Access in Trace.Space is decided by two things: whether you are an org admin, and the access level your user groups give you on each item. This page is the lookup table. For the how-to, see the article User groups and access control and Managing users.
Roles
Org admin. A member of the Organization Administrators user group, which every organization has and which cannot be deleted. The Members page shows an Org admin badge, and the role reads Admin: full permission, manages people, item types and organization settings. Org admins have Manage access at the root of the item tree. Make someone an org admin with Set as Org admin in the row's ... menu.
Member. Everyone else. The role reads Editor: can create and edit items, leave comments and invite others; cannot create item types. What a member can do to a given item depends on the access level below.
View-only member. Not a separate role. A member whose user groups give View only (also shown as Readonly) access on an item behaves as a viewer of that item. The app also describes a Viewer role ("Can only read items, leave comments and invite viewers"), but there is currently no control to assign it; invited people always get the Editor role.
System admin. A platform-level flag, separate from any organization, granted by another system admin from System administration > Organizations. It adds the System administration entry to the settings menu.
Who can do what
The first two columns are members, split by the access level they have on the item in question.
Action | View only | Edit | Org admin | System admin |
Open an item, read its attributes, history and comments | Yes | Yes | Yes | |
Edit text and attributes, change the item's type | No | Yes | Yes | |
Create, move, delete and restore items under an item | No | Yes, with Edit on the parent | Yes | |
Create top-level items, import or paste at the top level | No | Only with Edit at Root | Yes | |
Import a document under an item | No | Yes | Yes | |
Export items, baselines, reviews and saved filters | Yes | Yes | Yes | |
Comment on an item, edit and delete your own comments | Yes | Yes | Yes | |
Resolve a comment | Your own comments only | Yes | Yes | |
Create or delete a trace between two items you can read | Yes | Yes | Yes | |
Create parent/child traces, move items in the tree | No | Yes, on both items | Yes | |
Trace to from the ... menu and bulk Actions | No | Yes | Yes | |
Create a baseline; add, remove and re-pin items; freeze and unfreeze | Yes | Yes | Yes | |
Archive and restore a baseline | Yes | Yes | Yes | |
Create a review, edit its details, add participants, create a revision, close it | Yes | Yes | Yes | |
Give feedback in a review | Participants only | Participants only | Participants only | |
Open a review that is not Publicly visible | Participants only | Participants only | Participants only | |
Create a test run, add testers, record results, end it | Yes | Yes | Yes | |
Create, rename and delete saved filters, matrices and analyses | Yes | Yes | Yes | |
Make a saved filter, matrix or analysis public or private | Creator only | Creator only | Creator only | |
Create and edit custom dashboards | No | Only with Edit at Root | Yes | |
Use the Space Agent chat | Yes, if a default model is set | Yes | Yes | |
Edit with AI, Fix issues with AI, regenerate an attribute | No | Yes | Yes | |
Open Organization settings and see the Members list | Yes | Yes | Yes | |
Invite people | Yes, without choosing user groups | Yes, without choosing user groups | Yes | |
Set or remove org admin, suspend, update email, change a member's groups | No | No | Yes | |
View Item types and Trace types | Yes | Yes | Yes | |
Create and edit item types, dropdowns, trace types, traceability rules and quality check defaults | No | No | Yes | |
Manage user groups, the Resources tab and per-item Access control | No | No | Yes | |
Connect Jira and GitHub | No | No | Yes | |
Create API clients | Yes | Yes | Yes | |
SSO and AI Providers pages | No | No | Yes | |
System administration: organizations, email server, identity providers, system integrations, templates, projection rebuilds | No | No | No | Yes |
Creating baselines, reviews, test runs and saved views is gated by the organization-level permission to create items, not by your access to the individual items, so a member who can only view items can still create them over the items they can see.
Access levels
Access levels are set per user group and per item. The same five levels carry two sets of labels: the group's Permissions tab and the per-item Access control dialog use four icon buttons whose tooltips read Deny, View only, Edit and Manage; the Groups by access dialog on the Resources tab uses the tags Deny, Readonly, Edit, Inherit and Manage.
Level | What it allows |
Edit (Read/Write) | Open, edit, move and delete the item, plus everything in the View only row. |
View only / Readonly | Open the item, read its history, comment, export, and create traces that are not parent/child. |
Deny | The item is hidden from the group, together with everything below it. |
Inherit | No explicit rule on this item; the level comes from the nearest ancestor that has one. |
Manage | Full access to the item and its whole subtree, overriding any Deny deeper down. Org admins have Manage at Root. |
How access is resolved
Permissions are evaluated along the path from Root to the item, and Root is the baseline for the whole tree. The app shows the same rules under How permissions work on a group's Permissions tab.
Root is required for visibility. A group needs View only or higher at Root to see any items. If Root is Deny, its members see no items at all.
The closest explicit level wins. With no Deny in the way, the nearest ancestor with an explicit level decides.
Deny blocks the subtree, unless a Manage level appears higher up the path. Manage on an ancestor grants full access to that subtree and ignores denies below it.
Inherit means no rule here. Resolution continues upward.
No explicit level anywhere means no access.
Path from Root | Result |
Root (Manage) | Manage |
Root, A (Deny), B (Manage), item | Denied: the Deny on A comes before the Manage on B |
Root, A (Manage), B (Deny), item | Manage: ignores the Deny on B |
Root, A (Deny), B (Read), item | Denied |
Root, A (Read), B, item | Read: the closest explicit ancestor is A |
Root, A (Read), B (Write), item | Write: the closest explicit ancestor is B |
Root, A, B, item, nothing explicit | No access |
Root (Deny) | No items visible |
Setting access on one item
Org admins can change access without leaving the tree. Hover an item, click ... and choose Access control; for the top level, use the ... on the Items header. The dialog lists every user group under User groups with four Permissions buttons per row (Deny, View only, Edit and Manage; hover a button to see its name). Click a button to set that level for the group. The ... at the end of a row opens the group's own page. Other members can open the dialog but cannot change it.
Special cases
Traces with read access. Read access to both items is enough to create and delete a trace. Parent/child traces change the tree, so they still need Edit on both items, and the Trace to menu entry is only offered when you have Edit on the selected items.
Review participants see the items in their review even when their groups deny those items elsewhere. Reviews that are not Publicly visible are open to participants only; enabling the AI reviewer forces a review to be public.
Comments can be resolved by their author or by anyone with Edit on the item. Only the author can edit or delete a comment.
Saved filters, matrices and analyses are private to their creator until the creator chooses Make public. Public views are listed for everyone; only the creator can switch them back to private.
API clients can be created by any member and act with that member's permissions. The Jira, GitHub and MCP sections of the Integrations page are for org admins.
Org-admin-only pages. SSO and AI Providers do not appear in the Organization settings sidebar for other members, and the User groups and Resources tabs are read-only for them.
Access denied page. Someone who opens a link to an item they cannot see gets a page that lists the org admins to ask.
The last org admin cannot be suspended, and you cannot suspend yourself.

