Roles & permissions
Keikaku uses role-based access control. Every member of an organization has one org role; some members are additionally assigned a project role on specific projects. Permissions are enforced on the server for every action — the interface simply hides what you can't do.
Overview
There are four org-wide roles and two project-scoped roles. Org roles apply across the whole organization; project roles grant access to just the projects a person is assigned to — useful for giving someone control of their work without exposing the rest of the org.
Organization roles
-
Owner
Org · one per orgFull control of the organization. The buck stops here — and ownership can be transferred.
- ✓ Everything an Admin can do
- ✓ Delete the organization, manage billing, transfer ownership
-
Admin
OrgRuns the organization day to day. Everything except the owner-only actions.
- ✓ Create & manage projects, agents and secrets
- ✓ Invite people and set their roles
- — Can't delete the org, change billing, or transfer ownership
-
Systems Admin
OrgLooks after shared infrastructure — the agents and secrets the whole org relies on — without seeing the work itself.
- ✓ Create, rotate and delete org agents
- ✓ Create and manage org secrets
- — No access to projects or their tasks
-
Org Read-Only
OrgFull visibility, zero edits — ideal for stakeholders, auditors or onlookers.
- ✓ View all projects, agents, secrets, members and billing
- — Can't change anything, anywhere
Project roles
Project roles are assigned per project. A person with a project role has a minimal org footprint — they only see and touch the projects they're assigned to. Great for contractors, clients, or a team lead who owns a slice of the work.
-
Project Manager
ProjectFull control inside the projects they're assigned to — and nothing outside them.
- ✓ Manage outcomes, tasks and questions
- ✓ Attach agents & secrets and assign project members
- — Only their assigned projects; no org-wide admin or billing
-
Project Read-Only
ProjectView access to specific projects — see the plan and progress without making changes.
- ✓ Read outcomes, tasks and questions in assigned projects
- — Read-only, and only the projects they're assigned to
Assigning roles
- Org roles — set when you invite someone under Users in the app, and changeable any time from the same screen. Only an Owner can grant the Owner role, and there's always at least one Owner.
- Project roles — open a project → Members and assign an existing org member as Project Manager or Project Read-Only. An org Admin, or a project's own Project Manager, can manage that project's members.
Tip. For someone who should only ever touch one project, invite them as Project Read-Only at the org level (which grants almost nothing on its own), then add them to that project as a Project Manager. They'll see just that project and nothing else.
Organizations created before roles existed may still show a legacy Member role (broad project access). It's kept for compatibility and isn't offered for new invites — reassign those members to one of the roles above when convenient.