Roles and permissions
The five workspace roles — Owner, Admin, Member, Reader, Guest — what each can do, and how Owners delegate extra permissions.
Last updated
On this page
Every person in a Team workspace holds exactly one role, and that role controls what they can see and do. Laya ships sensible defaults, and the workspace Owner can loosen specific permissions for lower roles from a single Permissions screen.
The five roles
| Role | What they can do |
|---|---|
| Owner | Everything an Admin can, plus the owner-only set: delete the workspace, the audit log, API access tokens, ownership transfer and the Permissions tab. |
| Admin | Full workspace administration except the owner-only set — invite and remove members, change roles, manage connections and connectors, and update workspace settings. |
| Member | The everyday builder role: create boards and master boards, create and update work items, comment, upload files, create personal views, create and update docs, resolve backlog items and manage automations. |
| Reader | Read-only access to the workspace, boards, work items, saved views, docs and backlog. |
| Guest | External collaborators: read boards, work items and docs, update work items, post and edit their own comments, and upload files. Guests cannot see saved views or the backlog, create boards, or change workspace settings. |
A role can never grant a role stronger than its own. This ceiling is enforced both when an invitation is sent and again when it is redeemed.
Delegating permissions (Owner only)
The Permissions tab is a matrix. Rows are seven delegatable permissions grouped under Boards, Issues & content and Workspace; columns are "Admin (+ Owner)" — always ticked and locked — plus Member, Reader and Guest as editable toggles. Actions at the bottom are Reset to defaults, Cancel and Save changes.
| Permission | Product description |
|---|---|
| Create boards | Make new Kanban / Scrum boards |
| Create master boards | Roll several boards into one unified Laya-native view |
| Archive boards | Archive a board out of the active list |
| Create issues | Add new issues to a board. Creation only — what a role may do to issues that already exist is fixed by the role. |
| Comment | Post and reply on issues |
| Upload files | Attach files to issues |
| Invite people | Send workspace invitations |
The tab is equally clear about what can never be delegated: "Member management, billing, audit, delete and ownership transfer stay fixed to Owner/Admin and aren't listed — they can't be delegated." Managing tool connections (connecting or disconnecting Jira, Azure DevOps and the rest) is likewise fixed to Owner and Admin.
What Admins and Owners see that others don't
- The sidebar's Administration section (Settings, Properties, Automations, Audit) renders only for the Owner and Admins.
- Within Settings, the Permissions and Audit log tabs are Owner-only; the remaining tabs are described in Workspace settings.
- Sharing a doc publicly requires a share capability that defaults to Admin and Owner.
Roles from provider verification
Email support@laya.net — include what you expected, what happened, and a link to the affected board or item so we can help quickly.