Roles and permissions
Know what Owners, Admins, Managers, Team Leaders, Members, and Guests can see and change.
Trellis enforces permissions on the server, not just in the interface. Hiding a button is not the same as blocking an action, and Trellis does both.
Workspace roles set the broad boundary
Owners hold everything, including workspace deletion, restore, and promoting another owner. Admins manage settings, structure, teams, backups, exports, automations, and the audit log, but cannot delete the workspace. Managers can shape structure, run automations, manage tasks and teams, and export projects. Members work on tasks assigned to them. Guests are external people who see only what has been shared with them.
Team roles refine operational scope
Inside a team, a person can additionally be a team lead. That is separate from the workspace role and governs the team queue and its membership, so an ordinary Member can lead a team without gaining workspace-wide authority.
The server enforces access
Every permission-sensitive action is checked again on the server when it is submitted. A blocked action returns a clear error rather than silently failing, and sensitive changes are written to the audit log with the actor and a timestamp.
Choose access levels for guests deliberately
Each guest share carries a level. View lets a client watch progress, Comment lets them respond in context, and Approve lets them make a binding decision. Set this per person and per project, so a stakeholder who should never approve simply cannot, regardless of what they can see.
Review access on a schedule
Access tends to accumulate. Once a quarter, open your people list and check three things: that former contractors are disabled rather than merely inactive, that nobody holds Admin who no longer needs it, and that guest shares still point at engagements that are actually live.
Worth remembering
- Give people the lowest role that lets them do their job, then promote when the need is proven.
- Guests are scoped per project, so sharing one project never exposes another.
- Some roles are plan dependent. Admin and Manager are available on Studio and above.
Common questions
No. A guest can only reach the specific projects shared with them, and internal teams, other clients, and custom fields do not render for them.
No. Client guests are free and unlimited on paid plans and never count as a billable seat.
Related guides
Ready to apply this?
Bring a real project into Trellis with guided onboarding, or ask us anything about your setup.