Roles & permissions

A workspace-wide reference for what every role can and can't do across Trellis.

Trellis uses a six-role system to control what each person in your workspace can see and do. Your role isn't the only thing that shapes your access — it combines with four other layers to decide what you can actually do:

  • Workspace role — one of Owner, Admin, Editor, Member, Contributor, or Viewer. Assigned when someone joins the workspace and set by an Owner or Admin.
  • Project membership — being added as a member of a specific project. Reading a project follows your workspace role: Owner, Admin, and Editor can open any project without joining it, while Member, Contributor, and Viewer only see projects they've been explicitly added to. Writing to one doesn't work that way. Nearly every write inside a project — tasks, sprints, the board, the timeline, roadmap items, quotes, attachments, comments, time logs, project updates, resourcing, bookmarks, share links, and the project's own settings — requires project membership from every role, Owners and Admins included.
  • Feature area — Trellis is split into three areas: Project management, HR, and CRM. An Owner or Admin can switch any of them off for the whole workspace under Settings → Workspace → Features, which hides those pages for everyone regardless of role or plan.
  • Plan tier — some features (HR, CRM, Roadmap, Files, AI, Integrations, Activities log, the Resourcing heatmap, and parts of Dashboard reporting) are only available on the Enterprise plan.
  • Paid add-onsBranding & customization and Onboarding & forms are bought separately rather than bundled into a plan. Trellis checks only whether your workspace carries the add-on, never which plan you're on.
  • Per-record ownership — a handful of actions let a role affect only records they created themselves. Notable examples: Roadmap items (Members, Contributors, and Viewers can only edit or delete their own) and task comments (only the author can edit or delete).

The six roles at a glance

Owner

Top-level administrator of the workspace. Only role that can transfer ownership or delete the workspace, and the only role that can edit workspace-level company details (address, registration number, invoicing info). Every other Owner action overlaps with Admin.

Typical: Founders, Business owners, Workspace Creators.

Admin

Full administrative access to run day-to-day workspace operations. Manages members, invites, rate cards, absence types, and workspace-wide settings. Cannot transfer or delete the workspace, and sees company details in read-only form.

Typical: Operations leaders, Managers, Heads of delivery.

Editor

Broad edit access across projects, quotes, timelines, and creative production. Can create and manage workflows, labels, packages, and rate cards at the project level (but not workspace-level rate cards). Cannot administer workspace billing, membership, absence, or plan.

Typical: Project leads, Senior staff.

Member

Regular team member with edit access to projects they're a member of. Logs their own time, requests their own leave, can create and edit tasks, sprints, and roadmap items on their projects. Cannot see workspace-wide financial data or manage other people's timesheets, leave, or profiles.

Typical: Project delivery team members.

Contributor

Lightweight write role for people who need to interact with specific projects but not shape their configuration. Can create and edit tasks, comment on updates, and log time, but can't manage labels on projects, edit some sensitive workspace-wide settings, or use Quotes.

Typical: Freelance collaborators, Partners, Client reviewers.

Viewer

Read-only role for stakeholders who need visibility into project progress without editing rights. Sees timelines, boards, tasks, and roadmap items in read-only mode. Can post comments on tasks, but can't create, edit, or delete anything else.

Typical: Clients, External stakeholders, Observers.

Permissions by feature area

Each area below lists the most important actions in that surface. An asterisk (*) means the role needs project membership in addition to their workspace role — including Owners, Admins, and Editors, who get no bypass on writes.

Dashboard

ActionOwnerAdminEditorMemberContributorViewer
Access the Dashboard
Timesheet reporting — see team-wide view
Timesheet reporting — see own day-by-day breakdown
Timesheet reporting — drill into a teammate's day-by-day
Logged time across projects widget
Pinned projects widget
Resourcing heatmap (Enterprise)
Create a project from the Dashboard empty state

* Project membership required in addition to workspace role.

