Full |
Guests with Full access can Can duplicate, move, and merge tasks. Can convert tasks to Lists or subtasks, archive and delete tasks. Can add to Favorites, use templates, add comments. Can add, change, and remove assignees, edit, assign, resolve, and delete their own comments, assign and resolve other people's comments. Can view, edit, and print the task description. Can restore the task description from the history. Can create and add tasks to Relationships. Can view Relationships linked to any tasks they have permission to access.
Guests with Full access can't Can't manage Custom Fields for this task's List. Can't share the task. |
Edit |
Guests with Edit access can Can merge and move tasks. Convert tasks to Lists. Can add to Favorites, use templates, and archive the task. Can view, edit, and print the task description. Can restore the task description from the history. Can add, change, and remove assignees, and add comments. Can edit, assign, resolve, and delete their own comments, assign and resolve other people's comments. Can create and add tasks to Relationships. Can view Relationships linked to any tasks they have permission to access.
Guests with Edit access can't Can't create tasks, subtasks, or convert a task to a subtask. Can't delete the task. Can't perform any other actions. |
Comment |
Guests with Comment access can Can copy links and task IDs, print, attach emails, and add to Favorites. Can download task attachments. Can add comments, edit, assign, resolve, and delete their own comments, resolve and reassign comments they've been assigned. Assignees can change the status and set assignee(s) on the tasks they're assigned to. Can view Relationships linked to any tasks they have permission to access.
Guests with comment access can't Can't edit the task. Can't perform any other actions. |
View only |
Guests with View only access can Can view tasks, copy links and IDs, print the task, add to Favorites. Can view Relationships linked to any tasks they have permission to access.
Guests with View only access can't Can't add comments. Can't perform any other actions. |
Folders
What you can and can't do with a Folder varies by user role. Workspace owners and admins have the same permission options as members.
Members
Member, owner, and admin permission level By default, members, owners, and admins have full permissions to all public items and locations. |
Description |
---|---|
Full |
Members with Full access can Can create tasks in this Folder. Can edit Folder settings and delete the Folder. |
Edit |
Members with Edit access can Can edit tasks in this Folder and Folder settings. Can share Folders with others, including guests. Members with Edit access can't Can't create tasks or delete the Folder. |
Comment |
Members with Comment access can Can comment on Tasks in this Folder. Assignees can change the status and set assignee(s) on the tasks they're assigned to in this Folder. Members with Comment access can't Can't edit Folder settings. |
View only |
Members with View only access can Can view items in this Folder, and share Folders with others, including guests. Members with View only access can't Can't comment or edit on tasks in this Folder, or edit Folder settings. |
Guests
Guest Permission level |
Description |
---|---|
Full |
Guests with Full access can Can create tasks in this Folder, copy Folder links, and add to Favorites. Guests with Full access can't Can't edit Folder settings. |
Edit |
Guests with Edit access can Can edit, copy Folder links, and add to Favorites. Guests with Edit access can't Can't create tasks in this Folder or edit Folder settings. |
Comment |
Guests with Comment access can Can comment, copy links, and add to Favorites. Assignees can change the status and set assignee(s) on the tasks they're assigned to in this Folder. Guests with Comment access can't Can't edit Folder settings. |
View only |
Guests with View only access can Can view items in this Folder, copy links, and add to Favorites. Guests with View only access can't Can't comment or edit on tasks in this Folder, or edit Folder settings. |
Lists
What you can and can't do with a List varies by user role. Workspace owners and admins have the same permission options as members.
