TrayPage Docs

Permission reference

Role-based reference for common organization, project, and page operations.

TrayPage combines team roles with page-specific sharing settings to decide who can do what.

  • Creating projects, changing settings, and managing members are controlled by organization and project roles.
  • Opening a page, adding a version, publishing, and changing sharing settings are controlled by organization/project roles plus page-specific shares.
  • Whether someone can view the page body from a share link depends on sharing access, individual shares, and allowed company domains.
  • Commenting requires sign-in. Anonymous people with a public share link can view the page body, but they cannot comment.
  • Buttons in the app change based on the current user's permissions. The server still performs the final check.

Management operations

If either the organization role or the project role says "Yes" for an operation, the user can perform that operation. For example, organization owners and admins can broadly manage projects and page publishing, while project editors can add versions in projects they belong to.

Organization and members

OperationDescriptionOrganization ownerOrganization adminOrganization memberOrganization viewerProject adminProject editorProject viewer
Open organizationRead organization basics and membership contextYesYesYesYes---
Update organization settingsChange organization name and organization-wide settingsYesYes-----
View audit logRead the organization's audit logYesYes-----
View allowed email domainsRead settings for domain-user visibilityYesYes-----
Update allowed email domainsChange settings for domain-user visibilityYesYes-----
List membersView organization membersYesYesYesYes---
Invite membersInvite or add organization membersYesYes-----
Change member roleChange an organization member's roleYesYes-----
Remove membersRemove members from the organizationYesYes-----

Projects

OperationDescriptionOrganization ownerOrganization adminOrganization memberOrganization viewerProject adminProject editorProject viewer
List projectsView projects in an organizationYesYesYesYes---
Create projectCreate a new project in an organizationYesYesYes----
Open projectRead project surfaces and basic settingsYesYes--YesYesYes
Update project settingsChange project name or default visibilityYesYes--Yes--
Archive projectArchive a projectYesYes--Yes--
Add project memberAdd an organization member to a projectYesYes--Yes--

Pages in a project

OperationDescriptionOrganization ownerOrganization adminOrganization memberOrganization viewerProject adminProject editorProject viewer
List pagesView pages in a projectYesYes--YesYesYes
Publish pagePublish a page into a projectYesYes--YesYes-
Restore archived pageRestore an archived page from the project viewYesYes--Yes--
Open pageOpen the in-app page workbench and internal page APIsYesYes--YesYesYes
Upload versionUpload a new version or change editable page metadataYesYes--YesYes-
Publish versionMake a version live and pin it as sharedYesYes--Yes--
Manage accessManage visibility, grants, share links, moves, and archive stateYesYes--Yes--
Read commentsRead review comments and revision promptsYesYes--YesYesYes
Write commentsCreate review comments and repliesYesYes--YesYesYes
Resolve commentsResolve review comment threadsYesYes--YesYes-

Shared-Page Viewing And Explicit Grants

Shared-page viewing is evaluated separately from the management table above because it depends on sharing access, individual shares, allowed company domains, and link expiration.

Page permissionWhat it allows
ViewerView a page
EditorAdd new versions and work through review comments
AdminPublish versions, change sharing access, and manage individual shares

Users with individual page shares can use these page permissions for in-app operations. Comment creation requires sign-in, and signed-in users who can view the page body can comment. Anonymous public-link viewers are view-only.

See How it works for sharing access types.

On this page