Skip to content

Roles and permissions

The five workspace roles — Owner, Admin, Member, Reader, Guest — what each can do, and how Owners delegate extra permissions.

Last updated

On this page

Every person in a Team workspace holds exactly one role, and that role controls what they can see and do. Laya is open by default: a Member can get on with almost everything without asking anyone, and the workspace Owner tightens whatever they want to tighten from a single Permissions screen.

The five roles

Workspace roles and what they can do
RoleWhat they can do
OwnerEverything an Admin can, plus the owner-only set: delete the workspace, the audit log, API access tokens, ownership transfer and the Permissions tab.
AdminFull workspace administration except the owner-only set — invite and remove members, change roles, manage connections and connectors, and update workspace settings.
MemberThe everyday builder role, and a broad one: create boards and master boards, create and update work items, configure a board and its statuses and columns, restyle it in Board Studio, manage sprints, epics and tags, archive issues and run bulk actions, share saved views, comment, upload files, create and update docs, share a board publicly, invite people, add connections and mirror boards, and manage automations.
ReaderRead-only access to the workspace, boards, work items, saved views, docs and backlog.
GuestExternal collaborators: read boards, work items and docs, update work items, post and edit their own comments, and upload files. Guests cannot see saved views or the backlog, create boards, or change workspace settings.

A role can never grant a role stronger than its own. This ceiling is enforced both when an invitation is sent and again when it is redeemed.

Delegating permissions (Owner only)

The Permissions tab is a matrix. Rows are the delegatable permissions, grouped under Boards, Connections, Issues & content, Planning, Docs & sharing and Workspace; columns are "Admin (+ Owner)" — always ticked and locked — plus Member, Reader and Guest as editable toggles. Actions at the bottom are Reset to defaults, Cancel and Save changes.

The delegatable permissions, by group
GroupPermissions
BoardsCreate boards · Create master boards · Configure boards · Manage statuses & columns · Restyle boards · Archive boards
ConnectionsAdd connections & mirror boards
Issues & contentCreate issues · Archive issues · Bulk actions on issues · Manage tags · Comment · Upload files
PlanningManage sprints · Manage epics
Docs & sharingShare externally
WorkspaceShare saved views · Invite people

Restyle boards is presentation only — theme, colours, column look and effects. It is deliberately separate from Configure boards, so you can let everyone make a board look right without also handing over its structure or its sync settings.

The tab is equally clear about what can never be delegated: "Member management, billing, audit, delete and ownership transfer stay fixed to Owner/Admin and aren't listed — they can't be delegated." Disconnecting a tool sits in that fixed set too: a Member can add a connection and mirror a board, but taking one away — and everything it feeds — stays with Admins and the Owner.

What Admins and Owners see that others don't

  • The sidebar's Administration section (Settings, Properties, Automations, Audit) renders only for the Owner and Admins.
  • Within Settings, the Permissions and Audit log tabs are Owner-only; the remaining tabs are described in Workspace settings.
  • A short list stays with Admins and the Owner by default: removing people, changing roles, disconnecting a tool, moderating other people’s comments, and workspace settings.

Roles from provider verification

Still stuck?

Email support@laya.net — include what you expected, what happened, and a link to the affected board or item so we can help quickly.

Contact support