Access in Trace.Space has two layers. A member's role decides what they can do in the organization as a whole. User groups with per-item access levels decide which items each group can see, edit or manage.
Everything described here lives under Organization settings > Members, which has three tabs: Members, User groups and Resources. Click the gear icon at the top of the left sidebar and choose Organization settings to get there. Only org admins can change groups and access levels; other members see the pages read-only. Inviting and managing individual members is covered in Managing users.
Roles
There are two roles in practice: org admins, who manage people, item types and organization settings, and everyone else, who gets the Editor role. View-only access is given through a user group's access levels rather than by choosing a role. The roles, and exactly what each one may do, are listed in Roles and permissions reference.
Org admins carry an Org admin badge on the Members tab, and an admin can promote or demote a member from the row's ... menu with Set as Org admin and Remove Org admin.
User groups
A user group is a named set of members that you grant access to items. A member can belong to several groups.
On the User groups tab:
Click New group, enter a Name and click Create. The group's page opens.
Click a group's name to open it.
Hover over a row and click ... for Edit, Duplicate (creates a copy of the group with the same members, named "Copy of ...") and Delete.
Tick several groups and use Actions > Delete to remove them at once.
A group's page has two tabs.
Members lists who is in the group. Click Add members, pick people from the list and click Add members to confirm. Hover over a member and click ... > Remove from group to take them out.
Permissions shows the item tree with one access level per row. The Root permissions control at the top of the column sets the default for every item, including items created later. Expand folders to override the level for a subtree or a single item. Each row has four icon buttons; hover one to see its name:
Deny: the group cannot see the item.
View only: the group can read the item.
Edit: the group can change the item.
Manage: full access to the item and everything under it.
An inherited level is drawn in a lighter shade and its tooltip reads, for example, Edit (inherited): it comes from the nearest ancestor that has an explicit level. Click a button to set an explicit level for that item; click the already selected button again to remove the explicit level and inherit again. If Root permissions is set to Deny, a banner warns that members of the group will not see anything in the app.
Click How permissions work on the Permissions tab for the exact resolution rules. The same rules, with worked examples, are in Roles and permissions reference.
Resources
The Resources tab shows the same item tree from the item's point of view. The Groups by access column counts how many groups have Edit, View only, Deny and Manage on each item; hover over a count to see the group names.
Click the counts, or ... > Edit, to open the Groups by access dialog for that item. It lists every group with its current level. Click a group's tag to choose Edit, Readonly, Deny or Inherit, then click Save. ... > Deny all sets Deny for every group on that item in one go.
What each access level allows
In short, View only lets a member open, read and comment on the item and create traces to it; Edit adds creating, editing, moving and deleting items in that part of the tree; Manage gives full control of a subtree regardless of denies further down. The full breakdown by action is in Roles and permissions reference.
Items a member cannot see are hidden from them everywhere in the app. If someone opens a link to such an item, they see an access denied page that lists the org admins to ask.



