Permissions in detail
The four access levels, how access flows down through spaces, and exactly who can do what in tasks, docs, dashboards, chat, attendance and settings.
Your role covers the whole workspace. Your access covers one item at a time — one space, project, doc or dashboard. This page is about that second half, and then what both halves mean in each part of Kokar.
If you have not read Roles yet, start there.
The four access levels
Every space, folder and project is shared using one of these.
| Level | Good for | What it allows |
|---|---|---|
| View only | Stakeholders, observers | Read. Nothing else — no comments |
| Interact | Clients, contractors, assigned people | Comment, attach files, tick checklists, write a task's description, and set the status and assignees of tasks assigned to them |
| Edit | The team doing the work | Everything in Interact, plus create and edit tasks and content freely — including the status and assignees of any task, not only your own |
| Full edit | Project managers, space leads | Everything, plus settings, members, statuses and deleting |
The jump that matters most is Edit → Full edit. Edit is for people doing the work; Full edit is for people running it. Only Full edit can change an item's settings, manage who else is in it, set manager-only statuses, or delete other people's things.
Public and private
Every space, folder and project is one or the other.
Public — everyone in the workspace can open it, at whatever level you set as its default. A new space starts everyone on Edit, so the whole workspace can create and edit work inside it without also being able to delete other people's tasks or change who has access. Raise or lower that whenever you like.
Private — only the people added to it can see it. For everyone else it does not appear anywhere and cannot be opened.
Private is a hard stop
Private overrides everything above it. Full edit on a space does not get you into a private project inside that space — you have to be added to the project itself.
This applies to admins as well. Only the workspace owner sees private items they were never added to.
How access flows down
Spaces hold folders, folders hold projects, projects hold tasks. Access flows downwards, and there are only two rules.
- Being named beats a default. If someone added you to an item by name, that is your level — wherever else you might have picked one up.
- The closest one wins. Between two things that both apply, the one nearer the item decides. Project beats folder, folder beats space.
A task has no sharing of its own. It uses whatever you have on the project it lives in.
An example
The Nike space is public and has been set to give everyone Full edit. Inside it is a Legal Docs folder, also public, but where everyone gets View only by default.
- Sara was added to the Nike space by name, as Full edit. She opens a project in Legal Docs and gets Full edit — she was named, and being named beats the folder's default.
- Bilal was never added to anything. He opens the same project and gets View only — no name anywhere, so the closest default applies, and that is the folder's.
Now the team makes a Confidential Q4 project private and adds nobody.
- Sara has Full edit on the whole space, and still cannot open it.
- An admin cannot open it either.
- The workspace owner can.
Spaces, folders and projects
Creating one of these is the one thing that needs both halves to agree: your role has to allow it at all, and you need Create access where you are putting it.
| Action | Who |
|---|---|
| Create a space | Anyone whose role allows it — members can by default |
| Create a folder or project | Anyone with Edit or above where it goes in |
| Open it | Anyone with View only or above |
| Rename, change icon, description | Full edit |
| Change public/private, manage members | Full edit |
| Manage task statuses | Full edit |
| Manage custom fields | Owners and admins — see below |
| Archive | Anyone who can edit it |
| Unarchive | Owners and admins, who can also reach it |
| Delete | Full edit, if your role still allows deleting |
| Reorder spaces in the sidebar | Owners and admins — the order is everyone's, not yours |
Only creating a space is decided purely by role — a space sits at the top, so there is no parent to check Create access against. Folders and projects go inside something, so the place you are putting them decides: Edit or above there is enough, whatever your role.
Statuses and custom fields part company here, even though they sit side by side in the same dialog. Statuses are a Full edit thing: run a space, set its workflow. Custom fields — the extra columns that appear on every task in the space — stay with owners and admins, and Full edit does not unlock them. On Enterprise a custom role can be given them.
Tasks
Tasks take their permissions from the project they are in. There is no per-task sharing.
| Action | Level needed |
|---|---|
| See a task | View only |
| Comment, react | Interact |
| Attach files, tick checklist items | Interact |
| Write the description | Interact |
| Change status or assignees | Edit — or Interact, if the task is assigned to you |
| Change title, dates, priority, estimate, tags | Edit |
| Create a task | Edit |
| Move or reorder a task | Edit — or Interact, for a task assigned to you |
| Archive a task | Edit |
| Delete a task | Full edit — and by default members only their own |
| Set a manager-only status | Full edit |
Three of those are worth spelling out.
If it is assigned to you, you can move it along. Someone at Interact — a contractor, a designer, a client-side reviewer — can change the status and assignees of tasks assigned to them, without being able to edit the project generally. They cannot do it to anyone else's task.
At Edit that restriction is gone: status and assignees are ordinary fields, settable on any task in the project, whoever it belongs to. So handing work to a teammate — or taking it on yourself — needs Edit, unless the task is already yours.
The description is open at Interact, the rest of the fields are not.
