Permissions

Give clients and contractors a board, not your whole workspace.

Two layers of roles, private boards and a permissions matrix. Every write is checked on the server against the caller's role, whether it comes from the app, the API or an automation.

Start free See pricingIncluded on the Free (roles) and Pro (guests, private boards, matrix) plan.

Workspace roles and board roles

Workspace roles: Owner, Admin, Member, Guest. Owners have full control. Admins manage members and boards. Members work. Guests only exist on the boards they were invited to.

Board roles: Owner, Editor, Contributor, Viewer. Share a single board with someone as a viewer, contributor or editor without changing their workspace role.

  • Only an owner can grant the owner role
  • The last owner can never be removed
  • Board shares by email invite
  • Pending invites shown next to members
  • Guests are hidden from other boards

Private boards and the permissions matrix

Boards are visible to the workspace by default. Switch one to private and only its members can see it exists. Private boards are on the Pro plan.

The permissions matrix lets an owner decide what admins, members and guests may do: create boards, invite people, change settings, edit items, and so on. It applies to the app, the API and the MCP server alike.

Enforced on the server

There are no client-side shortcuts. Every access-control write goes through a route that checks the caller's session and role.

API keys inherit roles

A key acts as one member and can never do more than that member, and scopes clamp it further.

Questions

What is on the Free plan?

All four workspace roles and all four board roles. Guests, private boards and editing the permissions matrix are Pro.

Do guests count as members?

Guests are not workspace members and do not count toward the Free plan's 3-member limit, but inviting guests requires the Pro plan.

Can a member see a private board's items through the API?

No. Boards a member cannot open do not exist to a key acting as that member.

Is there single sign-on?

Not yet. Sign in with email and password or with Google.

Step-by-step instructions are in the docs.

Start a free workspace for your team.

14 days of Pro with no card, then Free for up to 3 members with every view and every automation.