Projects & per-project pages

ActionOwnerAdminEditorMemberContributorViewer
All Projects — view and search
All Projects — pin or unpin a project******
All Projects — create a new project
All Projects — see Project profitability column
Project Overview — access the page***
Project Overview — see Profitability chart & Project Spend
Project Overview — see Cost to business column
Project Overview — post to Project Updates*****
Timeline — access and export***
Timeline — add / edit / delete deliverables and dependencies*****
Timeline — save / restore timeline versions
Quotes — access the page
Quotes — create, edit, and send***
Quotes — attach terms and conditions***
Quotes — read the approval record
Quotes — export to Xero
Planning — open the tab
Planning — edit budgets and allocations
Planning — add tasks
Tasks — access the page***
Tasks — create, edit, duplicate, archive, delete*****
Tasks — see Reports section (budget vs resourced vs worked)
Tasks — comment on a task******
Sprints — access, browse, expand***
Sprints — create, start, complete, or delete*****
Board — access and watch cards move***
Board — move tasks or create from + button*****
Board — reorder columns or Modify workflow
Roadmap — access the page (Enterprise)***
Roadmap — create or edit any item*****own only*
Roadmap — attach labels to items****
Roadmap — delete an item***own only*own only*own only*
Files — access, search, preview, download (Enterprise)***
Project settings — access the page***
Project settings — edit name, stage, labels, PM/Lead***
Project settings — add or remove Collaborators
Project settings — archive or delete the project
Project settings — leave the project

* Project membership required in addition to workspace role.

Workload

ActionOwnerAdminEditorMemberContributorViewer
Timesheet — log time against your own timesheet*****
Timesheet — log time on behalf of another user**
Resourcing — open a project's resourcing calendar**
Resourcing — auto-resource, assign, split, or reassign allocations*****
My Leaves — access the page and see your balance (Enterprise)
My Leaves — request or log leave for yourself (Enterprise)
My Leaves — cancel your own approved leave without admin review (Enterprise)
Notes — create, edit, delete your own private notes

* Project membership required in addition to workspace role.

HR

ActionOwnerAdminEditorMemberContributorViewer
Requests — approve, decline, or request more info (Enterprise)
All Absence — view workspace-wide absence records (Enterprise)
All Absence — log or edit absence on behalf of others (Enterprise)
Allocation — allocate, adjust, or remove leave allowances (Enterprise)
Absence types — create, edit, or delete (Enterprise)

* HR is only available on the Enterprise plan.

Personal settings

ActionOwnerAdminEditorMemberContributorViewer
Getting around Trellis — use workspace switcher and user menu
Getting around Trellis — invite a teammate from the switcher (Enterprise)
Getting around Trellis — Log Time shortcut in user menu
Profile — manage your own account details
Preferences — manage theme, cookies, tutorial
Notifications — manage your own channels and preferences
Security & Authentication — sign-in methods, passkeys, 2FA, devices
Connected apps — manage your own app connections

Project setup (workspace-level)

ActionOwnerAdminEditorMemberContributorViewer
Workflows — create, edit, delete workflows and statuses
Labels — create, edit, delete workspace labels
Labels — apply existing labels to your own work
Packages — create, edit, delete, duplicate
Packages — import a package into a quote***
Packages — save a quote's deliverable group as a package

* Project membership required in addition to workspace role.

Admin section

ActionOwnerAdminEditorMemberContributorViewer
Rate cards — view the page
Rate cards — create, edit, or delete workspace rate cards
Rate cards — adjust rate cards at project level
Support — access and raise support tickets
Branding & customization — change colours, themes, nomenclature (add-on)
Onboarding & forms — build, edit, publish, and send forms (add-on)
Onboarding & forms — fill out a form sent to you
Activities log — view, filter, and export (Enterprise)

Workspace

ActionOwnerAdminEditorMemberContributorViewer
General — view the page
General — edit workspace name and logo
General — edit company details
General — transfer ownership or delete the workspace
General — leave the workspace
Billing — view plan and usage, contact Trellis about billing
Members — invite, remove, edit members' roles and details
Members — assign the Owner role (via Transfer ownership)
Calendar configuration — edit working schedule
Calendar configuration — edit leave calendar settings (Enterprise)
Calendar configuration — remove all allocations (Danger zone) (Enterprise)
Integrations — enable or disable workspace integrations (Enterprise)
AI — enable Trellis AI for the workspace (Enterprise)
AI — use Trellis AI once enabled
My membership — see your own summary and complete forms

Cross-cutting concepts

Project membership

Project membership works differently for reading and for writing, and the difference catches people out.

