Skip to content

Permissions matrix

This is the exhaustive permissions reference for every system defined role in Plane.

For conceptual background, see Roles and permissions. For the role catalog, see Member roles.

How to read this page

Legend

  • ✓ - the role has unconditional access to this permission.
  • +Creator - the role can perform the action only on resources they created.
  • +Lead - the role can perform the action only if they're the teamspace lead.
  • x - the role does not have this permission.

Owner has full access. Workspace Owner holds a full-access wildcard and matches every permission in this document. The Owner column is omitted from individual tables and assumed ✓ throughout.

Workspace Admin and Owner bypass projects. Both have wildcard access to every project resource type, so they appear as ✓ on all project-level permissions even without explicit project membership.

Workspace permissions

Workspace settings

Core workspace configuration: name, logo, currency, domain, archival, deletion, and ownership transfer.

PermissionOwnerAdminMemberGuest
View Workspace
Edit Workspace Settingsxx
Manage Workspacexx
Invite Membersxx
Archive Workspacexx
Delete Workspacexxx
Transfer Ownershipxxx

Only Owner can delete the workspace or transfer ownership.

Member management

Inviting, editing, importing, and removing workspace members.

PermissionOwnerAdminMemberGuest
View Members
Invite Membersxx
Edit Member Detailsxx
Import Members (CSV / SSO)xx
Change Member Rolexx
Remove Membersxx

Role hierarchy is enforced. Admins cannot modify members at the same or higher level than their own.

Project management

Creating and managing projects from the workspace context.

PermissionOwnerAdminMemberGuest
Browse Projectsx
View Project Detailsx
Create Projectsx
Edit Project Settingsxx
React to Projectsx
Publish Projects (make public)x
Archive Projectsxx
Delete Projectsxx
Manage Project Accessxx

Guests can only see projects they've been explicitly added to.

Role administration

Creating and managing custom roles and project roles.

PermissionOwnerAdminMemberGuest
View Custom Rolesxx
Create Custom Rolesxx
Edit Custom Rolesxx
Delete Custom Rolesxx
View Project Rolesxx
Create Project Rolesxx
Edit Project Rolesxx
Delete Project Rolesxx
Define Role Permissionsxx

Custom roles and permission schemes are an Enterprise feature.

Wiki

Workspace-level wikis.

PermissionOwnerAdminMemberGuest
View Wikix
Create Wiki Pagesx
Edit Wiki Pagesx
Share Wiki Pagesx
Delete Wiki Pagesx
Comment on Wiki Pagesx

Workspace Views

Workspace-level saved filters and view management.

PermissionOwnerAdminMemberGuest
View Workspace Views
Create Workspace Viewsx
Edit Workspace Views+Creatorx
Share Workspace Viewsx
Publish Workspace Viewsx
Export Workspace Viewsx
Delete Workspace Views+Creatorx

Members can only edit and delete views they created themselves.

Initiatives

Cross-project initiative tracking, including comments, attachments, links, and updates.

PermissionOwnerAdminMemberGuest
View Initiativesx
Create Initiativesxx
Edit Initiativesxx
Manage Initiativesxx
Delete Initiativesxx
Edit Initiative Comments+Creatorx
Delete Initiative Comments+Creatorx
Delete Initiative Attachments+Creatorx
Post Initiative Updatesx
Edit Initiative Updatesx
Delete Initiative Updatesx

Teamspaces

Browsing, creating, and managing teamspaces.

PermissionOwnerAdminMemberGuest
Browse Teamspacesx
View Teamspace Detailsx
Create Teamspacesxx
Edit Teamspaces+Leadx
Manage Teamspace Members+Leadx
Delete Teamspaces+Leadx

Editing, deleting, or managing members on a teamspace requires being the teamspace lead. Workspace Admin role alone is not sufficient.

Integrations

Third-party integrations, webhooks, and API tokens.

PermissionOwnerAdminMemberGuest
View Integrationsx
Create Integrationsx
Configure Integrationsx
Delete Integrationsxx
View Webhooksxx
Create Webhooksxx
Edit Webhooksxx
Delete Webhooksxx
View API Tokensx
Create API Tokensx
Delete API Tokensx

Analytics and reporting

Dashboards, analytics, and work logs.

PermissionOwnerAdminMemberGuest
View Analyticsx
Export Analyticsx
View Dashboardsx
Create Dashboardsxx
Edit Dashboardsxx
Delete Dashboardsxx
View Work Logsx
Export Work Logsx
Use AI Featuresx

Customers

Customer and customer request management.

PermissionOwnerAdminMemberGuest
View Customersxx
Create Customersxx
Edit Customersxx
Delete Customersxx
Add Customer Attachmentsxx
Delete Customer Attachmentsxx

Work Item Relations

Managing custom relation type definitions for work items.

