Manage team access to airfocus workspaces using roles, permissions, and groups for security and collaboration. Read on to learn how to use these features to grant the appropriate level of access to every user.
Members
The term "member" applies to all airfocus users. Account admins can invite team members to collaborate in airfocus by following these steps:
- Click your name in the bottom-left corner of airfocus.
- Select Team settings.
- Click + Invite member.
- You can change member role to Admin, Editor or Contributor form this panel. You can also manage their permissions by clicking the three dot menu to the left of their member role or remove them from the team.
- You can also bulk import your contacts through a CSV file by clicking + Bulk import via CSV in the bottom-left corner of the team settings. Full name and email address are the fields that can be imported, and a default role can be set for all members.
- Type the email address of the new member, as well as their full name and role.
After your colleagues accept their invitation, they can collaborate with you in your workspace. Keep in mind, the invitation link is valid for 24 hours. You can add or remove team members at any time.
If you add new members during the billing cycle (from the in-app billing page), we only charge for the time used.
Remove a team member
When you remove a team member, the removal becomes effective at the end of the current billing period.
- Deactivating a member keeps their name.
- Deleting a member replaces their name with '???'.
Member groups
Member groups allow you to organize multiple members into reusable groups, making it easier to manage access and collaboration at scale.
Create and manage groups
To create a new member group, follow these steps:
- Click your name in the bottom-left corner of airfocus.
- Select Team settings.
- Click Member groups.
- Create a new group, give it a name, and add members.
Members in a group inherit the same workspace permissions that are assigned to that group.
Use groups for permissions
Assign Member groups to workspaces or workspace groups to grant or change permissions in bulk.
We recommend setting permissions as high as possible (e.g. at a workspace group level) so they cascade downwards.
Use groups on items
Member groups can be used across items in the same way as individual members:
- Assign as item assignees: Groups can be added as assignees, either on their own or alongside individuals.
- Add to custom people fields: Groups can be selected in custom people fields, alongside individual members.
- Tag in descriptions and comments: Mention groups with @ just like individuals. All members of the group are notified.
- Notifications and watching: When a group is assigned or mentioned, all members automatically become watchers and receive notifications, exactly as they would if added individually.
- Grouping & filtering in views: Groups appear and can be used in filters and groupings just like individuals.
Update groups
Add or remove members at any time. Changes apply everywhere the group is assigned.
Deactivate a group if it’s no longer needed.
Roles
There are three possible roles a member can have in airfocus:
- Admins manage team settings (members, workspaces, billing) and everything an editor can do.
- Editors are the default role with all normal editing rights. They can manage workspaces and edit items.
- Contributors can read selected workspaces and comment on items.
Member roles are not workspace specific.
The number of members as well as the different roles available on your account is determined by the licenses included in your subscription.
Notes:
- Admins and Editors both need an "Editor seat". Contributors need a "Contributor seat".
- New members stay "Unseated" if no editor seats are available. To add them, update your subscription.
- This means you need to update your subscription accordingly in order to add them to the team.
Roles overview
| Admin | Editor | Contributor | |
| Invite & manage members | ✔️ | ||
| Manage billing settings | ✔️ | ||
| Manage team-wide workspace sorting | ✔️ | ||
| Create and manage team fields | ✔️ | ||
| Create objective workspaces | ✔️ | ||
| Manage status presets | ✔️ | ||
| Create workspaces | ✔️ | ✔️ | |
| Create workspace groups and nested groups | ✔️ | ✔️ | |
| Manage permissions for own workspace | ✔️ | ✔️ | |
| Create and manage API keys & share links | ✔️ | ✔️ | |
| Set up integrations | ✔️ | ✔️ | |
| Create and manage items | ✔️ | ✔️ | |
| Create and manage Priority Poker games | ✔️ | ✔️ | |
| Join Priority Poker games | ✔️ | ✔️ | ✔️ |
| Comment on items | ✔️ | ✔️ | ✔️ |
| Get assigned to items | ✔️ | ✔️ | ✔️ |
| airfocus login | ✔️ | ✔️ | ✔️ |
| Read & view workspaces | ✔️ | ✔️ | ✔️ |
| Provide feedback | ✔️ | ✔️ | ✔️ |
| View Reporting | ✔️ | ✔️ | ✔️ |
Permissions
Working together with roles are permissions. Permissions determine how admins, editors, and contributors can access airfocus features and actions across the application.
There are five levels of permissions:
- Full
- Write
- Comment
- Read Only
- No access
They need to be set up per workspace and are limited by the member's role already.
For example, a contributor never has full access to any workspace. These permissions can by default only be edited by the creator of a workspace or every admin. By default, every new member is created without any permissions or access to any workspace and the permissions need to be granted after the new member was created.
Note: If your account already has Team Permissions set up on a workspace, new members will inherit those permissions. You do not need to apply individual permissions for each member. For more information about Team Permissions, check out our Organize with workspace groups in airfocus article.
Permissions overview
| Full | Write | Comment | Read-only | |
| See workspace | ✔️ | ✔️ | ✔️ | ✔️ |
| See workspace items | ✔️ | ✔️ | ✔️ | ✔️ |
| Join Priority Poker games | ✔️ | ✔️ | ✔️ | ✔️ |
| Comment on items | ✔️ | ✔️ | ✔️ | |
| Create, own Priority Poker games | ✔️ | ✔️ | ||
| Add, edit, delete workspace items | ✔️ | ✔️ | ||
| Share, export views & manage share links | ✔️ | ✔️ | ||
| Manage workspaces (titles, fields, views, permissions) | ✔️ | |||
| Delete workspaces | ✔️ | |||
| Manage workspace permissions | ✔️ | |||
| Manage workspace group/subgroup permissions | ✔️ | |||
| Manage apps and integrations | ✔️ |
Note: Some apps (for example, the Portal and Objectives app) may require you to be an admin to make changes.