Members, admins, and owners
Member, admin, and owner permission level By default, members, owners, and admins have full permissions to all public items and locations. |
Description |
---|---|
Full |
Members with Full access can Can create tasks in this List, edit List settings, and delete the List. |
Edit |
Members with Edit access can Can edit tasks in this List and List settings. Can share Lists with others, including guests. Members with Edit access can't Can't create tasks or delete the List. |
Comment |
Members with Comment access can Can comment on tasks in this List. Can view List Info, copy links, and add to Favorites. Assignees can change the status and set assignee(s) on the tasks they're assigned to in this List. Members with Comment access can't Can't edit List settings. |
View only |
Members with View only access can Can view this List, List Info, copy links, and add to Favorites. Members with View only access can't Can't comment, edit tasks in this List, or edit List settings. |
Guests
Guest Permission level | Description |
---|---|
Full |
Guests with Full access can Can create tasks, copy links, edit List Info, and add to Favorites. Guests with Full access can't Can't edit List settings. |
Edit |
Guests with Edit access can Can edit tasks, copy links, edit List Info, and add to Favorites. Guests with Edit access can't Can't edit List settings. |
Comment |
Guests with Comment access can Can comment, copy links, view List Info, and add to Favorites. Assignees can change the status and set assignee(s) on the tasks they're assigned to in this List. Guests with Comment access can't Can't edit List settings. |
View only |
Guests with View only access can Can view this List, copy links, view List Info, and add to Favorites. Guests with View only access can't Can't comment, edit tasks, or edit List settings. |
Spaces
On the Enterprise Plan, you can give individual members Space permissions. Guests cannot have Spaces shared with them.
Members, admins, and owners
Member, admin, and owner permission level By default, members, owners, and admins have full permissions to all public items and locations. |
Description |
Full |
Members with Full access can Can create or delete Lists and Folders in the Space. Can share the Space with others. Members with Full access can't Can't delete the Space or edit Space settings unless they created the Space. |
Edit |
Members with Edit access can Can view this Space, copy links, and add the Space to Favorites. Can archive Lists or Folders in the Space. Members with Edit access can't Can't create or delete Lists or Folders in the Space. Can't share the Space with others. |
Comment |
Members with Comment access can Can comment on tasks that live in Lists in the Space. Can view List Info of Lists in the Space. Can view this Space, copy links, and add the Space to Favorites. Assignees can change the status and set assignee(s) on the tasks they're assigned to in Lists that live in the Space. Members with Comment access can't Can't edit Space settings. Can't archive Lists or Folders in the Space. |
View only |
Members with View-only access can Can view this Space, copy links, and add the Space to Favorites. Members with View-only access can't Can't comment or edit tasks that live in Lists in this Space. Can't edit Space settings. |
Views
User Role |
Description |
Members, admins, and owners |
Can access public views. Can access private views shared with them. Can create views. |
Guests |
Can access public views of items shared with them. Can access private views shared with them. Can create views if they have been given individual guest permissions. |
Protect and unprotect views
There are two permission options related to protecting views:
- Can protect and unprotect view: Can protect this view and unprotect it to save changes.
- Can't unprotect view: Can't save changes to this view.
Chat
Hierarchy locations and their Chats share permissions and sharing. When a member is given access to a location, they are also given access to the Chat and vice versa. Guests cannot access Chat.
Chat view
If the Chat ClickApp is disabled in your Workspace, you can use Chat view.
You can set unique permissions that just apply to a Chat view.
- Can manage chat: Can edit settings and delete this view.
-
Can't manage or delete chat: Can view, add comments, copy, and add to Favorites.
Can't edit settings or delete this Chat view.
Embed view
You can set unique permissions that just apply to an Embed view.
- Can manage Embed view: Can edit view settings and delete this view.
-
Can't manage Embed view: Can view, copy, and add to Favorites.
Can't edit settings or delete this view.
Form view
You can set unique permissions that just apply to a Form view.
- Can edit and manage Form: Can edit Form fields, Form and view settings, and delete this view.
-
Can't edit or manage Form: Can view, submit, copy, and add to Favorites.
Can't edit Form fields, Form or view settings, or delete this view.
Doc view
You can set permissions to a Doc shared as a Doc view. Permissions set on a Doc view also apply to the Doc itself.