PermissionOwnerAdminMemberGuest
View Relation Definitions
Create Relation Definitionsxx
Edit Relation Definitionsxx
Delete Relation Definitionsxx

Templates

Creating and managing workspace-level work item, page, and project templates.

PermissionOwnerAdminMemberGuest
View Templatesx
Create Templatesxx
Edit Templatesxx
Delete Templatesxx

Plane Runner

Workspace-level automation rules and configurations.

PermissionOwnerAdminMemberGuest
View Workspace Automationsx
Create Workspace Automationsxx
Edit Workspace Automationsxx
Delete Workspace Automationsxx

Project permissions

Workspace Owner and workspace Admin have wildcard access to all project resource types and appear as ✓ throughout the project tables. The columns below cover project-level role assignments only.

Project Members

Inviting, editing, and removing project members.

PermissionP-AdminContributorCommenterGuest
View Project Members
Invite Membersxxx
Edit Member Detailsxxx
Change Member Rolexxx
Remove Membersxxx

Work Items

The primary issue surface, including comments, attachments, links, relations, and custom properties.

PermissionP-AdminContributorCommenterGuest
View Issues+Creator
Create Issuesxx
Edit Issues+Creator+Creator
Bulk Edit Issuesxx
Export Issuesxx
React to Issuesx
Delete Issues+Creatorxx
Add Commentsx
Edit Comments+Creator+Creatorx
React to Comments
Delete Comments+Creator+Creatorx
View Attachments
Add Attachmentsx
Delete Attachments+Creator+Creatorx
View Work Item Linksx
Add Work Item Linksxx
Edit Work Item Linksxx
Delete Work Item Linksxx
View Custom Propertiesx
Edit Custom Propertiesxx

Project Guest sees only their own work items (issues created via intake). All other Guest views of issues are filtered to creator.

Epics

Epic lifecycle, including links, properties, and update threads.

PermissionP-AdminContributorCommenterGuest
View Epicsx
Create Epicsxx
Edit Epicsxx
Delete Epics+Creatorxx
View Epic Propertiesx
Edit Epic Propertiesxx
View Epic Updatesx
Post Epic Updatesxx
Edit Epic Updates+Creatorxx
Delete Epic Updates+Creatorxx
Edit Epic Update Comments+Creatorxx
Delete Epic Update Comments+Creatorxx

Modules and Cycles

Feature grouping and sprint/cycle management.

PermissionP-AdminContributorCommenterGuest
View Modulesx
Create Modulesxx
Edit Modulesxx
Manage Module Membersxx
Archive Modulesxx
Export Modulesxx
Delete Modules+Creatorxx
View Cyclesx
Create Cyclesxx
Edit Cyclesxx
Delete Cycles+Creatorxx

Pages and Views

Project-level pages and saved views.

PermissionP-AdminContributorCommenterGuest
View Pages
Create Pagesxx
Edit Pagesxx
Share Pagesxx
Delete Pagesxxx
View Project Views
Create Project Viewsxx
Edit Project Views+Creatorxx
Share Project Views+Creatorxx
Publish Project Views+Creatorxx
Export Project Viewsxx
Delete Project Views+Creatorxx

Page deletion is restricted to project Admins only. Contributors can edit pages but cannot delete them.

Intake

Issue intake and triage workflow.

PermissionP-AdminContributorCommenterGuest
View Intakex
Create Intake Items
Submit Intake Requests
Edit Intake Items+Creator+Creator+Creator
React to Intake Itemsx
Manage Intake Items (accept/reject/snooze)xxx
Configure Intakexxx
Export Intakexx
Delete Intake Items+Creator+Creator+Creator

Status changes (accept, reject, snooze, mark duplicate) are admin-only. Editing is restricted to creators for non-admin roles, with editable fields limited to name, description, priority, target/start dates, labels, and assignees.

Project Configuration

Labels, states, estimates, and milestones.

PermissionP-AdminContributorCommenterGuest
View Labels
Create Labelsxxx
Edit Labelsxxx
Delete Labelsxxx
View States
Create Statesxxx
Edit Statesxxx
Delete Statesxxx
View Estimates
Create Estimatesxxx
Edit Estimatesxxx
Delete Estimatesxxx
View Milestonesx
Create Milestonesxx
Edit Milestonesxx
Delete Milestonesxx

Automation and Workflows

Automations, workflow rules, and recurring work items.

PermissionP-AdminContributorCommenterGuest
View Automationsxx
Create Automationsxxx
Edit Automationsxxx
Delete Automationsxxx
View Workflows
Create Workflowsxxx
Edit Workflowsxxx
Delete Workflowsxxx
View Recurring Itemsxx
Create Recurring Itemsxx
Edit Recurring Itemsxx
Delete Recurring Itemsxx

Project Updates

Progress updates and comments on updates.

