Manage organization roles and custom access roles

The organization role sets the basic permissions. A custom access role adds module access and task restrictions on top of it. The four organization roles and self-defined access roles are therefore two separate settings.

Prerequisites
  • You're an Owner or Admin to manage custom roles and member access.

Tell the four organization roles apart

Choose the organization role that matches the person's responsibility.

Owner
Responsible for the organization, its underlying plan, and owner-exclusive actions like deleting the organization and transferring ownership.
Admin
Manages members, roles, modules, and settings, among other things. This doesn't make them the organization's owner.
Member
Works in the enabled modules within their access rights.
Viewer
Meant for read access; a custom access role doesn't turn this into an Admin role.

Create a custom access role

Open Custom roles in the Members tab.

  1. Create a new role and give it a unique name.
  2. Choose a color to tell it apart.
  3. Enable the modules that should be accessible with this role.
  4. Set any task restrictions if needed, and save.
  5. Assign the role to a member, or use it in an invite.

Restrict task visibility

For roles with task access, there's a setting for assigned tasks only, plus a selection of specific projects. In the current flow, 'own tasks' covers both tasks assigned to someone and tasks they created themselves. Restricting to own tasks drops the additional access through the management hierarchy and projects. Without that restriction, tasks from subordinates and selected projects can be added. Owners and Admins aren't limited by this task filter.

Account for meeting and file access

These kinds of access follow additional rules in their own module. For meetings, what matters for regular members is whether they organized the meeting or are listed as a participant. In the Files module, folders can be restricted to specific access roles; Owners and Admins have broader access there. So an enabled module doesn't automatically mean access to every single piece of content.

Check access on web and mobile

The mobile app also follows the organization's and member's available modules. Check the right organization and visible content with the account in question. A custom role doesn't unlock features that are disabled for the organization itself, or unavailable on the plan.

Frequently asked questions

Are custom roles additional organization roles?

No. The member stays, for example, a Member or Viewer, and additionally gets their own access profile.

Why do I see a task with no assignee under assigned tasks only?

Self-created tasks also count as own tasks, so they can stay visible.

Can a folder name alone protect files?

No. What matters is the file folder's sharing settings and the member's role, not the name.

Keep reading

Couldn't find your answer, or still stuck?

Go to support

Last reviewed on 2026-09-26