Manager-only statuses. A status can be marked manager-only — "Approved", "Accepted", "Signed off". It shows a lock and is greyed out for everyone without Full edit on that project, so nobody approves their own work.
Creating something is not a standing right to delete it
Deleting needs Full edit now, not when you made the thing. If you created a task while you had Full edit on a project and your access there was later reduced, you can no longer delete it — your permission changed, and that is the point of changing it.
On top of that, workspaces start with members limited to deleting their own work. An admin can lift that, or tighten it further, in Settings → Roles.
Docs
Docs are organised the same way as the rest of the workspace — space → folder → subfolder — and hold pages and uploaded files. It is a separate tree from the spaces in your main sidebar, but the words mean the same thing, so "put it in the Brand folder" reads the same in both places.
Docs use three levels — View, Edit and Full edit. There is no Interact for docs. The whole feature is covered in Docs, with the sharing detail in Sharing and privacy.
Sharing applies to a whole branch
You do not share every page one by one. Sharing is set on a space or folder, and everything inside it follows.
Share a folder separately and it becomes its own island: from then on it has its own audience, and the space above it no longer decides who gets in.
New spaces start out private to the person who made them.
| Action | Level needed |
|---|---|
| Open and read | View |
| Edit content, rename | Edit |
| Create anything inside | Edit on the space or folder it goes in |
| Share, change private/public | Full edit |
| Pin to a workspace space or project | Full edit |
| Move or drag-and-drop | Full edit on both ends — where it comes from and where it goes |
| Delete | Full edit — and by default members only their own pages |
| Move or reorder a folder at the top level | Owners and admins only |
| Move or reorder a page or file at the top level | Full edit on it |
Whoever creates a space starts with Full edit on it — that is a floor, not a guarantee. It is there so a new space is never stranded without anyone who can manage it. If someone later adds the creator to that space at a lower level, the level they were given is the one that applies.
Only containers are locked at the top of the tree. Reordering top-level spaces, promoting a folder up to the top, or filing one into another are owner-and-admin actions, because they reshape the tree everyone sees. A top-level page is different — it is usually a personal note, and creating one is the only way a member gets one — so anyone with Full edit on it can reorder it, file it into a folder they manage, or pull it back out.
Why moving needs Full edit. Rearranging the tree changes it for everyone, so it is treated like sharing or deleting rather than like typing. It is also what keeps drag-and-drop inside your own patch: you can reorganise a folder you manage all you like, but you cannot pull pages out of it into one you only have View on.
Position decides the name. A container at the top of the tree is a space; the same container moved inside another becomes a folder, and one level deeper a subfolder. Move it back out and it is a space again.
Pinning grants access. Pinning a doc to one of your workspace spaces also gives that space's people access to it — that is the point of pinning. A private doc stays private otherwise.
Moving and sharing. Something you shared deliberately keeps its own audience wherever you move it. Something that simply inherited from its parent picks up its new parent's sharing instead — and if you pull it out to the top level, it keeps the audience it already had, so it does not go dark on the people using it.
Dashboards
Dashboards use the same three levels as docs — View, Edit, Full edit.
| Action | Level needed |
|---|---|
| Open the dashboard and see its cards | View |
| Add, edit, rename, move or resize a card | Edit |
| Share it with someone | Edit |
| Delete a card | Full edit |
| Rename the dashboard, change its visibility | Full edit |
| Delete the dashboard | Full edit |
Editors build things up; only managers tear them down. That is why deleting a card sits one level higher than adding one.
Where a dashboard lives changes who can open it
- A dashboard filed in a space, folder or project belongs to that location's people. You need access to the location to open it — being invited to the dashboard alone is not enough.
- A dashboard in the Hub, filed nowhere, works on visibility alone: public means everyone in the workspace, private means the people invited to it.
Cards check your access separately
Opening a dashboard does not mean you see every number on it. Each card checks your access to the data it draws on, so a card built on a space you cannot see simply shows nothing instead of leaking the totals.
Some cards are managers-only by nature — Estimate vs tracked, or someone else's work log. Your own work log is always visible to you.
Dashboards cannot be archived
Every other kind of item can be archived. Dashboards are deleted instead. A dashboard filed in a space that gets archived stays reachable — archiving hides a location, it does not lock what is inside it.
Chat
Chat does not use workspace roles or access levels at all. The only question is whether you are in the conversation.
| Action | Who |
|---|---|
| Create a room | Anyone in the workspace |
| Read and post in a room | Members of that room |
| Edit or delete your own message | You, any time |
| Delete someone else's message | Room admins, in their own room |
| Rename the room, change its picture | Room admins |
| Add or remove members, make someone an admin | Room admins |
| Edit a post | Its author only |
| Delete a post | Its author, or a room admin |
| Pin a post | Room admins |
| Edit or delete a post comment | Its author only |
Whoever creates a room is its first admin.
