Skip to main content

Control who can access a project

Use this guide when you want to decide who can see or edit a project's tickets, boards, docs, and project work.

Choose the right access pattern

Before changing settings, decide what you want:

You wantChoose
Everyone in the organisation can see and edit the projectOpen project
Only selected people or groups can see the projectRestricted project
Some people can view but not editRestricted project + Viewer role
A team can view and edit ticketsRestricted project + Member role
A project owner can manage access and settingsLead or Admin role

Open projects are writable by organisation members. If that is too broad, use a restricted project.

The built-in Open and Restricted schemes match the original visibility choices. Organisation admins can create fine-grained reusable schemes in Organisation Settings > Permissions and assign them from a project's Access tab.

Allow only one group to view and edit tickets

Use this for customer delivery, confidential initiatives, or any project where one team should own the work.

  1. Open Organisation Settings.
  2. Open Groups.
  3. Create a group for the team, such as Delivery Team.
  4. Add the people who should work in the project to that group.
  5. Choose the built-in Restricted project scheme.
  6. Open the project's Access tab, then choose Groups.
  7. Add the delivery group.
  8. Choose Member if its members should view and edit tickets.
  9. Assign Lead or Admin to the people or groups that should manage project settings.
  10. Save the access changes.
  11. Ask someone outside the group to confirm they cannot see the project.

Result: the granted group, project leads, and organisation administrators can see the project. Members can edit tickets. Other organisation members should not see the project in project lists, ticket lists, boards, TQL results, search results, or AI context.

Let a group view but not edit

Use this when leadership, stakeholders, or support teams need visibility but should not change work.

  1. Confirm the project uses the built-in Restricted project scheme or a custom scheme that grants browse permissions to Viewer.
  2. Open Access > Groups and add the stakeholder group.
  3. Choose Viewer.
  4. Save.
  5. Open the project as one of those users or ask a teammate to verify.

Viewers can read the project but should not create, edit, move, comment on, or delete tickets.

Let one person edit temporarily

Use a person role assignment for short-term exceptions.

  1. Open the project.
  2. Open the project's Access tab and choose People.
  3. Select Add people.
  4. Search for the person.
  5. Choose Member.
  6. Save.
  7. Add a reminder to remove the assignment after the review or handoff.

Do not create a new group for one short-term person unless that pattern will repeat.

Make a project visible to everyone but editable by only a few people

Do not use an open project for this. Open projects let organisation members edit.

Instead:

  1. Use the built-in Restricted project scheme.
  2. Open the project's Access tab.
  3. Add the broad audience as Viewer.
  4. Add the working team as Member.
  5. Add project owners as Lead or Admin.
  6. Save.

Result: the broad audience can read, while the working team edits.

Remove someone's project access

  1. Open the project.
  2. Open Access > People.
  3. Find the person.
  4. Remove their direct project roles if any exist.
  5. Check whether they still belong to a group with project access.
  6. Remove them from that group in Organisation Settings > Groups, or remove the group's project roles from Access > Groups.
  7. Save.
  8. Ask the person to refresh TOW and confirm they no longer see the project.

Removing direct roles is not enough if the person also receives access from a group.

Change someone's project role

  1. Open the project.
  2. Open Access > People.
  3. Find the person.
  4. Select Edit roles.
  5. Select every role the person needs:
    • Viewer for read-only.
    • Member for normal editing.
    • Lead for project ownership.
    • Admin for full project administration.
  6. Save.

Keep most contributors as Member. Use Lead or Admin only for people who should manage settings and access.

Troubleshoot access problems

If someone cannot see a project:

  1. Confirm they are a member of the organisation.
  2. Check which permission scheme the project uses.
  3. Check direct person role assignments.
  4. Check group role assignments.
  5. Check whether they are in the expected group.
  6. Ask them to refresh the app.

If someone can see a project but cannot edit:

  1. Check whether they are Viewer.
  2. Change them or their group to Member if they should edit.
  3. If they cannot move a ticket, check workflow transition rules.
  4. If they cannot assign a ticket, check whether the assignee can access the project.

If someone can edit more than expected:

  1. Check direct person role assignments.
  2. Check every group they belong to.
  3. Check whether they are an organisation Owner or Admin.
  4. Change from the built-in Open scheme to Restricted, or ask an organisation admin to choose a more suitable custom scheme.

Related guides: Use groups for project access, Review access before sensitive work, Configure workflows and required fields.