Permissions in detail

The four access levels, how access flows down through spaces, and exactly who can do what in tasks, docs, dashboards, chat, attendance and settings.

Your role covers the whole workspace. Your access covers one item at a time β€” one space, project, doc or dashboard. This page is about that second half, and then what both halves mean in each part of Kokar.

If you have not read Roles yet, start there.

The four access levels

Every space, folder and project is shared using one of these.

LevelGood forWhat it allows
View onlyStakeholders, observersRead. Nothing else β€” no comments
InteractClients, contractors, assigned peopleComment, attach files, tick checklists, write a task's description, and set the status and assignees of tasks assigned to them
EditThe team doing the workEverything in Interact, plus create and edit tasks and content freely β€” including the status and assignees of any task, not only your own
Full editProject managers, space leadsEverything, plus settings, members, statuses and deleting

The jump that matters most is Edit β†’ Full edit. Edit is for people doing the work; Full edit is for people running it. Only Full edit can change an item's settings, manage who else is in it, set manager-only statuses, or delete other people's things.

Public and private

Every space, folder and project is one or the other.

Public β€” everyone in the workspace can open it, at whatever level you set as its default. A new space starts everyone on Edit, so the whole workspace can create and edit work inside it without also being able to delete other people's tasks or change who has access. Raise or lower that whenever you like.

Private β€” only the people added to it can see it. For everyone else it does not appear anywhere and cannot be opened.

Private is a hard stop

Private overrides everything above it. Full edit on a space does not get you into a private project inside that space β€” you have to be added to the project itself.

This applies to admins as well. Only the workspace owner sees private items they were never added to.

How access flows down

Spaces hold folders, folders hold projects, projects hold tasks. Access flows downwards, and there are only two rules.

  1. Being named beats a default. If someone added you to an item by name, that is your level β€” wherever else you might have picked one up.
  2. The closest one wins. Between two things that both apply, the one nearer the item decides. Project beats folder, folder beats space.

A task has no sharing of its own. It uses whatever you have on the project it lives in.

An example

The Nike space is public and has been set to give everyone Full edit. Inside it is a Legal Docs folder, also public, but where everyone gets View only by default.

  • Sara was added to the Nike space by name, as Full edit. She opens a project in Legal Docs and gets Full edit β€” she was named, and being named beats the folder's default.
  • Bilal was never added to anything. He opens the same project and gets View only β€” no name anywhere, so the closest default applies, and that is the folder's.

Now the team makes a Confidential Q4 project private and adds nobody.

  • Sara has Full edit on the whole space, and still cannot open it.
  • An admin cannot open it either.
  • The workspace owner can.

Spaces, folders and projects

Creating one of these is the one thing that needs both halves to agree: your role has to allow it at all, and you need Create access where you are putting it.

ActionWho
Create a spaceAnyone whose role allows it β€” members can by default
Create a folder or projectAnyone with Edit or above where it goes in
Open itAnyone with View only or above
Rename, change icon, descriptionFull edit
Change public/private, manage membersFull edit
Manage task statusesFull edit
Manage custom fieldsOwners and admins β€” see below
ArchiveAnyone who can edit it
UnarchiveOwners and admins, who can also reach it
DeleteFull edit, if your role still allows deleting
Reorder spaces in the sidebarOwners and admins β€” the order is everyone's, not yours

Only creating a space is decided purely by role β€” a space sits at the top, so there is no parent to check Create access against. Folders and projects go inside something, so the place you are putting them decides: Edit or above there is enough, whatever your role.

Statuses and custom fields part company here, even though they sit side by side in the same dialog. Statuses are a Full edit thing: run a space, set its workflow. Custom fields β€” the extra columns that appear on every task in the space β€” stay with owners and admins, and Full edit does not unlock them. On Enterprise a custom role can be given them.

Tasks

Tasks take their permissions from the project they are in. There is no per-task sharing.

ActionLevel needed
See a taskView only
Comment, reactInteract
Attach files, tick checklist itemsInteract
Write the descriptionInteract
Change status or assigneesEdit β€” or Interact, if the task is assigned to you
Change title, dates, priority, estimate, tagsEdit
Create a taskEdit
Move or reorder a taskEdit β€” or Interact, for a task assigned to you
Archive a taskEdit
Delete a taskFull edit β€” and by default members only their own
Set a manager-only statusFull edit

Three of those are worth spelling out.

If it is assigned to you, you can move it along. Someone at Interact β€” a contractor, a designer, a client-side reviewer β€” can change the status and assignees of tasks assigned to them, without being able to edit the project generally. They cannot do it to anyone else's task.

At Edit that restriction is gone: status and assignees are ordinary fields, settable on any task in the project, whoever it belongs to. So handing work to a teammate β€” or taking it on yourself β€” needs Edit, unless the task is already yours.

The description is open at Interact, the rest of the fields are not.

