Permissions Management in awork

Control who can view and edit what. Learn here how to manage permissions efficiently.


Key benefits and use cases

  • Simple role management: Understand who has access to what.
  • Clear structure: General and project roles define specific access rights.
  • Flexibility: Customize permissions to fit your team's needs.

Permissions management in awork is based on two levels:

  1. General permission roles (workspace level): Applies to your entire awork workspace.
  2. Project roles (project level): Applies only to specific projects where a user is a member.

Accessing permissions management

  1. Navigate to Settings (gear icon in the bottom left of the main menu).
  2. Click on Permissions Management.

Only users with the Admin role can configure these settings.


General permission roles

  • Each person in the workspace has a general permission role (e.g., Admin or User)
  • Important: If a user is not a project member, only the rights of the general role apply.

Creating a general role

  1. In the General Permission Roles section, click on + Role.
  2. Give it a name and choose either a blank role or a template.
  3. Customize the individual permissions.

Pre-configured roles

  • Admin: Full access and can manage workspace settings.
  • User: Can work with projects but cannot change central settings.

Set menu visibility per role

In the details of a permission role, you'll find the Menu Visibility tab, where you can specify which areas of the menu are visible.

Important: If the eye icon is disabled, the role lacks the necessary permissions.

Assigning general roles

At the bottom of the Permissions Management page, you'll find a list of all users where you can assign a role to each person.

Note: You cannot remove yourself from the Admin role.


Managing project roles

Project roles define specific rights at the project level.

Important: Project roles can extend permissions, but cannot restrict them. Restrictions are always controlled through the general role.

Creating a project role

  1. In the Project-Specific Permission Roles section, click on + Role
  2. Give it a name and set the view and edit rights.

Optional: Mark the role as Default Role so it's pre-selected when adding members to projects.


Editing or deleting a role

In the role overview, you can edit or delete roles using the action button.

Important: System roles like Admin and Guest cannot be edited or deleted. When deleting a role that's already assigned to users, you must select a replacement role.


Permissions in detail

Create project

Active

Users can create projects.


Inactive

Users cannot create projects.


Important: The project creator always has all rights on that project.

Project details

Manage

  • see all projects in the project overview

  • view and edit project details of all projects

  • delete projects

Read

  • see all projects in the project overview

  • view project details of all projects

None

  • only see projects you're a member of

Project tasks

Manage

  • view, edit, create, and delete tasks in all projects

  • use task templates within projects

Read

  • view tasks in all projects

  • no editing of task details (including no comments)

None

  • no general view of project tasks (except through project membership and project role)

Project times

Manage

  • view, edit, and delete times from all projects

  • see aggregated times for project/task progress

Read

  • view times from all projects

  • see aggregated times for project/task progress

None

  • no general view of project times (except through project membership and project role)

  • no aggregated times for project/task progress

Users

New users can only be created by Admins.

User details

Manage

  • view overview and details of all users

  • activate or deactivate users

  • edit users

Read

  • view overview and details of all users

None

  • no overview/details visible

  • only people with whom you share projects are visible (e.g., for mentioning or assigning)

User times

Manage

  • view and edit all tracked times of other users (even without project relation)

Read

  • view all tracked times of other users (even without project relation)

None

  • no general view of other users' times (except through project membership, project roles, or general rights to project times)

Customers

Customer details

Manage

  • view, edit, and delete all customers

  • create new customers

Read

  • view customer overview and details

  • customers are available when creating new projects

None

  • no access to customer overview and details

Settings

Project settings

  • create and manage project templates and project types

Task settings

  • create, edit, and delete activities and task templates (also in project templates)

General settings

  • manage workspace settings (e.g., name, logo, URL)

  • manage integrations

  • manage time tracking settings

Note: The workspace can only be deleted by Admins.


Tips & hints

Please note:

  • Project roles only extend permissions, they cannot remove rights.

  • You cannot remove yourself from the Admin role.

  • Project creators always retain full rights on their projects.

Tip: Access to only specific projects

If users should have access to only selected projects, we recommend this approach:

  • In the general role, keep cross-project rights (e.g., view of all projects/project tasks/project times) restrictive.

  • Then specifically add the person as a project member and give them the needed rights in that specific project via the project role.


FAQ

Is it possible for users to only see their own projects and tasks?

Yes. You can configure a general role so that users only see projects they're a member of.

Is there a setting so users fundamentally cannot track time?

Yes. Admins can disable time tracking for the entire workspace under Settings > Workspace. This is available starting with the Professional Plan.

Who can delete projects?

Users who are allowed to manage project details (in the general role and/or via project role) can delete projects. Additionally, each user can delete projects they created themselves at any time.

Do the permissions also apply in the API?

Yes, the permissions configured in permissions management also apply to access via the awork API.

Last updated HappySupportPowered by happysupport.ai
© 2026 HappySupport. All rights reserved.