Skip to content
ProjectBrain Docs
Work in progress: these docs are being written and change often.

Roles and permissions

How roles work in ProjectBrain, what each default role can do, and why a role in one organization grants nothing in another.

GAOwnerLast updated 5 October 2026

A role is a named set of permissions. Each person holds a role in each organization they belong to, and the role decides what they can see and do there.

A role counts only in the organization where you hold it. If you are an owner in one organization and a team member in another, you have a team member’s permissions in the second one. Nothing carries across.

This also applies to people who work for several clients or companies. Switching organizations switches the role that applies.

Every organization starts with the same default roles:

Role Meant for
Owner The people who run the organization’s account. Owners can do everything, and only owners can delete the organization, manage billing, or change roles.
Executive Senior leaders who need almost everything, without organization-level controls.
Team lead People who run teams and projects day to day.
Team member Individual contributors who do the work on projects they can see.
Client (read & comment) Clients who read and comment on shared wiki pages.
External Invited outside people. This role holds no permissions of its own. An external person sees only the projects they were invited to.

To give someone a role, go to Settings > Organization > People. To change what a role can do, see Custom roles.

The table below shows the permissions each default role starts with. Your organization may have changed them. To see your own, open Settings > Organization > Roles and permissions and pick a role.

Permissions also stack with project visibility. A permission to edit projects does not let someone open a project they cannot see, such as a walled-off project they are not a member of.

What each default role can do
PermissionOwnerExecutiveTeam leadTeam memberClient (read & comment)External
Organization and people
Organization: deleteOwner onlyOwner canExecutive cannotTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Organization: manage billingOwner onlyOwner canExecutive cannotTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Invite people, change their roles and remove themOwner canExecutive cannotTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Organization: updateOwner canExecutive cannotTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Organization: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Projects and sharing
Archive a project and write up its lessonsOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
See archived projects and their lessonsOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Record and edit decisionsOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
See the decision journalOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Review outside access (clients and vendors)Owner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Projects: createOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Projects: deleteOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Share projects by emailOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Manage a project's teamOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Wall off projects and open a walled project with a recorded reasonOwner canExecutive cannotTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Comment on, suggest changes to and review project timelinesOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Projects: updateOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Projects: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
See project budgetsOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Create, edit and archive this organization's timeline templatesOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Teams and structure
Departments: manageOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Departments: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Organization structure: auditOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Subsidiaries: manageOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Subsidiaries: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Teams: createOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Teams: deleteOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Teams: manageOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Teams: manage membersOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Teams: updateOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Teams: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Clients, vendors and rates
Clients: createOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Clients: deleteOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Clients: editOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Clients: manage contactsOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Clients: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Clients: view financialsOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Rate cards: createOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Rate cards: deleteOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Rate cards: editOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Rate cards: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Vendors: createOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Vendors: deleteOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Vendors: editOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Vendors: manage contactsOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Vendors: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Vendors: view financialsOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Documents, estimates, blueprints and guardrails
Blueprints: approveOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Blueprints: createOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Blueprints: deleteOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Blueprints: updateOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Blueprints: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Custom fields: manageOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Documents: createOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Documents: deleteOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Documents: force checkinOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Documents: updateOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Documents: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Estimates: analyzeOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Estimates: approveOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Estimates: createOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Estimates: deleteOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Estimates: track actualsOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Estimates: updateOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Estimates: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Guardrails: createOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Guardrails: curateOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Guardrails: deleteOwner canExecutive cannotTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Guardrails: updateOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Guardrails: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Guardrails: voteOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Time tracking
Time entries: createOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Time entries: deleteOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Delete everyone's timeOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Time entries: exportOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Time entries: importOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Time entries: updateOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Edit everyone's timeOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Time entries: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
See everyone's timeOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Reports and health scores
Health scores: recalculateOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Health scores: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Reports: exportOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Reports: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
See reports for all teamsOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Briefs and SOWs
Project Docs: adminOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Project Docs: createOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Project Docs: editOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Project Docs: edit anyOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Project Docs: exportOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Project Docs: reviewOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Project Docs: sendOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Project Docs: signOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Project Docs: submitOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Project Docs: templates manageOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Project Docs: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Resource planning
Resource planning: allocateOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Resource planning: auditOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Resource planning: capacity manageOwner canExecutive cannotTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Resource planning: flags manageOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Resource planning: manageOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Resource planning: viewOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Standups
Start a new standupOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Run a standup: ask questions, nudge people who have not postedOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Edit or delete any standup, and manage templatesOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
See standups and post their own updateOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Agents
Approve plans for agents, pause them, take over their work and change agent settingsOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
See the Agents page and what AI agents are working onOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Workflow automation
Workflow templates: ai authorOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Workflow templates: applyOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Workflow templates: bulk applyOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Workflow templates: escalationsOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Workflow templates: manageOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Workflow templates: observabilityOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Webhooks: manageOwner canExecutive cannotTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Wiki
Wiki attachments: manageOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Wiki attachments: uploadOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Wiki comments: createOwner canExecutive canTeam lead canTeam member canClient (read & comment) canExternal cannot
Wiki comments: moderateOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Wiki pages: approveOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Wiki pages: archiveOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Wiki pages: createOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Wiki pages: deleteOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Wiki pages: moveOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Wiki pages: rejectOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Wiki pages: restoreOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Wiki pages: shareOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Wiki pages: submitOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Wiki pages: updateOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Wiki pages: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) canExternal cannot
Wiki page history: compareOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Wiki page history: restoreOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Wiki page history: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) canExternal cannot
Wiki templates: approveOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Wiki templates: submitOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Wiki templates: useOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Open other people's personal wikis (recorded)Owner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Wikis: ai manageOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Wikis: archiveOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Wikis: audit viewOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Wikis: createOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Wikis: deleteOwner canExecutive cannotTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Wikis: permissions manageOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Wikis: restoreOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Wikis: updateOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Wikis: viewOwner canExecutive canTeam lead canTeam member canClient (read & comment) canExternal cannot
AI and MCP
Manage AI connection rules for the organizationOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Connect their own AI toolsOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Let AI start workflowsOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Focus and Cortex
Cortex: manageOwner canExecutive cannotTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Cortex: useOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Focus mode: manageOwner canExecutive cannotTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Focus mode: useOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Focus mode: view aggregatesOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Use the focus coaching toolkitOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Code and GitHub
Merge pull requests from a taskOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Connect the organization to GitHubOwner canExecutive canTeam lead cannotTeam member cannotClient (read & comment) cannotExternal cannot
Link tasks to pull requests and issuesOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot
Choose a project's repositoriesOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
Manage GitHub issue syncingOwner canExecutive canTeam lead canTeam member cannotClient (read & comment) cannotExternal cannot
See GitHub links on tasksOwner canExecutive canTeam lead canTeam member canClient (read & comment) cannotExternal cannot

A small number of ProjectBrain staff hold platform roles, for support and for reviewing the shared template library. Platform roles are separate from your organization’s roles. No role in your organization can be given these staff powers, and owners cannot grant them.