Roles and permissions

The permission model: what admins, editors and viewers can each do, what happens when you change someone's role, and what the active switch is for.

Tasuki does not hand each person a different slice of the workspace: everyone sees the same projects, and what changes is what they can do with them. That is set by three roles, from the Team view, which is the workspace admin panel.

The three roles

  • Admin. Invites people, changes roles, activates and deactivates members, and handles workspace settings and the subscription. Also does everything an editor does.
  • Editor. Does the work: creates and moves cards, comments, logs hours, writes notes. This is the role for most of the team.
  • Viewer. Sees the work and does not change it. For anyone who needs to follow a project without taking part in it: someone from management, an internal client, an occasional collaborator.

There are no other levels. If you are torn between two, give the smaller one: promoting someone is one click, demoting them is an awkward conversation.

Reading the directory

The user table gives one row per person, with avatar and initials, email, role as a coloured badge, department, how many projects they are in, and a status switch. Your own row is marked "(you)". Above the table sit search, a filter and the create-user button, plus a count along the lines of "7 results · 5 active · 2 inactive".

💡

Departments grant nothing

Design, Development, Accounts or Content help you find people and keep the directory tidy; they open and close no doors. What each person can do is decided by the role, always.

Changing someone's role

You edit it from the row itself, with the pencil icon. The change touches nothing that is already done: cards, comments and logged hours stay in their name. What changes is what that person can do from that moment on.

⚠️

Careful when demoting someone to viewer

Their cards stay assigned to them, but they can no longer move or close them. Reassign before you demote, or the board is left holding work in the name of somebody who cannot touch it.

Per-board permissions

The three roles apply to the whole workspace: an editor is an editor on every project. When what you need is for someone to be an editor on one board and a viewer on another — the classic case of a freelancer brought in on one account who should not see the others — that is advanced RBAC with per-board roles, and it starts on the Business plan. Check the pricing table.

Active or inactive

The switch in the status column cuts access without deleting anything. Deactivate and the row dims, the email is marked as deactivated and the count above moves that person from active to inactive. Their history stays intact, and the switch goes back whenever you want.

The bin icon on the row is a different matter, and it does not go back. When in doubt, deactivate.

What next

Roles are not the only thing deciding what people get: chat, announcements and clock-in depend on the plan as well. Those are covered in Communication and Time and clock-in.

Still stuck?

If this page didn't answer your question, write to us and we'll improve it.

Write and tell us