Roles and permissions
The four organization roles, the four workspace roles, guests, and who can do what in Openbook.
Permissions work at two levels, and they are genuinely two different things:
- An organization role says what a person is to the company. It lives at the Vibeforce account and is the same in every Vibeforce product.
- A workspace role says what a person may do inside one Openbook workspace. It lives in Openbook and is set per workspace.
Both use the same four names — owner, admin, member, viewer — which is convenient to remember and worth keeping straight.
Organization roles
Every member of an organization holds one of four roles, assigned at the account service:
| Role | Who it's for |
|---|---|
| Owner | The one person responsible for the organization |
| Admin | People who run the organization day to day |
| Member | Everyone who does the work |
| Viewer | Stakeholders who need to see and not change |
Three things follow from where these live:
- Changing them happens at the account, not here. The Members & access button on the organization's Home in Openbook opens the account service, where anything to do with who is in the organization is decided. Openbook reads the answer.
- The role travels. Make someone an admin once and they are an admin in every Vibeforce product that organization uses.
- Viewers are free. Openbook counts a billable seat as an organization member whose role is anything other than viewer.
Inside Openbook, an organization owner or admin is treated as an administrator of every workspace in that organization — they get workspace-admin abilities directly, without being added to each workspace as an admin.
Workspace roles
Inside a workspace, each member holds one of the same four roles. This is what the workspace's Settings → Community tab sets, and it is what the guards actually check when you click something. That tab also shows this table, under Roles & permissions.
| Capability | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
| View rooms and content | yes | yes | yes | yes |
| Create and edit content | yes | yes | yes | — |
| Create and delete rooms | yes | yes | — | — |
| Manage members and roles | yes | yes | — | — |
| Change workspace settings | yes | yes | — | — |
| Delete the workspace | yes | — | — | — |
- Owner — created the workspace. Full control, including deleting it. There is exactly one, and the role cannot be assigned or changed; it belongs to whoever created the workspace.
- Admin — manages members and roles, creates and deletes rooms, changes settings.
- Member — creates and edits content in the rooms they can reach.
- Viewer — read-only.
Only admin, member and viewer can be assigned. The member list and the Add Member dialog name them by what they allow: Full access assigns admin and Read only assigns viewer; the member role is assigned through Bulk Invite (a Role column of member). When you change someone's workspace role they are notified, with a link to the workspace.
The owner's role cannot be changed and the owner cannot be removed from their own workspace. If ownership needs to move, that is a separate operation — see Transferring ownership.
Guests
A guest is not a fifth role. It is a flag on top of viewer-shaped permissions, and it changes what they can see rather than what they can do.
A normal viewer can read the whole workspace. A guest can read only the rooms they were explicitly added to — including rooms whose visibility is set to everyone in the workspace. That makes a guest the right shape for a client or a contractor who should see one board and nothing around it.
- Guests are always read-only. Permissions supplied in a guest invitation are ignored.
- A guest must already have a Vibeforce account before you can invite them, because their scoping hangs off a real account.
- You add and remove a guest's rooms one at a time with Manage rooms on the guest's row in the workspace's Settings → Community.
- Giving a guest a normal workspace role ends guest status. That is the only way out of it.
- Guests never count as billable seats.
Room visibility
On top of roles, each room has its own visibility:
- Everyone in the workspace — any member of the workspace can open it.
- Only certain people — you pick who; it is hidden from everyone else.
Visibility decides who can see a room. Roles decide who can change what is inside it. A managers-only Check-in room and an open Feed room sit happily in the same workspace.
Workspace owners and admins can see every room in their workspace regardless of its visibility. Guests are the exception in the other direction: they see only their listed rooms, whatever the visibility says.
Who can do what — quick reference
- Add, remove or re-role an organization member, or transfer the organization: at the Vibeforce account, by the organization's owner or an admin.
- Add someone to a workspace, change a workspace role, or invite a guest: in the workspace's Settings → Community, by the workspace's owner or an admin (or by an organization owner or admin).
- Set a workspace's or a room's visibility: the workspace's Settings → General and Settings → Rooms, by the same people.
- Create or delete a room: the workspace's owner or an admin.
- Manage billing: an organization owner or admin, on Openbook's organization Settings page.
- Create and edit work: owner, admin and member, subject to room visibility.
- View work: everyone, within the workspaces they can open, the room's visibility, and — for a guest — their room list.
Choosing roles for a typical team
A sensible default for a small company:
- Organization owner: the founder or whoever owns the billing relationship.
- Organization admin: the one or two people who add and remove staff.
- Organization member: everyone who does the work.
- Organization viewer: advisors, clients, and anyone who asked to be kept in the loop. They cost nothing.
Then, per workspace, leave most people as member, make the one or two people who run the workspace admin, and use room visibility for the exceptions. Reach for guest only when someone should see a named room and nothing else.