Openbook

Roles and permissions

The four organization roles, the four workspace roles, guests, and who can do what in Openbook.

Permissions work at two levels, and they are genuinely two different things:

  • An organization role says what a person is to the company. It lives at the Bookbag account and is the same in every Bookbag product.
  • A workspace role says what a person may do inside one Openbook space. It lives in Openbook and is set per space.

Both use the same four names — owner, admin, member, viewer — which is convenient to remember and worth keeping straight.

Organization roles

Every member of an organization holds one of four roles, assigned at the account service:

Role Who it's for
Owner The one person responsible for the organization
Admin People who run the organization day to day
Member Everyone who does the work
Viewer Stakeholders who need to see and not change

Three things follow from where these live:

  • Changing them happens at the account, not here. Openbook's Organization → Members & access page sends you to the account service for anything to do with who is in the organization. Openbook reads the answer.
  • The role travels. Make someone an admin once and they are an admin in every Bookbag product that organization uses.
  • Viewers are free. Openbook counts a billable seat as an organization member whose role is anything other than viewer.

Inside Openbook, an organization owner or admin is treated as an administrator of every space in that organization — they get space-admin abilities directly, without being added to each space as an admin.

Workspace roles

Inside a space, each member holds one of the same four roles. This is what the space's Settings page sets, and it is what the guards actually check when you click something.

Capability Owner Admin Member Viewer
View rooms and content yes yes yes yes
Create and edit content yes yes yes
Create and delete rooms yes yes
Manage members and roles yes yes
Change workspace settings yes yes
Delete the workspace yes
  • Owner — created the space. Full control, including deleting it. There is exactly one, and the role cannot be assigned or changed; it belongs to whoever created the space.
  • Admin — manages members and roles, creates and deletes rooms, changes settings.
  • Member — creates and edits content in the rooms they can reach.
  • Viewer — read-only.

Only admin, member and viewer can be assigned. When you change someone's workspace role they are notified, with a link to the space.

The owner's role cannot be changed and the owner cannot be removed from their own space. If ownership needs to move, that is a separate operation — see Transferring ownership.

Guests

A guest is not a fifth role. It is a flag on top of viewer-shaped permissions, and it changes what they can see rather than what they can do.

A normal viewer can read the whole space. A guest can read only the rooms they were explicitly added to — including rooms whose visibility is set to everyone in the space. That makes a guest the right shape for a client or a contractor who should see one board and nothing around it.

  • Guests are always read-only. Permissions supplied in a guest invitation are ignored.
  • A guest must already have a Bookbag account before you can invite them, because their scoping hangs off a real account.
  • You add and remove a guest's rooms one at a time from the space's Settings page.
  • Giving a guest a normal workspace role ends guest status. That is the only way out of it.
  • Guests never count as billable seats.

Room visibility

On top of roles, each room has its own visibility:

  • Everyone in the space — any member of the space can open it.
  • Only certain people — you pick who; it is hidden from everyone else.

Visibility decides who can see a room. Roles decide who can change what is inside it. A managers-only Check-in room and an open Feed room sit happily in the same space.

Space owners and admins can see every room in their space regardless of its visibility. Guests are the exception in the other direction: they see only their listed rooms, whatever the visibility says.

Who can do what — quick reference

  • Add, remove or re-role an organization member, or transfer the organization: at the Bookbag account, by the organization's owner or an admin.
  • Change which Openbook workspaces a member can reach: in Openbook, on Organization → Members & access.
  • Change a workspace role, invite a guest, or set a room's visibility: in the space's Settings, by the space's owner or an admin (or by an organization owner or admin).
  • Create or delete a room: the space's owner or an admin.
  • Manage billing: an organization owner or admin, from Organization → Settings → Billing.
  • Create and edit work: owner, admin and member, subject to room visibility.
  • View work: everyone, within their workspace scope, the room's visibility, and — for a guest — their room list.

Choosing roles for a typical team

A sensible default for a small company:

  1. Organization owner: the founder or whoever owns the billing relationship.
  2. Organization admin: the one or two people who add and remove staff.
  3. Organization member: everyone who does the work.
  4. Organization viewer: advisors, clients, and anyone who asked to be kept in the loop. They cost nothing.

Then, per space, leave most people as member, make the one or two people who run the space admin, and use room visibility for the exceptions. Reach for guest only when someone should see a named room and nothing else.