PermissionP-AdminContributorCommenterGuest
View Project Updates
Post Project Updatesxx
Edit Project Updates+Creatorxx
Delete Project Updates+Creatorxx
Edit Project Update Comments+Creatorxx
Delete Project Update Comments+Creatorxx

Analytics and Activity

Project analytics and activity logs.

PermissionP-AdminContributorCommenterGuest
View Activity Logx

Project-level links.

PermissionP-AdminContributorCommenterGuest
View Project Linksx
Add Project Linksxx
Edit Project Linksxx
Delete Project Linksxx

Templates

Project-scoped work item and page templates.

PermissionP-AdminContributorCommenterGuest
View Templatesxx
Create Templatesxxx
Edit Templatesxxx
Delete Templatesxxx

Teamspace permissions

Teamspace content access requires teamspace membership. Workspace Owner has full bypass via wildcard. Workspace Admin has resource-level wildcards for teamspace content (view, create, edit, delete teamspace content) but does not automatically have teamspace edit, delete, or member management. Those require the teamspace lead condition.

Teamspace

PermissionTS-MemberTS-Member +Lead
View
Edit settingsx✓ +Lead
Deletex✓ +Lead
Manage membersx✓ +Lead

Teamspace Comments

PermissionTS-MemberTS-Member +Lead
View
Create
Edit (own)+Creator✓ (any)
Delete (own/any)+Creator only✓ (any)
React

Teamspace Views

PermissionTS-MemberTS-Member +Lead
View
Create
Edit+Creator only✓ (any)
Delete+Creator only✓ (any)

Teamspace Pages

PermissionTS-MemberTS-Member +Lead
View
Create
Edit✓ (collaborative)
DeleteOwner only✓ (any)
Archive/UnarchiveOwner only✓ (any)
Lock/UnlockOwner only✓ (any)

Teamspace Page Comments

PermissionTS-MemberTS-Member +Lead
Create
Edit+Creator only✓ (any)
Delete+Creator only✓ (any)
React
Resolve/Unresolve

Edge cases and behavioral nuances

Workspace Owners and Admins can't be locked out of projects

Removing a workspace Owner or Admin from a project removes the project-level membership record but has no functional effect. Their workspace-level wildcards still grant access through inheritance.

Hidden permissions reserved for specific roles

PermissionHolderNotes
Delete WorkspaceOwner onlyCannot be granted via custom roles
Transfer OwnershipOwner onlyCannot be granted via custom roles
Manage BillingOwner + AdminBilling access
Manage Integrations (uninstall)Admin onlySome destructive integration operations

Creator-only business rules

Some restrictions apply regardless of role level. Even an Admin cannot bypass them:

  • A workspace view can only be edited by its creator.
  • A project view can only be edited by its creator.

Permissions that cannot be added to custom roles

PermissionWhy
Full access (*)Reserved for Owner
Delete WorkspaceReserved for Owner
Transfer OwnershipReserved for Owner

Permission dependencies

Some permissions require others to function. The role builder enforces these automatically. Enabling a permission auto-enables its prerequisites, and disabling a prerequisite auto-disables permissions that depend on it.

Common dependencies:

  • Edit requires View on the same resource type.
  • Delete requires View on the same resource type.
  • Member management actions require View Members on the relevant scope.

Feature flags that gate permissions

Some permissions only become available when the corresponding feature is enabled at the workspace or project level. If a feature is disabled, the related permissions exist in the role definition but have no effect.

Conditional grants summary

For convenience, here are all the conditional grants in the system:

RolePermissionCondition
Project ContributorDelete work items, epics, modules, cyclesCreator
Project ContributorEdit and delete comments and attachmentsCreator
Project ContributorEdit, delete, share, and publish viewsCreator
Project ContributorEdit and delete intake itemsCreator
Project ContributorEdit and delete project, epic, and cycle updatesCreator
Project ContributorEdit and delete project assetsCreator
Project CommenterEdit and delete work itemsCreator
Project CommenterEdit and delete commentsCreator
Project CommenterEdit and delete intake itemsCreator
Project GuestView, edit, and delete intake itemsCreator
Workspace MemberEdit and delete workspace viewsCreator
Workspace MemberEdit and delete wiki collectionsCreator
Workspace MemberEdit and delete initiative commentsCreator
Workspace MemberDelete initiative attachmentsCreator
Workspace MemberDelete workspace draftsCreator
Teamspace MemberEdit, delete, and manage teamspaceLead
Teamspace MemberEdit and delete teamspace commentsCreator
Teamspace MemberEdit and delete teamspace viewsCreator

See also