Skip to content

Roles and permissions

Permission in Truetask comes from two places. Your workspace role decides what you can do across the whole instance. Your board role decides what you can do on one board. Both are checked on every action, so the narrower of the two always wins.

Workspace roles

Every person has exactly one workspace role: Owner, Admin, Lead, User or Guest. Set it in Settings > Members & Teams > User Directory.

CapabilityOwnerAdminLeadUserGuest
Open Settingsyesyesyesnono
Manage integrationsyesyesnonono
Manage backupsyesyesnonono
Edit AI promptsyesyesnonono
Invite peopleyesyesyesnono
Manage teamsyesyesyesnono
Create a boardyesyesyesyesno
Edit a boardyesyesyesyesno
Delete a boardyesyesyesown boardsno
Share a boardyesyesyesown boardsno
Open a boardyesyesyesyesyes
Create a taskyesyesyesyesno
Edit a taskyesyesyesyesno
Commentyesyesyesyesno

A User who created a board can delete it and share it, even though the role alone does not grant those two. Any board they did not create stays read-through-board-role.

A Guest can open the boards they were added to and nothing else: no task creation, no editing, no comments.

Only owners and admins change roles

A role change is rejected unless the request comes from an Owner or an Admin. Only the Owner can hand ownership to someone else, and doing so makes the previous owner an Admin.

Board roles

A board has one owner, its creator, plus a role per member. Set them in the Share dialog on the board.

Board roleWhat it means
OwnerOwns the board. It is the person who created it, and they are always a board admin.
AdminCan change board settings and manage members.
EditorCan add, edit, and delete tasks on the board.
ViewerCan view tasks but can't add, edit, or comment.

Three rules fill in the gaps:

  • A workspace Owner or Admin is a board admin on every board, whether or not they hold a role there.
  • The board's creator is always a board admin.
  • A member added without an explicit role is an Editor.

Board admin is what gates the board-level configuration: Board flow, Custom fields, Agent workflows, the board's webhooks and the Automations view. Non-admins never see the Automations tab at all.

See Sharing a board and Members, roles and teams.

What each settings pane needs

Settings is grouped into six sections, and each section has its own role floor. A Lead opens Settings straight onto Members & Teams, because that is the only section they can see.

SectionRolesPanes
SiteOwner, AdminHealth, Plan, License
GeneralOwner, AdminWorkspace, Board statuses, Custom Fields, Uploads, Network, Unsplash, Board Templates, Automations, Archived boards
Members & TeamsOwner, Admin, LeadUser Directory, Agents, Teams
Audit & SecurityOwner, AdminAudit Log, Active Sessions
IntegrationsOwner, AdminAI, API Tokens, Webhooks, Git Provider
ServerOwner, AdminSMTP, OAuth2, Active Directory, Backups, S3 Storage, Data Retention, Logs, Export

Which panes appear also depends on where your workspace runs.

Self-hosted only

License, Network, SMTP, Backups, S3 Storage, Data Retention and Unsplash exist only on self-hosted instances.

Truetask Cloud only

Plan is the Truetask Cloud pane, and it replaces License. A pane your plan does not include shows a crown icon. See Plans and billing.

Who can manage what

ThingWho
Webhook subscriptions and incoming endpointsWorkspace Owner or Admin, and the workspace needs outgoing webhooks on its plan.
Connected integrationsAnyone can look at the Integrations dialog; connecting one needs Owner or Admin.
Git provider connectionOwner or Admin. Linking a repository to a board also needs board admin on that board.
AI provider and modelsOwner or Admin.
AI promptsOwner or Admin, on self-hosted instances only.
Backups, S3 storage, data retentionOwner or Admin, on self-hosted instances only.
API tokens and the MCP connectorEveryone, for their own tokens. Each token carries the access of the person who made it.
Agent accounts across the workspaceThe Agents pane in Settings > Members & Teams opens for Owner, Admin and Lead; disabling or deleting somebody else's agent needs Owner or Admin.
Timesheets and approvalsOwner, Admin or Lead.
OverseerOwner or Admin.

An outgoing webhook created by a Lead or a User only keeps receiving a board's events while that person is still a member of the board. A webhook created by an Owner or an Admin is workspace-wide. See Webhooks.

Notes

Notes and note folders follow the board by default: anyone who can see the board can read them, and anyone who can edit the board can write them.

Manage access on a note or a folder restricts that instead. Each person you add gets Can view or Can edit; everyone else gets No access. Restricting a folder restricts everything inside it.

Four people always keep access to a restricted note, whatever the list says: whoever created it, the board's owner, and any workspace Owner or Admin. A restricted note you cannot see is simply not there for you; Truetask never says that it exists.

See Note permissions and Publishing notes.

Agents

Agents are accounts too, with two hard limits:

  • An agent can never hold the Owner or Admin workspace role.
  • An agent can never change its own guardrails, its own webhook wiring, or how many tasks it may work at once, even using its own token.

Everything else about an agent belongs to its owner, the person who created it. A workspace Owner or Admin who does not own an agent gets the kill switch only: they can disable it or delete it from Settings > Members & Teams > Agents, but not rename it or loosen its permissions.

Guardrails live under Has permission to on the agent's profile and cover four destructive actions plus web access: Complete, Archive, Delete, Merge PRs and Read the web. Powers are the other half: External access, Local access and Auto-start.

An agent's access to a board is board membership like anyone else's, so assigning a task to an agent that is not on the board does not let it see the board.

See Creating an agent and Delegating work.

Truetask works the same on Truetask Cloud and on your own server. Pages and sections that apply to one model only are labelled.