Edit permissions
There are two different ways to edit the permissions of a member within airfocus. Both are dependent on your current role and the permissions you have within airfocus.
- Edit permissions from the workspace settings. (You'll need full access to a workspace as Editor or Admin)
- Edit permissions from the global workspace settings. (You'll need Admin access)
Edit permissions from the workspace menu
To edit permissions from the workspace menu you need to be an Admin or Editor with full access to the specific workspace.
- Open the three-dot menu next to the title of your workspace.
- Select Settings.
- Click Permissions from the tabs at the top.
- Edit permissions using the dropdown to the right of each team member.
Edit permissions from the global workspace settings
If an admin or editor who owns a workspace is unable to change permissions, account admins can change them from the global workspace settings by following these steps:
- Click your name in the bottom-left corner of airfocus.
- Select Team settings.
- Click the Workspaces tab.
- Select the workspace for which you want to change the permissions.
- Add, edit, and remove members and permissions for that specific workspace.
Mirrored workspaces permissions
With our Item Mirror app, it's possible to combine the items from different workspaces in one portfolio-wide overview.
You need full admin permissions to install the Item Mirror app in a workspace.
Apart from that, it's also important what kind of permissions you have for the workspaces you want to use as a source for your combined view.
You also need "Full" permissions for all other workspaces you want to combine.
Cascade permissions for objective workspaces
Cascading permissions allow access settings to automatically flow from a parent objective workspaces down to all its child objective workspaces. Instead of manually configuring access for every single layer, permissions given at the top level automatically extend downward.
Note the following:
- Users and teams do not need to be manually added to child workspaces. If they have permission at the parent level, the system automatically grants them the corresponding access below.
- Cascading permissions also apply to team permissions. When a team is granted access to a parent objective workspace, all members of that team automatically inherit access to all nested child objective workspaces.
- The user interface inside a child workspace will display a banner at the top indicating that permissions are being inherited from a parent workspace. However, the individual permission dropdown menus themselves will not automatically update to match the parent settings.
To enable cascading permissions, access the objective workspace settings and toggling on “Cascade permissions” at the top of the panel.
How permissions work in workspace groups and nested groups
Workspace group permissions control access for both individuals and teams.
To edit group permissions:
- Click the three-dot menu next to the group name.
- Select Settings.
- Adjust individual or team-wide permissions.
A member's final permission level to an individual workspace is always the highest level found among the four permission settings:
- Workspace individual permissions
- Workspace team permissions
- Workspace group individual permissions (if present)
- Workspace group team permissions (if present)
Group-level permissions do not overwrite individual permissions to workspaces but potentially supersede them.
If a member has "Full" permissions to several groups, they can re-organize them in the side navigation.
Members with “Full“ permissions to the group can re-order workspaces inside a group.
Move a workspace into a group
To move a workspace into a group, the member needs "Full" permissions to the group and "Full" permissions to the workspace.
To move a workspace between two groups, the member needs "Full" permissions on both groups.
When a member moves a workspace out of a group and/or deletes the group:
- The member receives the "Full" permissions to the now independent workspace(s).
- All other members of the workspace(s) keep their individual permissions.
- Group members do not get automatically assigned their group permissions as individual workspace permissions. They will lose their group-bound access to the workspace(s).
Workspace permission examples
Example #1
If a user is allocated individual user permissions to a workspace, and higher group-level permissions are allocated, the user now inherits these higher group-level permissions.
With the configuration below, ALL team members, with sufficient roles have "Full" access to all the workspaces within the Kirst fake CRM group.
All the permissions set that are outlined in red get superseded by the green team permissions at the group level.
No settings on the individual Contacts workspace are higher than any settings on the group, therefore they are ignored.
In the screenshots below, we only show one ⚠️ icon and tooltip, whereas in reality, all scenarios in red should have this. ⚠️
Example #2
Kirsten has "Full" permission to access every workspace within the Kirst fake CRM workspace group.
The rest of the team has "Write" permission to every workspace within the Kirst fake CRM workspace group.
No settings on the individual Contacts workspace are higher than any settings on the group; therefore, they are ignored.
Example #3
Kirsten has "Full" access to ALL workspaces within the group.
All other team members have "Comment" access to ALL workspaces within the group.
Adding more "Comment" permissions for individuals at the group level is redundant - team permissions already cover this.
Similarly, adding any equal (e.g. Kirsten: "Full") or lower (e.g. team: NO ACCESS) permissions at the workspace level is redundant - these are all superseded by what has been set at the group level.
Recommendations
- The best way to handle permissions is to set them up starting from lowest permission for the widest scope to highest permission for the narrowest scope
- For example, "Everyone in my team should have at least X permission to this group of workspaces, but John and Jessica should have higher permissions to workspaces A and B in that group."
- This serves as an example of the broadest to the narrowest scopes. You can also configure those intermediate cases (specific users per group, or whole teams per single WS).
Give feedback on this article
Have feedback about this article? Tell us about your experience here.