All Features
Govern · Permissions

Roles and permissions

Invite the team, then decide who can see what and who can change it. Roles to start from, then groups, departments, and access set per app and per record when the general answer is not good enough.

Team 8 members · 1 invite pending

Members

O

Oytun

oytun@acme.com

Owner
M

Maria

maria@acme.com · Sales

Admin
D

Deniz

deniz@acme.com · Engineering

Editor
S

Sam

sam@northlight.io · Contractors

Viewer

elif@acme.com

Invited as Editor · link expires in 5 days

Pending

Groups

Engineering 3 Sales 4 Contractors 1

Permissions

Sales can open Lead ROI Auditor

Contractors can see billing

Deniz can delete records (override)

Who can open what, who can change it, and who is still just invited. Set it once and it holds across every app in the workspace.

What Permissions gives you

Role-Based Access

Four built-in roles: Owner, Admin, Editor, Viewer. Clear permissions hierarchy.

User Groups

Create groups for bulk permission assignment. "Engineering", "Sales", "Contractors".

Departments

Give a whole department its access once, instead of repeating the same decision per person.

Email Invitations

Invite team members by email with expiring tokens. Secure onboarding flow.

Permission Overrides

Grant or deny specific permissions per user or group. Fine-grained when you need it.

App-Level Access

Control access at the app level. Some apps for everyone, some for specific teams.

Member Status

Track pending, active, and suspended members. Full lifecycle management.

Why Permissions matters

How Permissions works

Access is one of those things you only think about after it goes wrong. Permissions is where you settle it up front, and it takes a minute. Four built-in roles (Owner, Admin, Editor, Viewer) cover most of a company on day one. Groups and permission overrides are there for the rest, and you only touch them when you actually need them.

Inviting team members is simple: enter their email address, select a role, and Runwork sends a secure invitation with an expiring token. New members join with their assigned permissions already in place. You can track invitation status (pending, accepted, or expired) and resend invitations when needed. The entire member lifecycle is managed: invite, activate, adjust permissions, and when necessary, suspend or remove.

User groups add a powerful layer of organization. Create groups like "Engineering", "Sales", or "Contractors", then assign permissions to the group rather than individual users. When a new team member joins, adding them to the appropriate groups immediately grants the right access levels. Groups also simplify app-level access, letting you make certain apps available only to specific groups.

Permission overrides handle edge cases. The four built-in roles cover most scenarios, but sometimes you need exceptions: an Editor who can also delete records, a Viewer who can access one specific app others can't. Override specific permissions per user or group without disrupting the overall role hierarchy. This flexibility extends across workspaces, where the same user can have different roles in different contexts.

Every access change is logged in your audit logs. See who invited whom, when permissions changed, and who accessed what. This visibility is essential for security reviews and compliance requirements.

Frequently Asked Questions

How do we let one group reach material the rest of the team should not see?
Give that group access to those apps and records, and give nobody else it. Access is decided per resource, so the material stays where the work is happening rather than being exiled to somewhere separate, and the people who should not see it do not see it. A separate workspace is still the right answer when the two sides share nothing at all, because a workspace has its own data, its own connected tools and its own members. Use it as a boundary between unrelated worlds, not as a workaround for permissions.
What roles are available in Runwork team management?
Runwork includes four built-in roles: Owner (full control including billing and workspace deletion), Admin (manage users and settings, but cannot delete the workspace), Editor (create and modify content but cannot manage users), and Viewer (read-only access). Each role inherits permissions from lower roles in the hierarchy.
How do user groups work in Runwork?
User groups let you organize team members and assign permissions collectively. Create groups like "Engineering" or "Sales", add members to groups, and assign app access or permission overrides at the group level. When you add someone to a group, they immediately inherit all group permissions. This makes onboarding and access management much simpler than individual assignments.
Can I give someone extra permissions beyond their role?
Yes. Permission overrides let you grant or deny specific permissions to individual users or groups, regardless of their base role. For example, you can give an Editor the ability to delete records, or restrict an Admin from accessing certain sensitive apps. Overrides provide fine-grained control without disrupting your overall role structure.
How do I invite team members to my workspace?
Invite team members by entering their email address and selecting a role. Runwork sends a secure invitation with a time-limited token. You can track invitation status (pending, accepted, expired) from the team management dashboard. Expired invitations can be resent. Once accepted, members immediately have access based on their assigned role and groups.

Use Cases

Team collaboration Contractor access Department separation Client access control

Related Features

See How Teams Use Permissions

Ready to try Permissions?

One shared cloud under the AI tools your team already uses.