Appearance
Roles and permissions
Permission in Truetask comes from two places. Your workspace role decides what you can do across the whole instance. Your board role decides what you can do on one board. Both are checked on every action, so the narrower of the two always wins.
Workspace roles
Every person has exactly one workspace role: Owner, Admin, Lead, User or Guest. Set it in Settings > Members & Teams > User Directory.
| Capability | Owner | Admin | Lead | User | Guest |
|---|---|---|---|---|---|
| Open Settings | yes | yes | yes | no | no |
| Manage integrations | yes | yes | no | no | no |
| Manage backups | yes | yes | no | no | no |
| Edit AI prompts | yes | yes | no | no | no |
| Invite people | yes | yes | yes | no | no |
| Manage teams | yes | yes | yes | no | no |
| Create a board | yes | yes | yes | yes | no |
| Edit a board | yes | yes | yes | yes | no |
| Delete a board | yes | yes | yes | own boards | no |
| Share a board | yes | yes | yes | own boards | no |
| Open a board | yes | yes | yes | yes | yes |
| Create a task | yes | yes | yes | yes | no |
| Edit a task | yes | yes | yes | yes | no |
| Comment | yes | yes | yes | yes | no |
A User who created a board can delete it and share it, even though the role alone does not grant those two. Any board they did not create stays read-through-board-role.
A Guest can open the boards they were added to and nothing else: no task creation, no editing, no comments.
Only owners and admins change roles
A role change is rejected unless the request comes from an Owner or an Admin. Only the Owner can hand ownership to someone else, and doing so makes the previous owner an Admin.
Board roles
A board has one owner, its creator, plus a role per member. Set them in the Share dialog on the board.
| Board role | What it means |
|---|---|
| Owner | Owns the board. It is the person who created it, and they are always a board admin. |
| Admin | Can change board settings and manage members. |
| Editor | Can add, edit, and delete tasks on the board. |
| Viewer | Can view tasks but can't add, edit, or comment. |
Three rules fill in the gaps:
- A workspace Owner or Admin is a board admin on every board, whether or not they hold a role there.
- The board's creator is always a board admin.
- A member added without an explicit role is an Editor.
Board admin is what gates the board-level configuration: Board flow, Custom fields, Agent workflows, the board's webhooks and the Automations view. Non-admins never see the Automations tab at all.
See Sharing a board and Members, roles and teams.
What each settings pane needs
Settings is grouped into six sections, and each section has its own role floor. A Lead opens Settings straight onto Members & Teams, because that is the only section they can see.
| Section | Roles | Panes |
|---|---|---|
| Site | Owner, Admin | Health, Plan, License |
| General | Owner, Admin | Workspace, Board statuses, Custom Fields, Uploads, Network, Unsplash, Board Templates, Automations, Archived boards |
| Members & Teams | Owner, Admin, Lead | User Directory, Agents, Teams |
| Audit & Security | Owner, Admin | Audit Log, Active Sessions |
| Integrations | Owner, Admin | AI, API Tokens, Webhooks, Git Provider |
| Server | Owner, Admin | SMTP, OAuth2, Active Directory, Backups, S3 Storage, Data Retention, Logs, Export |
Which panes appear also depends on where your workspace runs.
Self-hosted only
License, Network, SMTP, Backups, S3 Storage, Data Retention and Unsplash exist only on self-hosted instances.
Truetask Cloud only
Plan is the Truetask Cloud pane, and it replaces License. A pane your plan does not include shows a crown icon. See Plans and billing.
Who can manage what
| Thing | Who |
|---|---|
| Webhook subscriptions and incoming endpoints | Workspace Owner or Admin, and the workspace needs outgoing webhooks on its plan. |
| Connected integrations | Anyone can look at the Integrations dialog; connecting one needs Owner or Admin. |
| Git provider connection | Owner or Admin. Linking a repository to a board also needs board admin on that board. |
| AI provider and models | Owner or Admin. |
| AI prompts | Owner or Admin, on self-hosted instances only. |
| Backups, S3 storage, data retention | Owner or Admin, on self-hosted instances only. |
| API tokens and the MCP connector | Everyone, for their own tokens. Each token carries the access of the person who made it. |
| Agent accounts across the workspace | The Agents pane in Settings > Members & Teams opens for Owner, Admin and Lead; disabling or deleting somebody else's agent needs Owner or Admin. |
| Timesheets and approvals | Owner, Admin or Lead. |
| Overseer | Owner or Admin. |
An outgoing webhook created by a Lead or a User only keeps receiving a board's events while that person is still a member of the board. A webhook created by an Owner or an Admin is workspace-wide. See Webhooks.
Notes
Notes and note folders follow the board by default: anyone who can see the board can read them, and anyone who can edit the board can write them.
Manage access on a note or a folder restricts that instead. Each person you add gets Can view or Can edit; everyone else gets No access. Restricting a folder restricts everything inside it.
Four people always keep access to a restricted note, whatever the list says: whoever created it, the board's owner, and any workspace Owner or Admin. A restricted note you cannot see is simply not there for you; Truetask never says that it exists.
See Note permissions and Publishing notes.
Agents
Agents are accounts too, with two hard limits:
- An agent can never hold the Owner or Admin workspace role.
- An agent can never change its own guardrails, its own webhook wiring, or how many tasks it may work at once, even using its own token.
Everything else about an agent belongs to its owner, the person who created it. A workspace Owner or Admin who does not own an agent gets the kill switch only: they can disable it or delete it from Settings > Members & Teams > Agents, but not rename it or loosen its permissions.
Guardrails live under Has permission to on the agent's profile and cover four destructive actions plus web access: Complete, Archive, Delete, Merge PRs and Read the web. Powers are the other half: External access, Local access and Auto-start.
An agent's access to a board is board membership like anyone else's, so assigning a task to an agent that is not on the board does not let it see the board.
See Creating an agent and Delegating work.

