Permissions and sharing
Two layers decide what someone can do: their workspace role and their role on each board. API keys sit inside both.
Workspace roles
Everyone in a workspace has one of four roles, chosen when they are invited and changeable later by anyone who can manage members.
- Owner: can do everything. A workspace always keeps at least one owner, and the creator's role cannot be changed.
- Admin: everything except changing workspace settings.
- Member: creates boards and folders and works on items; cannot delete or archive boards, manage members or change settings.
- Guest: works on items and updates only, and only on boards shared with them. Guests are part of the Pro plan.
The permissions matrix
The Permissions tab on the workspace home shows twelve permissions in four groups. The table below lists the defaults. On the Pro plan an owner can switch any cell on or off, except that owners always have everything and the cells marked Never can never be granted to guests.
| Permission | Owner | Admin | Member | Guest |
|---|---|---|---|---|
| Boards | ||||
| Create boards | Yes | Yes | Yes | Never |
| Delete boards | Yes | Yes | No | Never |
| Archive boards | Yes | Yes | No | Never |
| Content | ||||
| Create folders | Yes | Yes | Yes | Never |
| Edit board structure | Yes | Yes | Yes | Never |
| Add & edit columns | Yes | Yes | Yes | Never |
| Items | ||||
| Create & edit items | Yes | Yes | Yes | Yes |
| Delete items | Yes | Yes | Yes | No |
| Move items between groups | Yes | Yes | Yes | Yes |
| Collaboration | ||||
| Post updates & comments | Yes | Yes | Yes | Yes |
| Manage members | Yes | Yes | No | Never |
| Change workspace settings | Yes | No | No | Never |
Board roles
Sharing a board gives a person a board role. The effective permission is the workspace matrix and the board role: a Viewer cannot edit items even if their workspace role allows it, and only a board Owner (or a workspace owner or admin) can delete or archive the board.
| Board role | Description | Limits on this board |
|---|---|---|
| Owner | Manage the board and edit everything. | No limits beyond the workspace matrix. |
| Editor | View and edit everything on this board. | Cannot delete or archive the board. |
| Contributor | Can create and edit items. | Cannot delete or archive the board, edit groups or columns, or delete items. |
| Assigned contributor | Only edit items assigned to them. | Same limits as Contributor. Restricting edits to assigned items only is not enforced yet, so treat this role as Contributor for now. |
| Viewer | Only view the board and add updates. | Cannot delete or archive the board, edit groups or columns, create or edit items, delete items or move items. Can view and post updates. |
General access and private boards
Share on a board sets who is invited and what everyone else in the workspace gets, called general access:
- Editor: Everyone in the workspace can view and edit.
- Contributor: Everyone in the workspace can create and edit items.
- Viewer: Everyone in the workspace can view and add updates.
- No access: Private — only invited people can open this board.
Choosing No access makes the board private: it is only visible to the people you invite, and it does not appear in lists, search or the API for anyone else. Private boards are part of the Pro plan.
Guests
Guests are for clients and contractors. Invite someone with the Guest role, then share specific boards with them. They see only those boards, work on items and updates there, and never get board, structure or admin powers, whatever the matrix says. Guests count as members of the workspace for plan purposes and require the Pro plan.
API keys
Keys for the REST API and the MCP server are created in Workspace home, API & MCP by anyone with the Change workspace settings permission. A key acts as one workspace member and carries scopes:
- Every call is first authorised as that member. Their workspace role, the permissions matrix and their board role apply exactly as in the app. Private boards they cannot open do not exist to the key.
- The key's scopes then clamp what is left. A read-only key held by an owner cannot write; an
items:deletekey held by a viewer still cannot delete.
The full key is shown once at creation; only a hash is stored. Revoking a key stops it immediately. The scope list is in the API reference. API keys are part of the Pro plan.
Related
- Getting started for inviting your first members.
- Boards and columns for what archive and trash mean.
- Security for how TallyWeek handles accounts and data.
Start a free workspace for your team.
14 days of Pro with no card, then Free for up to 3 members with every view and every automation.