skrümGitHubGet started

Reference

Roles and permissions

What each workspace role, team role and the instance admin may do, and what a guest may do in a session.

Use this page to find out why a button is missing, or which role to give someone. Each table lists actions in rows and roles in columns.

How the levels fit together

A person has one role in each workspace they belong to, and one role in each team they belong to. Being an instance admin is separate from both.

  • A workspace Owner or Admin acts as the owner of every team of the workspace, whether or not they are a member of the team. They are never treated as an observer, whatever their role in the team says. One thing still needs membership of the team: adding an action item outside a retrospective.
  • An instance admin gets no role in any workspace or team from being an instance admin. They see a workspace only when they are a member of it.
  • Each session also has its own facilitator, who is not a team role. See Inside a session.
  • A guest has no account and no role. See Guests.

Workspace roles

The workspace roles are Owner, Admin and Member. Anyone with an account can create a workspace, and becomes its owner.

Action Owner Admin Member
Open the workspace Yes Yes Yes
See the teams of the workspace All All The teams they belong to
Ask to join a team they are not in Yes Yes Yes
See the action items of the workspace All teams All teams The teams they belong to
Change the name and the description of the workspace Yes Yes No
Open the workspace’s Members page Yes Yes No
Invite someone to the workspace, as admin or member Yes Yes No
Resend or revoke an invitation Yes Yes Only an invitation to a team they may invite to
Change a member’s role Yes Yes, except to or from owner No
Remove a member Yes Yes, except an owner No
Leave the workspace Yes Yes Yes
Delete the workspace Yes No No
Create a team Yes Yes No
Delete a team Yes Yes No
Save a retro template for themselves Yes Yes Yes
Share a retro template with the whole workspace, change or delete such a template Yes Yes No
Create, change or delete a poker deck of the workspace Yes Yes No
Change or delete a whiteboard template Any Any The ones they created
Delete a planning poker game, a whiteboard or a game room they do not run Yes Yes No
Change, open, close or delete a survey they did not create Yes Yes No

A workspace always keeps one owner. The last owner cannot be given another role, be removed, or leave: the interface answers “A workspace needs at least one owner.”

An invitation to a workspace gives the role admin or member. Only an owner can make someone an owner, from the Members page.

Team roles

The team roles are Owner, Facilitator, Member and Observer. An invitation gives the role facilitator, member or observer; the owner role is given from the team’s members page.

Action Owner Facilitator Member Observer
Open the team, its sessions, its members, its insights, its health check, its eNPS, its activity and its estimates Yes Yes Yes Yes
Start a retrospective, a planning poker game, a whiteboard, a game room or a survey Yes Yes Yes No
Take part in a session Yes Yes Yes No, follows without taking part
Add an action item, comment on an action item Yes Yes Yes No
Save a poker deck for the team Yes Yes Yes No
Duplicate a whiteboard, save a whiteboard as a template Yes Yes Yes No
Take over a retrospective that is not completed, or the hosting of a game room Yes Yes No No
Create, change, delete and start sprints (team settings, Sprints) Yes Yes No No
Change the team’s retro settings, its list of facilitators and its default template (team settings, Retrospectives) Yes Yes No No
Share a retro template with the team, change or delete such a template Yes Yes No No
See the health check statements (team settings, Health check) Yes Yes No No
Add, change, reorder or archive health check statements Yes No No No
Invite people by email, resend or revoke those invitations Yes Yes No No
Create or revoke the team’s invite link Yes Yes No No
Add a member of the workspace to the team Yes No No No
Change a member’s role, remove a member Yes No No No
Approve or decline a request to join the team Yes No No No
Change the team’s name, description and link (team settings, General) Yes No No No
Choose the team’s default poker deck Yes No No No
Connect, set up, test and disconnect integrations (team settings, Integrations) Yes No No No
Open Data & export in the team settings Yes No No No
Delete the team No No No No

Only a workspace owner or admin can delete a team.

