Team Management Permissions
This page covers the user roles required to view and manage teams. It is about who can administer teams, not about what a team grants: for the five datastore-level permission levels (Editor, Author, Drafter, Viewer, Reporter), see Team Permissions.
Admin only
Creating, editing, and deleting teams is restricted to users with the Admin user role. Users with the Manager role can view the Teams list but cannot change it.
User Roles (Workspace-Level)
| Action | Member | Manager | Admin |
|---|---|---|---|
| View the Teams list, search it, and sort it | |||
| View a team's details and change history | |||
| Create a team | |||
| Edit a team (name, display name, description, permission, users, datastores) | |||
| Delete a team | |||
| Change the Public team's permission and datastores | |||
| Assign users to teams | |||
| Pick teams when creating a datastore | |||
| Reach datastores regardless of team membership |
Team membership is assigned from two places
An Admin adds people to a team either on the team itself, with Edit a Team, or on the person, with Edit a User. Both need the Admin role. With group sync on, membership can also arrive from the identity provider at sign-in; see Just-in-Time Provisioning and Group Sync.
UI Behavior Without Permission
| Scenario | What the user sees |
|---|---|
| User has the Member user role | Cannot open the Access settings page, so the Teams list is not reachable. Their own teams are visible on their profile and in the forms that list teams. Team permissions apply to everything they open. |
| User has the Manager user role | Can open the Teams tab, search and sort the list, and read every team's users, datastores, and permission. The Add Team button and the row menu with Edit and Delete are not shown. Team permissions apply to everything they open. |
| User has the Admin user role | Full access: create, edit, and delete teams, and change the Public team's permission and datastores. Admins reach every datastore whether or not they belong to a team. |
Info
Permissions for managing the accounts themselves (invite, edit role, deactivate, reactivate) are covered on the Personal Account Permissions page.
See Also
-
How It Works
Permission matrix, team roles (Editor, Author, Drafter, Viewer, Reporter), the Teams list, and detailed capability tables.
-
Examples
Team setups for common goals: least privilege by department, a locked-down Public team, a team filled by an identity-provider group, and more.
-
Best Practices
Team organization, permission assignment, Public team usage, and regular audits.