People and access
Roles and permissions
The eight capability bundles, the roles that grant them, and how a team role differs from an organization role.
The model in one sentence
You can do an action if a role you hold grants that capability over the organization, the team or the project the action belongs to. A project override is the one exception.
Every entry in a role is a grant. A role cannot refuse anything, and no role ranks above another. If you hold several roles, you have every capability that any of them grants. The Roles screen says the same at the top: Grants add up. Organization roles apply everywhere; team roles apply to that team’s work. A project override is the only exception.
The eight bundles
A capability bundle is one named permission. There are eight, and there is nothing finer underneath. A role is a set of them.
| Bundle | Key | What it allows |
|---|---|---|
| View | view | See the project, backlog, sprints, Scrum Events and reports |
| Comment | comment | Comments and questions on items |
| Write in Scrum Events | event_write | Notes and retro entries in event artifacts |
| Write items | item_write | Create, edit and delete items; status, impediments, DoD ticks |
| Refine the backlog | refine | Order, size, priority, dependencies, phase and epic |
| Run sprints | sprint_run | Create, plan, activate and close sprints; run and invite to events |
| Manage the project | project_manage | Settings, item types, team assignment, import, overrides, the DoD |
| Manage the organization | org_manage | Members, roles, teams, portfolios, billing |
Four bundles carry more than the table says:
- Write in Scrum Events
- Write your own notes in a session. Add a card on the Retrospective board or the Sprint Review board.
- Write items
- Add an item to the backlog. Change its status, or move its card on the board. Tick a Definition of Done line.
- Manage the project
- Change the project settings, and edit the Definition of Done, the phases and the item types. Assign a team and name the Product Owner. Import a .csv file. Set an override. See Project settings and Importing a backlog.
- Manage the organization
- Invite people, change their roles and remove them. Create teams and portfolios. Create, move and delete a project. Open the organization settings, the Activity screen and the billing screen. See Plans and billing.
Three kinds of role
Every role has a kind. The kind decides where its grants apply. You choose it when you create the role, and it never changes.
- Organization roles
- A member holds one or more. Their grants apply everywhere in the organization. The invitation dialog asks for at least one role under Roles on joining, and the person holds those roles from the moment they accept. See Invitations. After that, a person with Manage the organization grants and revokes them on the Members screen. See Members.
- Team roles
- A person on a Scrum Team holds one, one role per team. Its grants reach only that team's Scrum Events: the session itself, its attendees, its notes and its cards. See Scrum Teams.
- Product Owner roles
- A project names one person as its Product Owner. That person holds the role's grants across that whole project. A person with Manage the project names them in the Product Owner section of the project screen. The As select, which picks the Product Owner role, appears only when the organization has more than one Product Owner role. With one such role, the product applies the starting Product Owner role and does not ask. See Projects.
The screens also do not read a team role when they decide which controls to show. A grant held only through a team role shows no control anywhere.
A person on a team still matters in that team's sessions. They count as a Participant, so they can write notes and cards with Write in Scrum Events from an organization role. Because a team role reaches only that team's sessions, two team roles never collide. A person can be Scrum Master on one team and Developer on another. The grants end if somebody with Manage the project unassigns the team from the project. They also end if somebody with Manage the organization deletes the team.
The starting team roles and the starting Product Owner role do not grant View. A person needs View to see a project. It can come from an organization role, from a Product Owner role that grants it, or from an Allow override on that project.
Only an organization role puts the project on the organization overview and the screens in the left rail. A person with a Product Owner role or an Allow override types the URL instead. Five screens open that way: the backlog, the board, the planning screen, the review and the retrospective. The project screen itself answers with a not-found page.
Members, roles, teams, portfolios, the organization settings, the Activity screen and billing belong to the organization, not to a project. Only an organization role can reach them. No team role and no override does. The same is true of three project actions: create a project, move it to another portfolio, and delete it. Each needs Manage the organization, not Manage the project.
A team's own screen says which team role each of its people holds.
- Click Teams in the left rail.
- Click the team.
The roles every organization starts with
Every organization starts with ten roles. The Roles screen marks them with a system tag. The tag is only a label. A person with Manage the organization can edit all ten roles and can delete nine of them.
Organization roles
- Owner
- All eight bundles. The person who creates the organization holds it. Nobody can delete it.
- Admin
- Every bundle except Manage the organization.
- Member
- View, Comment, Write in Scrum Events, Write items.
- Viewer
- View only.
- Stakeholder
- View, Comment, Write in Scrum Events.
- SME
- View, Comment, Write in Scrum Events, Refine the backlog.
- QA
- View, Comment, Write in Scrum Events, Write items.
Team roles
- Developer
- Write items, Write in Scrum Events. The product grants it to a person added to a team in the Developer slot.
- Scrum Master
- Write items, Write in Scrum Events, Run sprints. The product grants it to a person added in the Scrum Master slot.
Product Owner role
- Product Owner
- Write items, Write in Scrum Events, Refine the backlog, Run sprints. One per project.
These are the grants at the start. A person with Manage the organization can change any of them, so the Roles screen of your own organization is the answer, not this list.
The Roles screen
NeedsView view
- Open the organization.
- Click Roles in the left rail.
Anybody with View from an organization role can read the screen. Only a person with Manage the organization can change it. The line under the title says which. An administrator reads Tick a box to grant that capability to that role. Changes apply immediately. A reader reads What each role in this organization grants. Only an administrator can change it.
