← Docs

Roles & permissions

Keikaku uses role-based access control. Every member of an organization has one org role; some members are additionally assigned a project role on specific projects. Permissions are enforced on the server for every action — the interface simply hides what you can't do.

Overview

There are four org-wide roles and two project-scoped roles. Org roles apply across the whole organization; project roles grant access to just the projects a person is assigned to — useful for giving someone control of their work without exposing the rest of the org.

Organization roles

Project roles

Project roles are assigned per project. A person with a project role has a minimal org footprint — they only see and touch the projects they're assigned to. Great for contractors, clients, or a team lead who owns a slice of the work.

Assigning roles

Tip. For someone who should only ever touch one project, invite them as Project Read-Only at the org level (which grants almost nothing on its own), then add them to that project as a Project Manager. They'll see just that project and nothing else.

Organizations created before roles existed may still show a legacy Member role (broad project access). It's kept for compatibility and isn't offered for new invites — reassign those members to one of the roles above when convenient.