Permission Management in awork
Manage workspace and project permission roles in awork Settings to control who can access, edit, and view your projects and customize menu visibility per role
Control who can see and edit what. Learn here how to manage permissions efficiently.
Key Benefits and Use Cases
- Simple role management: Understand who has access to what.
- Clear structure: General and project roles define specific access rights.
- Flexibility: Tailor permissions to your team's needs.
Permission management in awork is based on two levels:
- General permission roles (workspace level): Applies to your entire awork workspace.
- Project roles (project level): Applies only to specific projects where a user is a member.
Accessing Permission Management
- Navigate to Settings (gear icon in the bottom left of the main menu).
- Click on Permission Management.
Only users with the Admin role can configure these settings.
General Permission Roles
- Every person in the workspace has a general permission role (e.g., Admin or User)
- Important: If a user is not a project member, only the rights of the general role apply.
Creating a General Role
- In the General Permission Roles section, click + Role.
- Give it a name and choose either a blank role or a template.
- Customize the individual permissions.
Pre-configured Roles
- Admin: Full access and can manage workspace settings.
- User: Can work with projects but cannot change central settings.
Setting Menu Visibility per Role
In the details of a permission role, you'll find the Menu Visibility tab, where you can specify which areas of the menu are visible.
Important: If the eye icon is disabled, the role lacks the necessary permissions.
Assigning General Roles
At the bottom of the Permission Management page, you'll find a list of all users where you can assign a role to each person.
Note: You cannot remove yourself from the Admin role.
Managing Project Roles
Project roles define specific rights at the project level.
Important: Project roles can expand permissions, but cannot restrict them. Restrictions are always controlled through the general role.
Creating a Project Role
- In the Project-Specific Permission Roles section, click + Role
- Give it a name and set the view and edit rights.
Optional: Mark the role as a Default Role so it's pre-selected when adding members to projects.
Editing or Deleting a Role
In the role overview, you can edit or delete roles using the actions button.
Important: System roles like Admin and Guest cannot be edited or deleted. When deleting a role that's already assigned to users, you must select a replacement role.
Permissions in Detail
Create Project | Active Users can create projects.
Users cannot create projects.
|
Project Details | Manage
Read
None
|
Project Tasks | Manage
Read
None
|
Project Time | Manage
Read
None
|
Users
New users can only be created by Admins.
User Details | Manage
Read
None
|
User Time | Manage
Read
None
|
User Planning | Manage
Read
None
|
Clients
Client Details | Manage
Read
None
|
Settings
Project Settings |
|
Task Settings |
|
General Settings |
Note: The workspace can only be deleted by Admins. |
Tips & Notes
Please keep in mind:
-
Project roles only expand permissions, they cannot restrict rights.
-
You cannot remove yourself from the Admin role.
-
Project creators always retain full rights on their projects.
Tip: Access to Specific Projects Only
If you want users to have access to only selected projects, we recommend the following approach:
-
Keep cross-project rights (e.g., visibility of all projects/project tasks/project time) restrictive in the general role.
-
Then add the person as a project member and grant the needed rights in that specific project through the project role.
FAQ
Is it possible for users to only see their own projects and tasks?
Yes. You can configure a general role so that users only see projects they're a member of.
Is there a setting so users generally cannot track time?
Yes. Admins can disable time tracking for the entire workspace under Settings > Workspace. This is available starting with the Professional Plan.
Who can delete projects?
Users who have permission to manage project details (in the general role and/or through project role) can delete projects. Additionally, every user can delete projects they created themselves at any time.
Do the permissions also apply in the API?
Yes, the permissions configured in permission management also apply to access through the awork API.
