Skip to main content

Roles and permissions reference

Who can do what in Trace.Space: org admins, members, view-only access, system admins, the five access levels, how access is resolved down the tree, and the special cases.

Written by Matthew Maclaine

Access in Trace.Space is decided by two things: whether you are an org admin, and the access level your user groups give you on each item. This page is the lookup table. For the how-to, see the article User groups and access control and Managing users.

Roles

  • Org admin. A member of the Organization Administrators user group, which every organization has and which cannot be deleted. The Members page shows an Org admin badge, and the role reads Admin: full permission, manages people, item types and organization settings. Org admins have Manage access at the root of the item tree. Make someone an org admin with Set as Org admin in the row's ... menu.

  • Member. Everyone else. The role reads Editor: can create and edit items, leave comments and invite others; cannot create item types. What a member can do to a given item depends on the access level below.

  • View-only member. Not a separate role. A member whose user groups give View only (also shown as Readonly) access on an item behaves as a viewer of that item. The app also describes a Viewer role ("Can only read items, leave comments and invite viewers"), but there is currently no control to assign it; invited people always get the Editor role.

  • System admin. A platform-level flag, separate from any organization, granted by another system admin from System administration > Organizations. It adds the System administration entry to the settings menu.

Who can do what

The first two columns are members, split by the access level they have on the item in question.

Action

View only

Edit

Org admin

System admin

Open an item, read its attributes, history and comments

Yes

Yes

Yes

Edit text and attributes, change the item's type

No

Yes

Yes

Create, move, delete and restore items under an item

No

Yes, with Edit on the parent

Yes

Create top-level items, import or paste at the top level

No

Only with Edit at Root

Yes

Import a document under an item

No

Yes

Yes

Export items, baselines, reviews and saved filters

Yes

Yes

Yes

Comment on an item, edit and delete your own comments

Yes

Yes

Yes

Resolve a comment

Your own comments only

Yes

Yes

Create or delete a trace between two items you can read

Yes

Yes

Yes

Create parent/child traces, move items in the tree

No

Yes, on both items

Yes

Trace to from the ... menu and bulk Actions

No

Yes

Yes

Create a baseline; add, remove and re-pin items; freeze and unfreeze

Yes

Yes

Yes

Archive and restore a baseline

Yes

Yes

Yes

Create a review, edit its details, add participants, create a revision, close it

Yes

Yes

Yes

Give feedback in a review

Participants only

Participants only

Participants only

Open a review that is not Publicly visible

Participants only

Participants only

Participants only

Create a test run, add testers, record results, end it

Yes

Yes

Yes

Create, rename and delete saved filters, matrices and analyses

Yes

Yes

Yes

Make a saved filter, matrix or analysis public or private

Creator only

Creator only

Creator only

Create and edit custom dashboards

No

Only with Edit at Root

Yes

Use the Space Agent chat

Yes, if a default model is set

Yes

Yes

Edit with AI, Fix issues with AI, regenerate an attribute

No

Yes

Yes

Open Organization settings and see the Members list

Yes

Yes

Yes

Invite people

Yes, without choosing user groups

Yes, without choosing user groups

Yes

Set or remove org admin, suspend, update email, change a member's groups

No

No

Yes

View Item types and Trace types

Yes

Yes

Yes

Create and edit item types, dropdowns, trace types, traceability rules and quality check defaults

No

No

Yes

Manage user groups, the Resources tab and per-item Access control

No

No

Yes

Connect Jira and GitHub

No

No

Yes

Create API clients

Yes

Yes

Yes

SSO and AI Providers pages

No

No

Yes

System administration: organizations, email server, identity providers, system integrations, templates, projection rebuilds

No

No

No

Yes

Creating baselines, reviews, test runs and saved views is gated by the organization-level permission to create items, not by your access to the individual items, so a member who can only view items can still create them over the items they can see.

Access levels

Access levels are set per user group and per item. The same five levels carry two sets of labels: the group's Permissions tab and the per-item Access control dialog use four icon buttons whose tooltips read Deny, View only, Edit and Manage; the Groups by access dialog on the Resources tab uses the tags Deny, Readonly, Edit, Inherit and Manage.

Level

What it allows

Edit (Read/Write)

Open, edit, move and delete the item, plus everything in the View only row.

View only / Readonly

Open the item, read its history, comment, export, and create traces that are not parent/child.

Deny

The item is hidden from the group, together with everything below it.

Inherit

No explicit rule on this item; the level comes from the nearest ancestor that has one.

Manage

Full access to the item and its whole subtree, overriding any Deny deeper down. Org admins have Manage at Root.

How access is resolved

Permissions are evaluated along the path from Root to the item, and Root is the baseline for the whole tree. The app shows the same rules under How permissions work on a group's Permissions tab.

  1. Root is required for visibility. A group needs View only or higher at Root to see any items. If Root is Deny, its members see no items at all.

  2. The closest explicit level wins. With no Deny in the way, the nearest ancestor with an explicit level decides.

  3. Deny blocks the subtree, unless a Manage level appears higher up the path. Manage on an ancestor grants full access to that subtree and ignores denies below it.

  4. Inherit means no rule here. Resolution continues upward.

  5. No explicit level anywhere means no access.

Path from Root

Result

Root (Manage)

Manage

Root, A (Deny), B (Manage), item

Denied: the Deny on A comes before the Manage on B

Root, A (Manage), B (Deny), item

Manage: ignores the Deny on B

Root, A (Deny), B (Read), item

Denied

Root, A (Read), B, item

Read: the closest explicit ancestor is A

Root, A (Read), B (Write), item

Write: the closest explicit ancestor is B

Root, A, B, item, nothing explicit

No access

Root (Deny)

No items visible

Setting access on one item

Org admins can change access without leaving the tree. Hover an item, click ... and choose Access control; for the top level, use the ... on the Items header. The dialog lists every user group under User groups with four Permissions buttons per row (Deny, View only, Edit and Manage; hover a button to see its name). Click a button to set that level for the group. The ... at the end of a row opens the group's own page. Other members can open the dialog but cannot change it.

The Access control dialog opened from an item's ... menu

Special cases

  • Traces with read access. Read access to both items is enough to create and delete a trace. Parent/child traces change the tree, so they still need Edit on both items, and the Trace to menu entry is only offered when you have Edit on the selected items.

  • Review participants see the items in their review even when their groups deny those items elsewhere. Reviews that are not Publicly visible are open to participants only; enabling the AI reviewer forces a review to be public.

  • Comments can be resolved by their author or by anyone with Edit on the item. Only the author can edit or delete a comment.

  • Saved filters, matrices and analyses are private to their creator until the creator chooses Make public. Public views are listed for everyone; only the creator can switch them back to private.

  • API clients can be created by any member and act with that member's permissions. The Jira, GitHub and MCP sections of the Integrations page are for org admins.

  • Org-admin-only pages. SSO and AI Providers do not appear in the Organization settings sidebar for other members, and the User groups and Resources tabs are read-only for them.

  • Access denied page. Someone who opens a link to an item they cannot see gets a page that lists the org admins to ask.

  • The last org admin cannot be suspended, and you cannot suspend yourself.

Did this answer your question?