Permission reference
Role-based reference for common organization, project, and page operations.
TrayPage combines team roles with page-specific sharing settings to decide who can do what.
- Creating projects, changing settings, and managing members are controlled by organization and project roles.
- Opening a page, adding a version, publishing, and changing sharing settings are controlled by organization/project roles plus page-specific shares.
- Whether someone can view the page body from a share link depends on sharing access, individual shares, and allowed company domains.
- Commenting requires sign-in. Anonymous people with a public share link can view the page body, but they cannot comment.
- Buttons in the app change based on the current user's permissions. The server still performs the final check.
Management operations
If either the organization role or the project role says "Yes" for an operation, the user can perform that operation. For example, organization owners and admins can broadly manage projects and page publishing, while project editors can add versions in projects they belong to.
Organization and members
| Operation | Description | Organization owner | Organization admin | Organization member | Organization viewer | Project admin | Project editor | Project viewer |
|---|---|---|---|---|---|---|---|---|
| Open organization | Read organization basics and membership context | Yes | Yes | Yes | Yes | - | - | - |
| Update organization settings | Change organization name and organization-wide settings | Yes | Yes | - | - | - | - | - |
| View audit log | Read the organization's audit log | Yes | Yes | - | - | - | - | - |
| View allowed email domains | Read settings for domain-user visibility | Yes | Yes | - | - | - | - | - |
| Update allowed email domains | Change settings for domain-user visibility | Yes | Yes | - | - | - | - | - |
| List members | View organization members | Yes | Yes | Yes | Yes | - | - | - |
| Invite members | Invite or add organization members | Yes | Yes | - | - | - | - | - |
| Change member role | Change an organization member's role | Yes | Yes | - | - | - | - | - |
| Remove members | Remove members from the organization | Yes | Yes | - | - | - | - | - |
Projects
| Operation | Description | Organization owner | Organization admin | Organization member | Organization viewer | Project admin | Project editor | Project viewer |
|---|---|---|---|---|---|---|---|---|
| List projects | View projects in an organization | Yes | Yes | Yes | Yes | - | - | - |
| Create project | Create a new project in an organization | Yes | Yes | Yes | - | - | - | - |
| Open project | Read project surfaces and basic settings | Yes | Yes | - | - | Yes | Yes | Yes |
| Update project settings | Change project name or default visibility | Yes | Yes | - | - | Yes | - | - |
| Archive project | Archive a project | Yes | Yes | - | - | Yes | - | - |
| Add project member | Add an organization member to a project | Yes | Yes | - | - | Yes | - | - |
Pages in a project
| Operation | Description | Organization owner | Organization admin | Organization member | Organization viewer | Project admin | Project editor | Project viewer |
|---|---|---|---|---|---|---|---|---|
| List pages | View pages in a project | Yes | Yes | - | - | Yes | Yes | Yes |
| Publish page | Publish a page into a project | Yes | Yes | - | - | Yes | Yes | - |
| Restore archived page | Restore an archived page from the project view | Yes | Yes | - | - | Yes | - | - |
| Open page | Open the in-app page workbench and internal page APIs | Yes | Yes | - | - | Yes | Yes | Yes |
| Upload version | Upload a new version or change editable page metadata | Yes | Yes | - | - | Yes | Yes | - |
| Publish version | Make a version live and pin it as shared | Yes | Yes | - | - | Yes | - | - |
| Manage access | Manage visibility, grants, share links, moves, and archive state | Yes | Yes | - | - | Yes | - | - |
| Read comments | Read review comments and revision prompts | Yes | Yes | - | - | Yes | Yes | Yes |
| Write comments | Create review comments and replies | Yes | Yes | - | - | Yes | Yes | Yes |
| Resolve comments | Resolve review comment threads | Yes | Yes | - | - | Yes | Yes | - |
Shared-Page Viewing And Explicit Grants
Shared-page viewing is evaluated separately from the management table above because it depends on sharing access, individual shares, allowed company domains, and link expiration.
| Page permission | What it allows |
|---|---|
| Viewer | View a page |
| Editor | Add new versions and work through review comments |
| Admin | Publish versions, change sharing access, and manage individual shares |
Users with individual page shares can use these page permissions for in-app operations. Comment creation requires sign-in, and signed-in users who can view the page body can comment. Anonymous public-link viewers are view-only.
See How it works for sharing access types.