People and access
Project overrides
Give or refuse one person one capability on one project, and see every override in the organization.
What an override is
Roles grant capabilities, and the grants combine. An override is the one exception. It names one member, one capability and one project, and it says Allow or Deny. It can carry a reason. See Roles and permissions for the eight capabilities and the roles that grant them.
The override decides, whatever the member's roles say. A deny removes the capability on that project, even when an organization role, a team role or the Product Owner role grants it. An allow gives the capability on that project alone, even when no role grants it. A deny is the only way the product removes a capability from a member who holds it by role.
The Overrides section on the project screen
NeedsManage the project project_manage
You set, replace and clear an override in one place: the Overrides section of the project screen, between Import and Settings. See Projects. The section is absent for a member without Manage the project on that project. The product has no read-only view of it. A deny on Manage the project also removes the section from that member on that project.
The section header counts the rows: 1 exception, 2 exceptions and so on. With no rows the header reads 0 exceptions, and the section shows this sentence in place of the list: No overrides on this project. Everybody’s access here is exactly what their roles say.
When a project has three or more overrides, a warning is above the list: 3 exceptions on one project usually means a role grants the wrong thing. Changing the role is more durable than maintaining these. The number at the start of the warning is that project's own count, so it reads 4 exceptions when there are four. The warning does not block anything, and you can still set a fourth.
Each row shows, from left to right:
- the effect, deny or allow,
- the member's name,
- the capability, by its label, such as Refine the backlog,
- the reason, or no reason given,
- who set it, and the date the override began,
- a Clear button.
The date is in your own timezone. See Time and timezones. The rows are in the member's name order. Rows for the same member follow the order of the Capability list, View first and Manage the project last.
Set an override
NeedsManage the project project_manage
- Open the project screen.
- Go to Overrides.
- Under Person, choose a member.
- Under Capability, choose a capability.
- Under Effect, keep Deny or choose Allow.
- If the override needs an explanation later, type a Reason.
- Click Set override.
The Person list offers every member of the organization except you. A hint under Capability shows what the chosen capability covers.
The button stays disabled until you choose both a member and a capability. While the product saves or clears an override, the buttons in the section are disabled. This covers the button, each row's Clear button, and Clear and Keep inside an open confirmation. The Person, Capability, Effect and Reason controls stay usable throughout. You save with one click, with no confirmation. After the save, the form clears, the row appears, and the override is in force.
A note under the form says what the chosen effect does. For Deny: Deny takes the capability away on this project, whatever their roles grant. It is the only revocation in the product. For Allow: Allow grants the capability on this project alone, whether or not their roles do.
The Capability list offers seven capabilities:
- View
- Comment
- Write in Scrum Events
- Write items
- Refine the backlog
- Run sprints
- Manage the project
The list never offers Manage the organization.
View is the capability that opens the project. A deny on View makes every screen of the project answer the not-found page for that member. The project's card stays on the organization overview, so a click on the card opens the not-found page.
An allow on View changes nothing for a member whose roles already grant View in the organization. For a member whose roles grant no View, the organization overview answers the not-found page. The left rail is empty for that member, because every link in it needs View or Manage the organization. Even Overview is absent. The rail lists organization screens only, and you open a project from its card on the overview. See Getting started.
That member opens the backlog, the board, the planning screen, the review and the retro by the address of each screen. The project screen itself still answers the not-found page for them.
If the server refuses to save the override, its message appears above the list, and the form keeps what you typed. If another administrator deleted the project while your page was open, the message reads Project not found. If another administrator removed Manage the project from you while your page was open, the message reads You do not have permission to perform this action. Clear then shows the same message, and nothing else on the screen changes.
Replace an override
NeedsManage the project project_manage
A project holds one override per member and capability. A row has no edit control. To change the effect or the reason, set the override again with the same member and the same capability.
- In the form, choose the member and the capability of the existing row.
- Choose the effect you want now.
- Type the reason you want now.
- Click Replace override.
When your choice matches a row, the button reads Replace override. The note adds Replaces the deny already on … for this capability. The member's name stands in place of the dots, and allow replaces deny for an allow row.
The product replaces the whole row. The new reason takes the place of the old one, a blank reason clears it, and you become the author. The date on the row does not change. It stays the date of the first save, so the row shows your name beside that earlier date.
Clear an override
NeedsManage the project project_manage
- Click Clear on the row.
- Read the line that replaces the button: …’s roles decide “…” here again.
- To clear the override, click Clear.
- To keep the override, click Keep.
In that line, the member's name and the capability stand in place of the dots. When you clear an override, the member's roles decide again. A cleared override does not deny the capability. If you clear a deny and their roles grant the capability, they have it again. If you clear an allow and their roles do not grant it, they lose it.
The list shows every override on the project, including a row that another administrator set on you. Every row carries a Clear button, and you can clear a row on yourself. A member under a deny on Refine the backlog who still holds Manage the project can clear that deny.
The reason
NeedsManage the project project_manage
The Reason field is optional. Its hint reads Why, for whoever reads this later. Optional, and the one thing the audit cannot recover without. The product stores the text without spaces at the start or the end.
A reason is at most 280 characters. The box stops you at 280, so you cannot type or paste a longer one. The product stores a blank reason as none, and the row shows no reason given.
The reason appears on the project screen and on the Overrides screen.
The activity feed records every override you set or clear. No screen shows the project's own feed, which withholds both entries from a member without Manage the project on that project. See The activity feed.
The organization's Activity screen needs Manage the organization. Each entry there shows the time, who acted, and the name of the event. The entry does not show the member named, the project, the capability or the reason. The screen loads the 50 newest entries of any kind, and it has no paging control. When older entries exist, the screen says Older entries exist. Paging arrives with the audit screen. The entry for an override older than those 50 is on no screen.
Every override in the organization
NeedsManage the organization org_manage
The Overrides screen, in the organization's left rail, lists every override in force across every project. The project's Overrides section names it in its own description, under the section header: Every override in the organization is listed on the Overrides tab. That sentence calls the screen a tab. The link is absent for a member without Manage the organization, and a direct address opens the not-found page. An administrator who holds only Manage the project reads their own project's overrides on the project screen instead.
The line under the screen's title reads Every exception in force in this organization. An override is the only thing that can take a capability away from someone who holds it by role, so this is the complete list. With nothing in force it says No overrides are in force. Exceptions are added from a project’s own settings.
The screen groups the rows by project, with the project's key and name and a count. Projects are in name order. Under a project with three or more overrides, the same warning as on the project screen is above its rows. Each row shows the effect, the member and the capability. The capability appears as its short key, not its label. The row then shows the reason, or no reason given, and who set it beside the date the override began.
Inside each project, the rows are in the member's name order, then in the order of the Capability list. The screen does not list a deleted project's overrides.
What an override cannot do
Manage the organization covers members, roles, teams, portfolios and billing. It also covers three acts on a project. A member who holds it can create a project, move a project to another portfolio, and delete a project. Those three acts change where a project is in the organization, not what happens inside one project. To remove Manage the organization from a member, change their roles. See Members.
An override cannot reach past its project. The product has no organization-wide override and no override on a portfolio or a team. To change what a member can do everywhere, change their roles.
When an administrator removes a member from the organization, the product deletes every override that names them. If the member accepts a new invitation later, they start with none.
The product does not tell a member when an override on them changes, and no screen shows the source of a grant or a refusal. You can see an override in three places: the Overrides section, the Overrides screen and the Activity screen. The Activity screen shows only that a member set or cleared an override, and when. It holds the 50 newest entries of any kind, so an older entry is on no screen.