Permission level | Description |
---|---|
Edit |
Members, admins, owners, and guests with Edit access: Can edit Doc, edit Doc and view settings, and delete this view. Can share Docs with others, including guests. |
Comment |
Members, admins, owners, and guests with Comment access: Can view, add, edit, and delete their own comments. Can copy the view and add to Favorites. Members, admins, owners, and guests with Comment access: Can't edit Doc, view or Doc settings, or delete this view. |
View only |
Members, admins, owners, and guests with View-only access: Can view this Doc Can see Doc history Members, admins, owners, and guests with View-only access: Can't edit Doc, add comments, edit view or Doc settings, or delete this view. |
Dashboards
What you can and can't do with Dashboards varies by user role. Workspace owners and admins have the same permission options as members.
Members
Member, owner, and admins permission level By default, members, owners, and admins have full permissions to all public items and locations. | Description |
---|---|
Full |
Members with Full access can Can add, edit, and delete cards. Can edit settings and delete this Dashboard. |
Edit |
Members with Edit access can Can add, edit, and remove cards. Can share Dashboards with others, including guests. Members with Edit access can't Can't delete the Dashboard. |
View only |
Members with View-only access can Can view this Dashboard. Can comment, edit and delete their own comments in Discussion cards. Members with View-only access can't Can't add, edit, or delete cards. Can't edit or delete this Dashboard. |
Guests
There is only one Dashboard permission option available for guests.
View only: Can view this Dashboard. Cannot comment on Discussion cards in the Dashboard.
Guests must be given access to the tasks, Lists, or Folders referenced in Dashboard cards to see all data.
Docs
Permissions set on Docs also apply when Docs are shared as a view or in the Sidebar.
Permission level | Description |
---|---|
Edit |
Members with Edit access can Can edit the Doc, Doc settings, and delete the Doc. Can share Docs with others, including guests. They can also publicly share Docs and pages. Guests with Edit access can Can edit the Doc, Doc settings, and delete the Doc. Can't share Docs with others. |
Comment |
Members and guests with Comment access can Can view the Doc, add, edit, and delete their own comments. |
View only |
Members and guests with View-only access can Can view the Doc. Members and guests with View-only access can't Can't edit doc, add comments, edit Doc settings, or delete the view. |
Goals and Goal Folders
You can set unique permissions that just apply to Goals and Goal Folders.
Permission level | Description |
---|---|
Edit |
Members and guests with Edit access can Can create, edit, move, and delete goals. Can share Goals with others, including guests. |
View only |
Members and guests with View-only access can Can't create, edit, move, or delete goals. |
Conflicting permissions
- Task-level permissions override List level permissions, which override Folder and Space level permissions.
- For example: Sam has view only permissions to a private task. They have comment permissions to the private List where the task lives. Sam has view only access to that specific task, and comment permissions to the other tasks in the List.
- Permissions set for a specific person always override Team permissions.
- For example: A private task is shared with Alex (view only) and Team A (comment). Alex is a member of Team A. Alex has view only permissions to the private task.
- Create & Edit (full) permissions override can edit permissions, which override can comment, which override can view permissions.
Team permissions
Doc permissions
Permissions for Tasks in Multiple Lists
Permissions when sharing private items
Example of permissions logic
- Alex isn't the task owner. If they were, they would get full permissions.
- Alex doesn't have individual permissions to the task.
- Alex isn't a member of a team with permissions to the task.
- The task isn't private.
- Alex isn't the List owner.
- Alex doesn't have individual permissions to the List.
- Alex isn't a member of a team with access to the List.
- The List isn't private.
- Alex isn't the Folder owner.
- Alex doesn't have individual permissions to the Folder.
- Alex isn't a member of a team with access to the Folder.
- The Folder isn't private.
- Alex isn't the Space owner.
- Alex doesn't have individual permissions to the Space.
- Alex isn't a member of a team with access to the Space.
- The Space isn't private.
- Alex is not a guest.