Permissions · verified from product source August 8, 2026
Understand Stelaah Workspace Roles and Permissions
Roles define baseline access inside one workspace. Workspace features, role rules, and person-specific grants or restrictions combine to determine effective access.
Verification scope: These instructions describe the current product source. Authentication, plans, live delivery, and workspace configuration can affect results.
Purpose
Use roles to provide enough access for each responsibility without granting unnecessary workspace control. Database authorization remains the security boundary.
Before you start
- Be an owner or admin to change workspace roles.
- Identify the work the person must perform.
- Check plan and workspace feature availability.
Step-by-step guide
- Open Settings. Select Roles & access. Non-admin members may not have access to this tab.
- Review workspace features. A role cannot use a disabled or plan-unavailable feature.
- Select a role. Review its baseline access and current workspace overrides.
- Grant or restrict carefully. Role changes apply across the workspace. Person-specific rules can adjust one member.
- Verify the result. Check navigation, record actions, settings access, and external sharing as the affected role.
Example
A project lead can remain a Member. A client reviewer should use the Client role and receive only records explicitly shared with them.
Troubleshooting
A feature is missing
Check the plan, workspace feature state, role, role overrides, and person-specific restrictions.
A member cannot edit clients
Current client management is available to owner, admin, and member roles.
Permissions appear incomplete during loading
Authenticated sessions fail closed while identity and workspace access hydrate.
Permissions and limits
- Owner manages billing and workspace control.
- Admin manages members, roles, and workspace configuration, but not billing.
- Member performs ordinary internal work.
- Limited access is restricted and can manage created tasks only where rules allow.
- Guest and Client roles receive explicit external access only.