Manager-only statuses. A status can be marked manager-only β€” "Approved", "Accepted", "Signed off". It shows a lock and is greyed out for everyone without Full edit on that project, so nobody approves their own work.

Creating something is not a standing right to delete it

Deleting needs Full edit now, not when you made the thing. If you created a task while you had Full edit on a project and your access there was later reduced, you can no longer delete it β€” your permission changed, and that is the point of changing it.

On top of that, workspaces start with members limited to deleting their own work. An admin can lift that, or tighten it further, in Settings β†’ Roles.

Docs

Docs are organised the same way as the rest of the workspace β€” space β†’ folder β†’ subfolder β€” and hold pages and uploaded files. It is a separate tree from the spaces in your main sidebar, but the words mean the same thing, so "put it in the Brand folder" reads the same in both places.

Docs use three levels β€” View, Edit and Full edit. There is no Interact for docs. The whole feature is covered in Docs, with the sharing detail in Sharing and privacy.

Sharing applies to a whole branch

You do not share every page one by one. Sharing is set on a space or folder, and everything inside it follows.

Share a folder separately and it becomes its own island: from then on it has its own audience, and the space above it no longer decides who gets in.

New spaces start out private to the person who made them.

ActionLevel needed
Open and readView
Edit content, renameEdit
Create anything insideEdit on the space or folder it goes in
Share, change private/publicFull edit
Pin to a workspace space or projectFull edit
Move or drag-and-dropFull edit on both ends β€” where it comes from and where it goes
DeleteFull edit β€” and by default members only their own pages
Move or reorder a folder at the top levelOwners and admins only
Move or reorder a page or file at the top levelFull edit on it

Whoever creates a space starts with Full edit on it β€” that is a floor, not a guarantee. It is there so a new space is never stranded without anyone who can manage it. If someone later adds the creator to that space at a lower level, the level they were given is the one that applies.

Only containers are locked at the top of the tree. Reordering top-level spaces, promoting a folder up to the top, or filing one into another are owner-and-admin actions, because they reshape the tree everyone sees. A top-level page is different β€” it is usually a personal note, and creating one is the only way a member gets one β€” so anyone with Full edit on it can reorder it, file it into a folder they manage, or pull it back out.

Why moving needs Full edit. Rearranging the tree changes it for everyone, so it is treated like sharing or deleting rather than like typing. It is also what keeps drag-and-drop inside your own patch: you can reorganise a folder you manage all you like, but you cannot pull pages out of it into one you only have View on.

Position decides the name. A container at the top of the tree is a space; the same container moved inside another becomes a folder, and one level deeper a subfolder. Move it back out and it is a space again.

Pinning grants access. Pinning a doc to one of your workspace spaces also gives that space's people access to it β€” that is the point of pinning. A private doc stays private otherwise.

Moving and sharing. Something you shared deliberately keeps its own audience wherever you move it. Something that simply inherited from its parent picks up its new parent's sharing instead β€” and if you pull it out to the top level, it keeps the audience it already had, so it does not go dark on the people using it.

Dashboards

Dashboards use the same three levels as docs β€” View, Edit, Full edit.

ActionLevel needed
Open the dashboard and see its cardsView
Add, edit, rename, move or resize a cardEdit
Share it with someoneEdit
Delete a cardFull edit
Rename the dashboard, change its visibilityFull edit
Delete the dashboardFull edit

Editors build things up; only managers tear them down. That is why deleting a card sits one level higher than adding one.

Where a dashboard lives changes who can open it

  • A dashboard filed in a space, folder or project belongs to that location's people. You need access to the location to open it β€” being invited to the dashboard alone is not enough.
  • A dashboard in the Hub, filed nowhere, works on visibility alone: public means everyone in the workspace, private means the people invited to it.

Cards check your access separately

Opening a dashboard does not mean you see every number on it. Each card checks your access to the data it draws on, so a card built on a space you cannot see simply shows nothing instead of leaking the totals.

Some cards are managers-only by nature β€” Estimate vs tracked, or someone else's work log. Your own work log is always visible to you.

Dashboards cannot be archived

Every other kind of item can be archived. Dashboards are deleted instead. A dashboard filed in a space that gets archived stays reachable β€” archiving hides a location, it does not lock what is inside it.

Chat

Chat does not use workspace roles or access levels at all. The only question is whether you are in the conversation.

ActionWho
Create a roomAnyone in the workspace
Read and post in a roomMembers of that room
Edit or delete your own messageYou, any time
Delete someone else's messageRoom admins, in their own room
Rename the room, change its pictureRoom admins
Add or remove members, make someone an adminRoom admins
Edit a postIts author only
Delete a postIts author, or a room admin
Pin a postRoom admins
Edit or delete a post commentIts author only

Whoever creates a room is its first admin.

