Three levels, each inside the next:
Organization your company
└─ Workspace a client, a region, a portfolio
└─ Project one survey of one asset
Access is granted at any of the three, and reaches downward.
| Given access at | You get |
| Project | That project |
| Workspace | Every project in it, now and in future |
| Organization | Everything |
The same person can be an administrator of one workspace and a viewer in another. Nobody sits at a single "level": what someone has is the roles they hold in particular places.
So "what can Anna do?" has no answer on its own. "What can Anna do in this project?" does.
Access from different levels adds up rather than overriding. Someone with workspace-viewer access who is also invited to one project as an editor can edit that project and read the others.
Access is never taken away by a role at another level. If someone can do something you did not expect, look for a second grant somewhere else rather than assuming the first one is wrong.
Removing a person from a workspace does not remove project invitations they hold individually. For someone leaving the company, an organization administrator should remove them at organization level. See Inviting people and setting their roles.
Not just projects:
That second point shapes how you organise. See Managing workspaces and organizations.
A profile can be copied into another workspace, which is how one agreed standard reaches several of them. Each copy is then its own profile, so later edits have to be made in each. See Setting up Observation Profiles.
Open the project and look. Controls you cannot use are greyed or missing, and Troubleshooting project permissions works through the common cases.