Reading follows your workspace role. Owner, Admin, and Editor can open any project without joining it. Member, Contributor, and Viewer only see projects they've been explicitly added to — if you're a workspace Member but not a member of Project X, Project X won't appear in your project list at all.

Writing requires membership from everyone. There is no elevated-role bypass on almost any write. A workspace Owner or Admin who has never joined a project can read everything in it and export from it, but the moment they try to change something Trellis refuses and tells them they aren't a member of that project. This holds across:

  • Tasks — create, edit, label, archive, delete, reorder
  • Sprints and the Board — create, update, delete, reorder, bulk-move, bulk status change
  • Timeline — deliverables, dependencies, and share links
  • Roadmap items, Resourcing allocations, and project bookmarks
  • Quotes — building, attaching terms, sending, revising, and importing a package into one
  • Task comments and reactions, file attachments, and time logs against a task
  • Project updates on Project overview
  • Editing the project in Project settings, and pinning or unpinning it on All projects

A few project-level actions sit outside the rule because they're about the project rather than its contents: archiving, restoring, or deleting a project, adding and removing its members, and saving or restoring a timeline version all work on workspace role alone. Milestones are the same — they follow the read rule, so an Owner, Admin, or Editor can add one without joining.

In practice this rarely stops you dead. When a write is refused because you aren't a member, Trellis opens a Join this project? dialog — accept it and Trellis adds you as a project member and retries the action you were in the middle of, so nothing is lost. It's a speed bump that records who is working on what, not a locked door. Viewers are the exception: they can't join themselves, so the action stays refused.

Owners and Admins can also add people up front via Project settings → Collaborators on any individual project.

Feature areas

Trellis is split into three areas — Project management, HR, and CRM — and an Owner or Admin can switch any of them off for the whole workspace under Settings → Workspace → Features. This sits above role and plan: turning an area off hides its pages for everyone, Owners included. Data isn't deleted, and switching the area back on brings everything back.

HR and CRM need the Enterprise plan before they can be switched on at all. Project management is on by default on every plan — but if it's off, Projects, the Board, Sprints, the Timeline, Quotes, Timesheet, and every Dashboard widget go with it.

When a page is unavailable for either reason, Trellis sends you to the Dashboard with a dialog that names the cause. Owners and Admins get a button to act on it — Upgrade for a plan block, Go to settings for a switched-off area. Everyone else is pointed at an owner or admin.

Enterprise-only features

Trellis has two plans: Free and Enterprise. Some parts of the product are only available on Enterprise, and they behave in one of three ways. A page inside the HR or CRM area is hidden from the sidebar and, opened directly, sends you to the Dashboard with a dialog explaining why. A page of its own — Roadmap, Files, Activities, Trellis AI, Integrations — opens as normal but shows an Upgrade to Enterprise prompt in place of its content. A Dashboard widget simply isn't rendered: on Free the Resourcing heatmap is absent, with nothing in its place, so there's no prompt to look for.

Enterprise-only features:

Available on every plan, contrary to what you might expect: Resourcing itself, and the Logged time across projects widget — the latter just moves further down the Dashboard on Free.

Branding & customization and Onboarding & forms are bought separately rather than bundled into a plan, so they don't follow the plan rules above at all. Trellis checks only whether your workspace carries the add-on: an Enterprise workspace without it is turned away, and a workspace with it gets in whatever its plan. Without the add-on the link is hidden from Settings and the page returns "Page not found".

Per-record ownership

A handful of actions let a role affect only the records they created themselves, layered on top of the role check:

  • Roadmap items — Members, Contributors, and Viewers can only edit or delete items they authored. Owner, Admin, and Editor can edit or delete any item.
  • Task comments — regardless of role, only the original author can edit or delete their own comment.

Status-based locks

Some actions become unavailable once an object moves out of a certain state — independent of your role:

  • Quotes lock to read-only once they leave Draft. Sent, Approved, Declined, and Archived quotes cannot be edited by anyone until an eligible role uses Revise to move them back to Draft.
  • Sprints can only be deleted if they haven't started and have no tasks attached. Move tasks back to the backlog to unblock the delete.