Roles and permissions
How roles work in ProjectBrain, what each default role can do, and why a role in one organization grants nothing in another.
A role is a named set of permissions. Each person holds a role in each organization they belong to, and the role decides what they can see and do there.
Roles belong to one organization
Section titled “Roles belong to one organization”A role counts only in the organization where you hold it. If you are an owner in one organization and a team member in another, you have a team member’s permissions in the second one. Nothing carries across.
This also applies to people who work for several clients or companies. Switching organizations switches the role that applies.
The default roles
Section titled “The default roles”Every organization starts with the same default roles:
| Role | Meant for |
|---|---|
| Owner | The people who run the organization’s account. Owners can do everything, and only owners can delete the organization, manage billing, or change roles. |
| Executive | Senior leaders who need almost everything, without organization-level controls. |
| Team lead | People who run teams and projects day to day. |
| Team member | Individual contributors who do the work on projects they can see. |
| Client (read & comment) | Clients who read and comment on shared wiki pages. |
| External | Invited outside people. This role holds no permissions of its own. An external person sees only the projects they were invited to. |
To give someone a role, go to Settings > Organization > People. To change what a role can do, see Custom roles.
What each default role can do
Section titled “What each default role can do”The table below shows the permissions each default role starts with. Your organization may have changed them. To see your own, open Settings > Organization > Roles and permissions and pick a role.
Permissions also stack with project visibility. A permission to edit projects does not let someone open a project they cannot see, such as a walled-off project they are not a member of.
| Permission | Owner | Executive | Team lead | Team member | Client (read & comment) | External |
|---|---|---|---|---|---|---|
| Organization and people | ||||||
| Organization: deleteOwner only | Owner can | Executive cannot | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Organization: manage billingOwner only | Owner can | Executive cannot | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Invite people, change their roles and remove them | Owner can | Executive cannot | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Organization: update | Owner can | Executive cannot | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Organization: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Projects and sharing | ||||||
| Archive a project and write up its lessons | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| See archived projects and their lessons | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Record and edit decisions | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| See the decision journal | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Review outside access (clients and vendors) | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Projects: create | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Projects: delete | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Share projects by email | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Manage a project's team | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Wall off projects and open a walled project with a recorded reason | Owner can | Executive cannot | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Comment on, suggest changes to and review project timelines | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Projects: update | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Projects: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| See project budgets | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Create, edit and archive this organization's timeline templates | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Teams and structure | ||||||
| Departments: manage | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Departments: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Organization structure: audit | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Subsidiaries: manage | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Subsidiaries: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Teams: create | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Teams: delete | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Teams: manage | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Teams: manage members | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Teams: update | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Teams: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Clients, vendors and rates | ||||||
| Clients: create | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Clients: delete | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Clients: edit | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Clients: manage contacts | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Clients: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Clients: view financials | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Rate cards: create | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Rate cards: delete | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Rate cards: edit | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Rate cards: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Vendors: create | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Vendors: delete | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Vendors: edit | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Vendors: manage contacts | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Vendors: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Vendors: view financials | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Documents, estimates, blueprints and guardrails | ||||||
| Blueprints: approve | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Blueprints: create | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Blueprints: delete | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Blueprints: update | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Blueprints: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Custom fields: manage | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Documents: create | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Documents: delete | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Documents: force checkin | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Documents: update | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Documents: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Estimates: analyze | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Estimates: approve | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Estimates: create | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Estimates: delete | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Estimates: track actuals | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Estimates: update | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Estimates: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Guardrails: create | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Guardrails: curate | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Guardrails: delete | Owner can | Executive cannot | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Guardrails: update | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Guardrails: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Guardrails: vote | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Time tracking | ||||||
| Time entries: create | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Time entries: delete | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Delete everyone's time | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Time entries: export | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Time entries: import | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Time entries: update | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Edit everyone's time | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Time entries: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| See everyone's time | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Reports and health scores | ||||||
| Health scores: recalculate | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Health scores: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Reports: export | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Reports: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| See reports for all teams | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Briefs and SOWs | ||||||
| Project Docs: admin | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Project Docs: create | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Project Docs: edit | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Project Docs: edit any | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Project Docs: export | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Project Docs: review | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Project Docs: send | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Project Docs: sign | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Project Docs: submit | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Project Docs: templates manage | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Project Docs: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Resource planning | ||||||
| Resource planning: allocate | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Resource planning: audit | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Resource planning: capacity manage | Owner can | Executive cannot | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Resource planning: flags manage | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Resource planning: manage | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Resource planning: view | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Standups | ||||||
| Start a new standup | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Run a standup: ask questions, nudge people who have not posted | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Edit or delete any standup, and manage templates | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| See standups and post their own update | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Agents | ||||||
| Approve plans for agents, pause them, take over their work and change agent settings | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| See the Agents page and what AI agents are working on | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Workflow automation | ||||||
| Workflow templates: ai author | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Workflow templates: apply | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Workflow templates: bulk apply | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Workflow templates: escalations | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Workflow templates: manage | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Workflow templates: observability | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Webhooks: manage | Owner can | Executive cannot | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Wiki | ||||||
| Wiki attachments: manage | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Wiki attachments: upload | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Wiki comments: create | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) can | External cannot |
| Wiki comments: moderate | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Wiki pages: approve | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Wiki pages: archive | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Wiki pages: create | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Wiki pages: delete | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Wiki pages: move | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Wiki pages: reject | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Wiki pages: restore | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Wiki pages: share | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Wiki pages: submit | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Wiki pages: update | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Wiki pages: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) can | External cannot |
| Wiki page history: compare | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Wiki page history: restore | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Wiki page history: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) can | External cannot |
| Wiki templates: approve | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Wiki templates: submit | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Wiki templates: use | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Open other people's personal wikis (recorded) | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Wikis: ai manage | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Wikis: archive | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Wikis: audit view | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Wikis: create | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Wikis: delete | Owner can | Executive cannot | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Wikis: permissions manage | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Wikis: restore | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Wikis: update | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Wikis: view | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) can | External cannot |
| AI and MCP | ||||||
| Manage AI connection rules for the organization | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Connect their own AI tools | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Let AI start workflows | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Focus and Cortex | ||||||
| Cortex: manage | Owner can | Executive cannot | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Cortex: use | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Focus mode: manage | Owner can | Executive cannot | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Focus mode: use | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Focus mode: view aggregates | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Use the focus coaching toolkit | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Code and GitHub | ||||||
| Merge pull requests from a task | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Connect the organization to GitHub | Owner can | Executive can | Team lead cannot | Team member cannot | Client (read & comment) cannot | External cannot |
| Link tasks to pull requests and issues | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
| Choose a project's repositories | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| Manage GitHub issue syncing | Owner can | Executive can | Team lead can | Team member cannot | Client (read & comment) cannot | External cannot |
| See GitHub links on tasks | Owner can | Executive can | Team lead can | Team member can | Client (read & comment) cannot | External cannot |
Platform staff
Section titled “Platform staff”A small number of ProjectBrain staff hold platform roles, for support and for reviewing the shared template library. Platform roles are separate from your organization’s roles. No role in your organization can be given these staff powers, and owners cannot grant them.