Observers

An observer sees everything the team sees and changes nothing. On the team page they read “Observers cannot start sessions.” Inside a session, an attempt to write is refused with “Observers can follow this session but not take part.” In a planning poker game an observer joins as a spectator and does not vote.

A person who is made an observer while they facilitate a session keeps facilitating that session.

Action items

Who may act on an action item depends on the item, not on the team role:

Action Who
Change or delete an item The person who created it, the facilitator of the retrospective it comes from, a workspace owner or admin
Complete or reopen an item The same people, the person the item is assigned to, and the facilitator of any retrospective of the team that is not completed
Comment on an item Any member of the team except observers
Change a comment Its author
Delete a comment Its author, and whoever may delete the item
Export an item to a tracker Whoever may change the item, with an account

An observer of the team reads its action items and changes none of them, including one they created before becoming an observer.

Poker decks and templates

A deck saved for a team can be changed or deleted by the person who saved it, as long as they may still start planning poker games in the team, and by a workspace owner or admin. A template someone saved for themselves can be changed or deleted by that person only.

Inside a session

A retrospective, a planning poker game and a whiteboard each have one facilitator. A game room has a host. A survey is run by the person who created it. These are roles of the session, kept by one person at a time.

In a retrospective, the facilitator moves the phases, runs the timer, changes the board’s settings and columns, turns guest access on or off, and deletes the retrospective. The facilitator can hand the role to anyone who may start that kind of session in the team.

Session Who can take it over Who can delete it Who can share it to a channel
Retrospective While it is not completed: a team owner, a team facilitator, a workspace owner or admin Its facilitator Its facilitator while a member of the team, a workspace owner or admin
Planning poker game Any member of the team except observers Its facilitator, a workspace owner or admin Its facilitator, a workspace owner or admin
Whiteboard Any member of the team except observers Its facilitator, a workspace owner or admin Not shared to a channel
Game room The person who created it, a team owner, a team facilitator, a workspace owner or admin The person who created it, a workspace owner or admin Its host or the person who created it while a member of the team, a workspace owner or admin
Survey Nobody: the person who created it and the workspace’s owners and admins change, open and close it The person who created it, a workspace owner or admin Not shared to a channel

Instance admin

The first account created on an instance is its instance admin. An instance admin opens Administration, whose pages ask them to confirm their password before they open.

Action Instance admin Everyone else
Open Administration Yes No
Change the instance’s settings in General and check for an update Yes No
Change the Branding Yes No
Set up sign-in and single sign-on in SSO authentication Yes No
Set up mail in SMTP and send a test email Yes No
Turn on and set up the providers in Integrations Yes No
List and revoke MCP keys Yes No
Read the Licence page Yes No
Find an account, deactivate it or reactivate it in Users Yes No
Add or remove an instance admin in Admins Yes No
Read the Audit log Yes No

Two limits protect the instance:

  • An instance keeps at least one admin: removing the last one is refused with “An instance needs at least one admin.”
  • An admin cannot deactivate their own account, or the last active admin.

When single sign-on is required for everyone, an instance admin who has a second factor can still sign in with their password, followed by that second factor.

Guests

A guest is someone who joins one session through its guest link, with a name and no account. A person who has an account but is not a member of the session’s team joins the same way. Guest access is turned on or off for each session; when it is turned off, the guests of that session lose access.

Session A guest can A guest cannot
Retrospective Take part as the members do: write cards, vote, comment, react, rate the session, add action items Become the facilitator, share the retrospective to a channel, export an action item to a tracker, see the team’s name or the links to the team’s pages
Planning poker game Vote Add, change or import tasks, become the facilitator, share the game to a channel
Whiteboard Draw on the board Become the facilitator, duplicate the board, save it as a template
Game room Play Host the room, share the room to a channel
Survey Answer Change, duplicate or export the survey, compare it with another one

A guest is never emailed. An action item can be assigned to a guest only from the retrospective the guest joined.