Understanding roles and permissions

Understanding roles and permissions

Access in Twinsity is granted per project, per workspace or per organization. The roles are independent, so someone can be an administrator of one workspace and a viewer in another.

The roles

Project roles apply to one project:

Role For
Viewer Reading a project: observations, images and reports, without changing anything
Editor Doing inspection work: recording observations and generating reports
Admin An Editor who also administers the project: its settings, its Observation Profile, who has access, and deleting it

Workspace roles apply to every project in a workspace, and follow the same pattern: Viewer, Editor, Creator, Admin.

Organization admin covers everything in the organization.

Two things that surprise people

An Editor cannot change project settings. Editors record findings: observations, sections and reports. Changing a project's details, choosing its Observation Profile, deleting it or managing its members all need Admin. An Editor who reports that the project's settings are greyed out has the role working as intended.

Only a Creator or Admin can start a new project. A Project Admin manages an existing project, and cannot upload a new one. If a colleague reports that New project is greyed out, this is almost always why.

What each role can do

Proj Viewer Proj Editor Proj Admin WS Viewer WS Editor WS Creator WS Admin Org Admin
View observations, images, reports
Use Smart Detections
Create and edit observations · ·
Delete observations · ·
Capture section views · ·
Generate and delete reports · ·
Edit project settings · · · ·
Choose the Observation Profile · · · ·
Delete a project · · · ·
Invite people to a project · · · ·
Upload a new project · · · · ·
View Observation Profiles
Create and edit Observation Profiles · · · · · ·
Create, rename and delete workspaces · · · · · ·
Manage workspace members · · · · · ·
Invite people to the organization · · · · · · ·

Being given a project also gives you basic read access to the workspace holding it: you can see the workspace, its project list, and its Observation Profiles. That is why every project role can view profiles even though profiles belong to the workspace.

Choosing a role

  • Someone who only needs to read: Viewer.
  • An inspector recording findings: Editor, on the project or the workspace. Editors cannot change project settings, so this is the safe default for inspection work.
  • Someone who sets up new projects: Creator or Admin at workspace level.
  • Someone who manages people: Admin at the level they should manage.

Prefer the narrowest role that covers the job. Widening one later is a moment's work.

Related