WHOWORKEDDOCS

Team and permissions

Invite members, assign roles, and keep project and client access aligned with responsibility.

Workspace roles define broad responsibility. Manager scope and project access narrow what a person can manage or see. Use the smallest access that lets each member do their work.

Understand the standard roles

  • Owner: Controls the workspace and owner-only operations. Keep this role limited and make sure the workspace never depends on one unavailable person.
  • Admin: Manages workspace-wide configuration and operational access without owning the workspace.
  • Manager: Oversees selected projects or clients according to manager grants.
  • Member: Records and reviews work within the access available to them.
  • Viewer: Reads workspace records but cannot create or edit time entries.

Plan entitlements can affect which permission options are available. The role selector in your workspace is the source of truth for the choices you can assign.

Invite a member

  1. Open Team.
  2. Select the invite action.
  3. Enter the member's work email.
  4. Choose the lowest suitable role.
  5. Configure project access and, for managers, client or project grants when required.
  6. Send the invitation.

After the member accepts, confirm that they can open the projects they need and cannot open restricted work.

Configure managers

A manager receives authority through explicit client or project grants. Use a project grant for a delivery lead and a client grant for an account lead who needs authority over every project attached to that client.

Revisit manager scope when projects are created. A new project may not be included automatically in an intentionally limited assignment.

The Team area is available to managers, admins, and owners. Managers can invite members and viewers only within the projects covered by their own scope.

Review member activity

Open an individual team member to review their overview, time entries, and available audit history. Use this for operational correction and access review, not surveillance. The goal is a trustworthy work record and clear responsibility.

Change access safely

Before increasing a role, name the operation the person needs to perform and check whether narrower project or manager scope solves it. Before reducing or removing access, transfer any ownership or recurring review responsibility they hold.

When someone leaves the workspace:

  1. Stop or reassign active operational responsibility.
  2. Review running timers and incomplete work.
  3. Revoke integrations or personal credentials tied to their access.
  4. Preserve the historical work record.
  5. Remove current access according to your offboarding process.

Run a regular access review

At least quarterly, review owners, admins, managers, pending invitations, project access, API keys, OAuth applications, and personal access tokens. Record why exceptional access still exists.

Continue with data quality and governance for review and period-close practices.

On this page