Chat is private from everyone
This is the one place where nobody can get in from outside. Being a workspace admin — or the owner — does not let you read, join or moderate a room you are not a member of. Rooms are run by their own admins.
Time and attendance
Attendance goes by role alone — there is no per-space sharing for it.
Everyone can:
- Clock in and out
- See their own hours for today
- Look back over their own past days over any range, up to six months
- See their own time-off balance, request time off, and cancel a request
Owners and admins can also:
| Today's overview | Who is in, and how each person's day is going |
| Anyone else's history | Look up another person's past days, and export the PDF |
| Fix someone's hours | Correct a clock-in or clock-out that was wrong or missed |
| Time off | Approve and decline requests |
| Set the rules | Working weeks, holidays, quotas, office locations, and per-person exceptions |
On Enterprise, a custom role can be given just today's overview without the rest.
Your own record is yours to read. You do not need to ask anyone for a list of the days you worked. What needs the manager permission is reading somebody else's record, and the PDF export, which is on the computer only.
Archive and trash
Archive hides something without changing it — it still opens by link, and it is still editable. Trash deletes it, with 30 days to change your mind.
| Action | Who |
|---|---|
| Archive anything | Anyone who can edit it |
| Unarchive a space, folder or project | Owners and admins |
| Unarchive a task or doc page | Anyone who can edit it |
| Restore from trash | Whoever deleted it. Owners and admins can also restore anything public, and the owner anything at all |
| Restore a deleted chat post | Whoever deleted it, or an admin of that room — workspace role plays no part |
Members see the archive — what they do not get is the button to put a space, folder or project back, because that changes the sidebar for everybody. In trash, a member only ever sees their own deletions.
Deleted chat posts follow chat's rules, not the workspace's: one shows up in your trash if you deleted it or you are in the room, and nowhere else. Being an owner or admin does not put a private room's deleted posts in front of you.
Full detail is on Archive and trash.
Workspace settings and billing
| Page | Who |
|---|---|
| General | Everyone reads it; owners and admins edit |
| Automations | Everyone; you see the rules on locations you can already read |
| Members | Owners and admins |
| Roles & Permissions | Owners and admins |
| Attendance | Owners and admins |
| Audit logs | Owner only by default, Enterprise only — an owner can switch admins on in Settings → Roles |
| Billing & Plan | Owner only |
| Delete the workspace | Owner only |
There is no Archive page. Archived things reappear where they always lived when you turn on Show archived in the sidebar.
Anything under My Account — your profile, notifications, connected apps, trash — is yours and needs no permission.
Why can't I see something?
Work down this list; it is almost always one of these.
| What you are seeing | Why |
|---|---|
| A space or project is missing entirely | It is private and you were not added — ask someone with Full edit on it |
| You can read it but the buttons are greyed out | You have View only or Interact |
| You can edit tasks but not the project's settings | You have Edit. Settings and members need Full edit |
| A status is locked | It is manager-only — Full edit on that project can set it |
| The "Create space" button is missing everywhere | That is your role, not your access — space creation has been switched off for it. Ask an owner or admin |
| You cannot create a project or folder in one place | That is your access there. Creating needs Edit or above in that space or folder |
| The "+" is missing on a docs space or folder | You have View on that branch, not Edit |
| A dashboard card is empty | The card draws on something you cannot see, or it is managers-only |
| Everything is suddenly read-only across the whole workspace | The workspace has an unpaid invoice — reading still works, writing is paused until it is settled |
If none of these fit, the person to ask is whoever has Full edit on the item in question — or an admin, for anything workspace-wide.
Frequently asked questions
I have Full edit on a space, so why can't I open a project inside it?
The project is private and you were not added to it. A private item is a hard stop — access from the space above does not reach into it. Only the workspace owner is exempt.
Why can I comment on a task but not change its title?
You have Interact access. That covers comments, files, checklists and writing the description, plus setting the status and assignees of tasks that are assigned to you. Changing titles, dates and priorities needs Edit.
Can someone with Edit assign people to tasks?
Yes — Edit can set the status and assignees of any task in that space or project, not only tasks assigned to them. Interact can do the same but only on tasks already assigned to them. View cannot change a task at all.
Why is one status greyed out with a lock on it?
It is a manager-only status. Only someone with Full edit on that project can move a task into it — so nobody signs off their own work.
Can a workspace admin read a chat room they are not in?
No. Chat is decided by who is in the conversation, not by workspace role. An admin who is not in the room cannot read it or moderate it.
A dashboard opens but one of its cards is empty. Is it broken?
Probably not. Cards check your access separately, so a card drawing on a space you cannot see will show nothing rather than leak the numbers. Some cards are also manager-only.
Who can delete a task?
Anyone with Full edit on the project it lives in. By default members can only delete tasks they created themselves — an admin can change that in Settings → Roles. Creating a task does not give you a standing right to delete it — if your access to that project is later reduced, you lose deletion there too.