Chat is private from everyone

This is the one place where nobody can get in from outside. Being a workspace admin β€” or the owner β€” does not let you read, join or moderate a room you are not a member of. Rooms are run by their own admins.

Time and attendance

Attendance goes by role alone β€” there is no per-space sharing for it.

Everyone can:

  • Clock in and out
  • See their own hours for today
  • Look back over their own past days over any range, up to six months
  • See their own time-off balance, request time off, and cancel a request

Owners and admins can also:

Today's overviewWho is in, and how each person's day is going
Anyone else's historyLook up another person's past days, and export the PDF
Fix someone's hoursCorrect a clock-in or clock-out that was wrong or missed
Time offApprove and decline requests
Set the rulesWorking weeks, holidays, quotas, office locations, and per-person exceptions

On Enterprise, a custom role can be given just today's overview without the rest.

Your own record is yours to read. You do not need to ask anyone for a list of the days you worked. What needs the manager permission is reading somebody else's record, and the PDF export, which is on the computer only.

Archive and trash

Archive hides something without changing it β€” it still opens by link, and it is still editable. Trash deletes it, with 30 days to change your mind.

ActionWho
Archive anythingAnyone who can edit it
Unarchive a space, folder or projectOwners and admins
Unarchive a task or doc pageAnyone who can edit it
Restore from trashWhoever deleted it. Owners and admins can also restore anything public, and the owner anything at all
Restore a deleted chat postWhoever deleted it, or an admin of that room β€” workspace role plays no part

Members see the archive β€” what they do not get is the button to put a space, folder or project back, because that changes the sidebar for everybody. In trash, a member only ever sees their own deletions.

Deleted chat posts follow chat's rules, not the workspace's: one shows up in your trash if you deleted it or you are in the room, and nowhere else. Being an owner or admin does not put a private room's deleted posts in front of you.

Full detail is on Archive and trash.

Workspace settings and billing

PageWho
GeneralEveryone reads it; owners and admins edit
AutomationsEveryone; you see the rules on locations you can already read
MembersOwners and admins
Roles & PermissionsOwners and admins
AttendanceOwners and admins
Audit logsOwner only by default, Enterprise only β€” an owner can switch admins on in Settings β†’ Roles
Billing & PlanOwner only
Delete the workspaceOwner only

There is no Archive page. Archived things reappear where they always lived when you turn on Show archived in the sidebar.

Anything under My Account β€” your profile, notifications, connected apps, trash β€” is yours and needs no permission.

Why can't I see something?

Work down this list; it is almost always one of these.

What you are seeingWhy
A space or project is missing entirelyIt is private and you were not added β€” ask someone with Full edit on it
You can read it but the buttons are greyed outYou have View only or Interact
You can edit tasks but not the project's settingsYou have Edit. Settings and members need Full edit
A status is lockedIt is manager-only β€” Full edit on that project can set it
The "Create space" button is missing everywhereThat is your role, not your access β€” space creation has been switched off for it. Ask an owner or admin
You cannot create a project or folder in one placeThat is your access there. Creating needs Edit or above in that space or folder
The "+" is missing on a docs space or folderYou have View on that branch, not Edit
A dashboard card is emptyThe card draws on something you cannot see, or it is managers-only
Everything is suddenly read-only across the whole workspaceThe workspace has an unpaid invoice β€” reading still works, writing is paused until it is settled

If none of these fit, the person to ask is whoever has Full edit on the item in question β€” or an admin, for anything workspace-wide.

Frequently asked questions

I have Full edit on a space, so why can't I open a project inside it?

The project is private and you were not added to it. A private item is a hard stop β€” access from the space above does not reach into it. Only the workspace owner is exempt.

Why can I comment on a task but not change its title?

You have Interact access. That covers comments, files, checklists and writing the description, plus setting the status and assignees of tasks that are assigned to you. Changing titles, dates and priorities needs Edit.

Can someone with Edit assign people to tasks?

Yes β€” Edit can set the status and assignees of any task in that space or project, not only tasks assigned to them. Interact can do the same but only on tasks already assigned to them. View cannot change a task at all.

Why is one status greyed out with a lock on it?

It is a manager-only status. Only someone with Full edit on that project can move a task into it β€” so nobody signs off their own work.

Can a workspace admin read a chat room they are not in?

No. Chat is decided by who is in the conversation, not by workspace role. An admin who is not in the room cannot read it or moderate it.

A dashboard opens but one of its cards is empty. Is it broken?

Probably not. Cards check your access separately, so a card drawing on a space you cannot see will show nothing rather than leak the numbers. Some cards are also manager-only.

Who can delete a task?

Anyone with Full edit on the project it lives in. By default members can only delete tasks they created themselves β€” an admin can change that in Settings β†’ Roles. Creating a task does not give you a standing right to delete it β€” if your access to that project is later reduced, you lose deletion there too.