Roles & permissions

Who can do what - finally crystal clear

Sensitive project data stays with the right people. Grant rights role-based down to the area level - globally and per project, fully auditable and with no risk of locking yourself out.

Permission matrixLive
RoleProjectsPortfolioMeetingsAdmin
Administrator
Admin
Admin
Admin
Admin
Project lead
Editor
Editor
Editor
View
Team member
Editor
View
View
None
Guest
View
None
View
None
LevelNoneViewEditorAdmin

Access rights nobody can keep track of anymore

Without a clear role model, every new hire, every project and every audit turns into a struggle.

Everyone sees everything

Without granular rights, half the company can see budgets, assessments and confidential projects - a data-protection risk waiting to happen.

Rights live in heads and spreadsheets

Who may do what is written down nowhere reliable. Every question starts the hunt all over again.

Onboarding costs hours

New team members get their rights clicked together one by one - every time anew, every time error-prone.

The audit becomes a nightmare

When the compliance review arrives, nobody can cleanly prove who gained or lost which access, and when.

Access control in four clear steps

From the role model to the complete audit trail - one path your whole team can follow.

01

Define the role

Create roles and set the right level per area - from „None“ to „Administration“.

02

Pick the level

Global for the whole system or project-specific for individual initiatives - both levels mesh cleanly.

03

Assign

Rights follow the role. Via users, groups and teams, whole crews are set up in a single step.

04

Trace

Every change lands in the history - with actor and timestamp. Compliance stops being a project and becomes a side effect.

Global permission matrix

Every role, every area - at a glance

A single matrix shows who may do what across the system: every tenant-wide role against every permission area. No more scattered individual settings.

  • Create, rename and remove roles - shaped to your organization
  • Full transparency for PMO and administration instead of guesswork
  • Every role gets exactly the rights it needs - no more, no less
Role4

Administrator

3 members

Project lead

8 members

Team member

24 members

Guest

5 members

Permission level per area

Role: Project lead

Projects

None
View
Editor
Administration

Tasks

None
View
Editor
Administration

Portfolio

None
View
Editor
Administration

Administration

None
View
Editor
Administration

Four permission levels

Fine-grained instead of all-or-nothing

For each area you pick one of four clear levels: None, View, Editor or Administration. Role-based access control the way it should be.

  • A familiar RBAC model - no learning exotic permission logic
  • Controllable per functional area: projects, portfolio, meetings, administration
  • Read-only access for stakeholders, full rights for owners

Global & per project

Two levels that mesh cleanly

The global system role sets the frame. Inside a project you additionally assign project-specific roles - such as „Reviewer“ or „Guest“ - independent of the global model.

  • Freely create, edit and delete project roles
  • Guests and external reviewers see only their project - not the whole system
  • Responsibility per initiative, without touching the global role

Global system role

Project lead

Roles in the project

Website relaunchProject lead
ERP migrationReviewer
Marketing 2026Guest

Project role overrides global

Change history

Role: Reviewer

Permission changed

2 hrs ago

Portfolio: View → Editor

A. Weber

Role renamed

yesterday

„Guest“ → „External reviewer“

M. Klein

Role created

3 days ago

Reviewer

A. Weber

Change history

Who changed which right, and when?

Every role keeps its own history: created, renamed, deleted, permissions changed - with actor and timestamp. Project roles are logged completely too.

  • Traceability right in the edit dialog instead of a separate audit tool
  • A solid basis for GDPR and compliance evidence
  • Load older entries on demand - nothing gets lost

Lockout protection

Critical roles are safeguarded

Protected system roles can't be deleted by accident. The permission system's core stays intact - and nobody locks themselves or the whole team out.

  • The delete button never even appears for protected roles
  • Preconfigured base roles: ready to go instead of a blank page
  • Your own roles stay freely deletable - only the base is protected

Protected system roles

Default administratorProtected
Project leadProtected
ReviewerDelete
Intern (temporary)Delete

Cannot be deleted

Security that doesn't become a burden

A clean role model should protect, not slow you down. That's why the standard case is done in minutes.

Ready from the start

Preconfigured base roles cover the normal case right away - you only adjust what differs in your organization.

Whole teams in one step

Rights follow groups and teams. Instead of authorizing each person individually, you set up whole crews at once.

Nothing breaks

Protected roles prevent accidental lockout, and every change is traceable - and reversible - in the history.

Roles take effect through assignment

Rights land where people actually work

A role only takes effect once it's assigned. Via user groups and teams you distribute permissions exactly where collaboration happens - and withdraw them just as quickly when things get restructured.

Frequently asked questions

What PMOs and administrators want to know about roles & permissions.

Yes. You recreate your existing role model in the matrix or start from the preconfigured base roles and adapt them. No big-bang overhaul required.

No. Per area you pick one of four levels via a segmented control. The familiar RBAC principle makes the model understandable without training.

The change history logs every role and permission change with actor and timestamp - the basis for clean compliance and data-protection evidence.

Yes. Via project-specific roles such as „Guest“ or „Reviewer“, externals get access to exactly one project - with no view of the rest of the system.

The global system role applies tenant-wide and sets the frame. Project roles apply only within a project and can steer more finely or differently there - independent of the global role.

Bring order to your access rights

Try the role-based permission model free for 30 days - with no risk of locking yourself out.