Roles

Every workspace has three roles — Owner, Admin and Member. What each one means, and why a role is only half of what decides access.

Two separate things decide what you can do in Kokar. Almost every question about access comes down to knowing which of the two is in the way.

Your roleYour access
CoversThe whole workspaceOne space, project or doc at a time
Answers"What sort of thing can I do at all?""Can I open this, and do what here?"

Think of your role as your job title, and your access as which doors you have a key to. A job title does not open a locked door, and a key to one room does not make you the manager.

Both have to agree. If your role allows something but you have no access to that project, the answer is still no — and the other way round.

This page covers roles. Access levels and what they mean in each feature are on Permissions in detail.

The three roles

Every workspace has these, on every plan.

RoleWho it is
OwnerThe person who created the workspace. One per workspace. Full control, and sees everything in it
AdminRuns the workspace day to day — people, roles, attendance, restoring things
MemberEveryone else. Works in the spaces and projects they have been given

What each one can do

This is the workspace-wide half — the things a role allows anywhere.

Rows marked default are starting points, not fixed rules. On Business and above you can change them per workspace — see Changing what a role can do below.

OwnerAdminMember
Create tasks and docs
Create spacesdefault
Create folders and projects
Manage tags and task statusesdefault
Delete thingsdefault
Delete other people's workdefault
Manage custom fields
Invite peoplefixed
Add, remove people and change their rolesfixed
See attendance and manage policies
Restore an archived space, folder or project
Audit log (Enterprise)default
Custom roles (Enterprise)
Billing and plan
See everything, including private items
Delete the workspace

Three of those are worth reading twice.

Members can create spaces, folders and projects. What they cannot do is put one just anywhere — creating still needs Edit access wherever it is going. The role says "allowed to at all"; the place says "allowed to here".

Only the space row is switchable. Folders and projects always go inside something, so the place they are going is what decides, and there is nothing useful to turn off workspace-wide.

Members delete only their own work by default. Having Full edit on a project does not let a member remove a teammate's task. An admin can lift that if the team would rather work the other way.

Custom fields are not a sharing thing. Task statuses can be handed to anyone with Full edit on the space, but the fields themselves — the extra columns that appear on every task — stay with owners and admins whatever anyone's access says. On Enterprise a custom role can carry them.

Everything else a member does happens inside a space or project, and it is the sharing on that item that decides it. A member can be the most powerful person in one space and unable to open the next one.

Changing what a role can do

Settings → Roles, on Business and above.

Admin and Member each get a column, and you switch rows on or off for them. The owner has no column — a workspace that could switch the owner's own permissions off would be a door that locks from the inside with nobody left holding a key.

Three rows cannot be changed for members, and are shown locked with the reason:

  • Invite people. Workspace size decides the bill, so it is not something anyone can change.
  • Add, remove people and change their roles. It includes role assignment, so a member who had it could simply make themselves an admin.
  • Audit log. It records what happened in private spaces the reader cannot open.

The audit log row is also the one that starts off for admins. Out of the box the workspace owner is the only person who can read it; switch the admin cell on if you want your admins in there too.

Switching Add, remove people off for an admin does not take effect yet

The switch is there and it saves, but member management does not currently honour it — an admin can still invite, remove and re-role people with the row turned off. Do not rely on it as a restriction. The member side of that row is locked and genuinely enforced, so nobody below admin can reach any of it.

Delete things is the one with a sub-option. Switch it off and that role cannot delete anything at all — not even work they created themselves. Leave it on and tick Own items only to allow deleting, but only their own. Members start with that ticked; admins start without it, because tidying up after other people is most of what running a workspace is.

It also reaches deleting statuses and tags: a role can be allowed to create and rename them while still being unable to remove them.

Changes apply immediately

There is no save button and no delay. Someone who could delete a task a moment ago may find they cannot. On a plan that does not include this, roles go back to their defaults and stay there.

Private means private

Something private is only visible to the people added to it. Admins are no exception — running the workspace does not put them inside a space, project or doc they were never added to.

The owner is the one exception, so that a private project can still be reached after everyone who was in it has left.

Where an admin can get in — anything public, or a private item they were added to — they get full powers automatically over spaces, folders, projects, tasks and docs.

Dashboards are the exception. There an admin gets whatever level the board gives them, the same as anyone else: the level of the location it is filed in, or the board's own default in the Hub. To let an admin rename or delete a dashboard they did not build, share it with them at Full edit.

Chat is private from everyone

Conversations work differently. Nobody can read a room or a direct message they are not part of — not admins, and not the owner either.

Changing someone's role

Settings → Members, then choose the new role next to their name. Owners and admins can do this.

Changing a role changes what someone can do across the workspace. It does not add or remove them from any space, project or doc — those stay exactly as they were.

Custom roles

Enterprise only.

If the three built-in roles do not fit, build your own — "Designer", "QA Lead", "Client Reviewer" — and tick exactly which permissions it carries. Assign it to people the same way you assign the built-in roles.

Two things worth knowing:

  • You can only grant permissions you already have yourself. Nobody can build a role more powerful than they are.
  • A custom role is still only the workspace-wide half. It grants things like "can create projects" — it never decides which space someone can open.

Leaving Enterprise removes custom roles

Custom roles only exist on Enterprise. Moving to a lower plan asks you to move everyone on a custom role onto Owner, Admin or Member first, and then deletes the custom roles. Going back up to Enterprise later does not bring them back — you build them again.

Where to go next

Frequently asked questions

What is the difference between a role and sharing?

A role is workspace-wide and answers "what kind of thing can this person do at all". Sharing is per item and answers "can they open this particular space, project or doc". You need both to say yes.

Can an admin see a private space they were not added to?

No. Admins run the workspace but do not automatically appear in private items. The workspace owner is the only person who sees everything.

Can a member create a project?

Yes, anywhere they have Edit access or above — which includes every public space by default. Folders and spaces work the same way. An admin can turn space creation off for members in Settings → Roles.

Why can't I delete a task I created?

Deleting needs Full edit on the project as it stands now, not as it stood when you made the thing. If your access there was reduced, you lose deletion with it. Workspaces also start with members able to delete only their own work — an admin can change that in Settings → Roles.

Can the owner read our chat?

No. Chat is the one thing nobody can reach from outside — a room or a direct message is only visible to the people in it, owner included.

How do I change someone's role?

Settings → Members, then pick a new role next to their name. Owners and admins can do this. There is always exactly one owner.

Can I make my own roles?

On Enterprise, yes — build a role, tick the permissions it should have, and assign it like any other. Every plan has the three built-in roles.

Keep reading