Who can do what - finally crystal clear
Sensitive project data stays with the right people. Grant rights role-based down to the area level - globally and per project, fully auditable and with no risk of locking yourself out.
Access rights nobody can keep track of anymore
Without a clear role model, every new hire, every project and every audit turns into a struggle.
Everyone sees everything
Without granular rights, half the company can see budgets, assessments and confidential projects - a data-protection risk waiting to happen.
Rights live in heads and spreadsheets
Who may do what is written down nowhere reliable. Every question starts the hunt all over again.
Onboarding costs hours
New team members get their rights clicked together one by one - every time anew, every time error-prone.
The audit becomes a nightmare
When the compliance review arrives, nobody can cleanly prove who gained or lost which access, and when.
Access control in four clear steps
From the role model to the complete audit trail - one path your whole team can follow.
Define the role
Create roles and set the right level per area - from „None“ to „Administration“.
Pick the level
Global for the whole system or project-specific for individual initiatives - both levels mesh cleanly.
Assign
Rights follow the role. Via users, groups and teams, whole crews are set up in a single step.
Trace
Every change lands in the history - with actor and timestamp. Compliance stops being a project and becomes a side effect.
Global permission matrix
Every role, every area - at a glance
A single matrix shows who may do what across the system: every tenant-wide role against every permission area. No more scattered individual settings.
- Create, rename and remove roles - shaped to your organization
- Full transparency for PMO and administration instead of guesswork
- Every role gets exactly the rights it needs - no more, no less
Administrator
3 members
Project lead
8 members
Team member
24 members
Guest
5 members
Permission level per area
Role: Project lead
Projects
Tasks
Portfolio
Administration
Four permission levels
Fine-grained instead of all-or-nothing
For each area you pick one of four clear levels: None, View, Editor or Administration. Role-based access control the way it should be.
- A familiar RBAC model - no learning exotic permission logic
- Controllable per functional area: projects, portfolio, meetings, administration
- Read-only access for stakeholders, full rights for owners
Global & per project
Two levels that mesh cleanly
The global system role sets the frame. Inside a project you additionally assign project-specific roles - such as „Reviewer“ or „Guest“ - independent of the global model.
- Freely create, edit and delete project roles
- Guests and external reviewers see only their project - not the whole system
- Responsibility per initiative, without touching the global role
Global system role
Project lead
Roles in the project
Project role overrides global
Change history
Role: Reviewer
Permission changed
2 hrs agoPortfolio: View → Editor
A. Weber
Role renamed
yesterday„Guest“ → „External reviewer“
M. Klein
Role created
3 days agoReviewer
A. Weber
Change history
Who changed which right, and when?
Every role keeps its own history: created, renamed, deleted, permissions changed - with actor and timestamp. Project roles are logged completely too.
- Traceability right in the edit dialog instead of a separate audit tool
- A solid basis for GDPR and compliance evidence
- Load older entries on demand - nothing gets lost
Lockout protection
Critical roles are safeguarded
Protected system roles can't be deleted by accident. The permission system's core stays intact - and nobody locks themselves or the whole team out.
- The delete button never even appears for protected roles
- Preconfigured base roles: ready to go instead of a blank page
- Your own roles stay freely deletable - only the base is protected
Protected system roles
Cannot be deleted
Security that doesn't become a burden
A clean role model should protect, not slow you down. That's why the standard case is done in minutes.
Ready from the start
Preconfigured base roles cover the normal case right away - you only adjust what differs in your organization.
Whole teams in one step
Rights follow groups and teams. Instead of authorizing each person individually, you set up whole crews at once.
Nothing breaks
Protected roles prevent accidental lockout, and every change is traceable - and reversible - in the history.
Rights land where people actually work
A role only takes effect once it's assigned. Via user groups and teams you distribute permissions exactly where collaboration happens - and withdraw them just as quickly when things get restructured.
Frequently asked questions
What PMOs and administrators want to know about roles & permissions.
Yes. You recreate your existing role model in the matrix or start from the preconfigured base roles and adapt them. No big-bang overhaul required.
No. Per area you pick one of four levels via a segmented control. The familiar RBAC principle makes the model understandable without training.
The change history logs every role and permission change with actor and timestamp - the basis for clean compliance and data-protection evidence.
Yes. Via project-specific roles such as „Guest“ or „Reviewer“, externals get access to exactly one project - with no view of the rest of the system.
The global system role applies tenant-wide and sets the frame. Project roles apply only within a project and can steer more finely or differently there - independent of the global role.
Bring order to your access rights
Try the role-based permission model free for 30 days - with no risk of locking yourself out.
