Permissions work on three separate levels. The same person can be an admin in one workspace and an ordinary member in another.
| Level | What it covers |
|---|---|
| System admin | All workspaces, user and company management, module on/off, system logs |
| Workspace admin | Their own workspace: members, projects, reports, channel settings |
| Project level | A specific project: view / edit / manage — based on project membership |
A project's visibility is set separately: public (everyone in the workspace sees it), team, or private (members only).
When “client view” is enabled, external users with the viewer role only see statuses — they cannot post comments, reactions or time entries.