The screen has three bands, one per kind: Organization roles, Team roles and Product Owner roles. Each band is a table, and a note under its title repeats where that kind of role applies.
The eight bundles run down the Capability column, each with its one-line meaning. The roles run across, in name order, with a system tag on the ten starting roles.
For a reader, a cell shows ✓ when the role grants that bundle and · when it does not. For a person with Manage the organization, every cell is a box. A band with no roles shows None yet. to that person, and is absent for a reader.
The product stores the description you type when you create a role, but no screen shows it.
Grant or remove a bundle on a role
NeedsManage the organization org_manage
- Find the role's column and the bundle's row.
- To grant the bundle, tick the box.
- To remove the bundle, clear the box.
The box changes immediately and the product saves it. The box is unavailable until the product answers. The change applies immediately to everybody who holds the role. A box has two states. Ticked means the role grants the bundle. Clear means it does not, and a role can grant nothing at all.
The product tells nobody. A person whose access changes gets no email and no message in the product.
Each tick is one save. The product refuses more than 60 saves a minute from one person, and answers: Too many requests. The count covers every save you make anywhere in the product, not only the saves on this screen. Wait a minute, then continue.
If the product refuses a change for any reason, the box returns to its saved state. The message appears above the bands. Every rule on this screen blocks. None of them only warns.
The screen can also show these messages:
- Another person with Manage the organization revoked yours: You do not have permission to perform this action.
- Another person deleted the role: Role not found.
- The request never reached the product: Could not reach the server. Check your connection and try again.
The first two messages mean somebody changed something after the page loaded. Reload the page.
The product records every change to a role on the organization's Activity screen: a new role, a change to its grants, and a deleted role. Anybody with Manage the organization can read it there. A role has no history of its own. See The activity feed.
Create a role
NeedsManage the organization org_manage
- Click Add role in the band of the kind you want.
- Type a Name.
- If you want one, type a Description (optional).
- Click Create role.
- Tick the boxes in the new column to give the role its grants.
The kind comes from the band and is not a field. The dialog is titled New organization role, New team role or New Product Owner role. It says: The role starts granting nothing. Tick its boxes in the matrix once it exists. The button reads Creating… until the product answers. The dialog then closes, and the new column appears in the band.
Cancel closes the dialog. The Escape key and the × in the dialog header close it as well. If you click outside the dialog, it closes and the product discards what you typed.
These rules block:
- A name is required: A role needs a name.
- A name is at most 60 characters: Keep the name under 60 characters.
- A description is at most 280 characters: Keep the description under 280 characters.
- A name can appear once per kind, so an organization role and a team role can share one. For a duplicate the dialog shows, for example, A team role called "Release" already exists. The message names the kind as org, team or product.
A new role has no system tag, and a person with Manage the organization can delete it. Its kind never changes. No screen offers a way to rename a role, or to change its description, after you create it.
Delete a role
NeedsManage the organization org_manage
- Click the × beside the role's name at the top of its column.
- Read the confirmation.
- Click Delete role.
The confirmation is titled Delete …? with the role's name in place of the dots. It says: Deleting a role removes what it grants. Anyone holding it keeps only what their other roles grant. For one of the ten starting roles it adds: This is one of the roles the organization started with. Deleting it is allowed, but it will not come back.
The button reads Deleting… until the product answers. Cancel, the Escape key and the × in the dialog header close the dialog without deleting the role. A click outside the dialog leaves it open.
The product has no way to restore a deleted role. Three of the starting roles do work that no other role does, and nothing warns you before you delete one.
To release a role before you delete it:
- For a member: grant them another role on the Members screen. Then revoke this one. A member must keep at least one role.
- For a person on a team: on the team's screen, change their Granted by.
- For a project: in its Product Owner section, click Remove, or name somebody else. The As select cannot release the role on its own. It applies only when you name a new Product Owner, and the list never offers the person who holds the role already.
Why somebody can or cannot do something
NeedsView view
No screen names the role that granted a capability. The answer is always a list of grants plus at most one override, and you read it from the Roles, Teams and project screens.
- Open Roles.
- Find the bundle's row.
- Read which roles grant it.
- If the person holds none of those organization roles, open their team on Teams.
- If the person is the project's Product Owner, open the project screen.
- If the person still cannot do what you expect, and you have Manage the project, open the Overrides section on the project screen.
The Overrides section is absent without Manage the project.
Controls you cannot use
On most screens, a control you cannot use is absent. The screen leaves nothing in its place.
On the Members screen, a reader sees the roles a person holds as plain chips. The role buttons and Remove are absent without Manage the organization. See Members.
On the Roles screen, the boxes, Add role and × are absent. The Overrides link in the left rail is absent too. See Project overrides.
Content that is not a control stays. The role matrix stays readable, with ✓ and · in place of the boxes.
Three screens keep the control instead. It stays visible, and it accepts nothing:
- Name and Timezone on a team screen, without Manage the organization. Only Save changes is absent.
- The Definition of Done boxes in the item panel, without Write items.
- Demoed and Released on the review screen, without Run sprints.
What the screen shows is a hint. The product checks the same capability again on every screen and on every save. If you type the URL of a screen you cannot see, the product shows a not-found page. It shows no message about permission.
Project overrides
An override allows or denies one bundle for one person on one project. An override decides whatever the person's roles say, and it is the only way to remove a capability. It cannot touch Manage the organization. A person with Manage the project sets and clears overrides on the project screen. A person with Manage the organization sees every override on the Overrides screen. See Project overrides.