Coming soon

Control who sees what, down to the project level.

Built-in roles, custom RBAC, guest access for external collaborators, SAML SSO, and a complete audit log. Built for admins and IT buyers who need to approve Sprint Track with confidence.

Workspace, project, member, and role: the four layers of access.
Workspace
Tenant boundary. Members, billing, and global settings.
Project
Container for issues, cycles, and modules. Can be private.
Member
A person in the workspace, identified by SSO or email.
Role
Decides what the member can do at each level.
Built-in roles
Admin
Member
Viewer
Guest
Encrypted in transit and at rest Every action audited

How permissions work

Trust controls that admins and security teams can verify.

Six building blocks. Together they cover everything from a daily standup to an enterprise security review.

01 · Built-in roles

Four built-in roles. A predictable starting point.

Admin owns the workspace. Member runs the day-to-day. Viewer reads and comments. Guest gets scoped, read-only access for external collaborators. The comparison table below shows exactly what each role can and cannot do at a glance.

  • Admin: full control over workspace, billing, members
  • Member: create, edit, and comment on assigned projects
  • Viewer: read-only access with commenting
  • Guest: scoped read-only access for external collaborators
Capability
Admin
Full control
Member
Day-to-day
Viewer
Read-only
Guest
External
Workspace
Manage members and billing
Edit workspace settings
Create new projects
See workspace member list
Projects
Edit project settings
Add and remove project members
Create and edit issues
Comment on issues
View shared projects
Security
View audit log
Enforce SSO sign-in
Export workspace data
Workspace Manage members and billing
Workspace Edit workspace settings
Workspace Create new projects
Workspace See workspace member list
Projects Edit project settings
Projects Add and remove project members
Projects Create and edit issues
Projects Comment on issues
Projects View shared projects
Security View audit log
Security Enforce SSO sign-in
Security Export workspace data
Allowed Depends on project access Not allowed

02 · Custom roles and RBAC

Build your own roles with the exact permissions you need.

When the four built-in roles do not fit, configure custom roles from scratch. Pick a name, pick a color, copy a built-in role as a starting point, and toggle every permission across issues, cycles, project settings, and reporting. Move members into the new role in one click.

  • Configure roles per workspace, not per user
  • Copy a built-in role as a starting point
  • Toggle individual permissions across grouped categories
  • Required permissions stay locked so roles never break the basics
Custom role
RBAC
Project Lead
Start from
Permissions
12 of 16 enabled
Issues
Cycles and modules
Project settings
Reporting

03 · Project-level permissions

Workspace role and project role are independent.

A workspace Member can be an Admin in one project and a Viewer in another. Project owners manage their own membership without touching workspace settings. Private projects stay hidden from non-members in the same workspace.

  • Per-project role overrides the workspace role
  • Project owners manage their own members
  • Private projects hidden from non-members
  • Members can see their own project list and nothing else
SC
Sarah Chen
sarah@northwind.io
Workspace Member
Project Beacon
Admin in this project

Owns the engineering roadmap. Can edit settings and members.

Project Mirror
Member in this project

Contributes design reviews. Can create and edit issues.

Project Atlas Private
Viewer in this project

Read-only access on the launch plan. Cannot edit work.

Project-level roles override the workspace role for that project. A workspace Member can be an Admin in one project, a Viewer in another, and have no access to a third.

04 · Guest access

Bring clients and contractors in without exposing the workspace.

Invite external collaborators by email and scope them to a specific project. Guests see the project they were added to. They do not see the workspace member list, billing, settings, or any project they were not explicitly added to.

  • Invite by email, scope to specific projects
  • No workspace member list visibility
  • No billing or settings visibility
  • Free guest seats on every plan
Invite guests
eric@meridian-group.com priya@acme-design.studio Add another email…
Project BeaconViewer
Guests will only see this project and its issues. They will not see any other project in the workspace.
Guests can
  • View issues in Project Beacon
  • Comment on issues
  • Receive notifications they are mentioned in
Guests cannot
  • Workspace member list
  • Billing and plan
  • Workspace settings
  • Projects they were not added to

05 · SSO and authentication

Connect your identity provider in minutes.

SAML 2.0 SSO connects to Okta, Azure AD, Google Workspace, and any compliant IdP. Email and password and Google OAuth are available for standard plans. Admins can enforce SSO so every member signs in through the identity provider, every time.

  • SAML 2.0 SSO with Okta, Azure AD, Google Workspace
  • Email + password and Google OAuth for standard users
  • Admins can enforce SSO for the whole workspace
  • GDPR aligned, with a published Data Processing Agreement
Authentication
Workspace settings
SAML 2.0 SSO Recommended
Connected: Okta
Enabled
Google OAuth
Allowed for all members
Enabled
Email + password
Disabled when SSO is enforced
Disabled
Enforce SSO for all members
Active. All members must sign in via Okta. Password and OAuth are disabled.
SCIM 2.0
GDPR ready
SCIM provisioning
MFA enforced

06 · Audit log

Every action recorded, every event exportable.

Logins, issue edits, permission changes, member invites, settings updates, and deletions are all captured with the user, target, IP address, and timestamp. Filter the log by user, action type, or date range and export the result to CSV for compliance review.

  • Every member action recorded with user, target, and IP
  • Filter by user, action type, and date range
  • Export available on request for compliance review
  • 90-day retention as standard, 12 months on Enterprise
Audit log
UserActionTargetWhen
S
Sarah C.
203.0.113.42
Login
via Okta SSO
2 min ago
M
Marcus P.
203.0.113.18
Issue edited
BCN-049 status set to In Progress
14 min ago
A
Alex M.
203.0.113.42
Permission changed
Lena O. promoted to Project Admin
1h ago
L
Lena O.
203.0.113.81
Member invited
eric@meridian-group.com as Guest
2h ago
S
Sarah C.
203.0.113.42
Settings changed
Enforced SSO turned on
3h ago
K
Kai S.
203.0.113.55
Issue deleted
BCN-027 removed
yesterday
7,412events in the last 30 days
12unique users
Retained for two years on Enterprise plans.

Enterprise security on day one.

SSO, audit log, and SCIM provisioning sit on the Enterprise plan. The free tier ships with role-based access and guest invites for every workspace.

No credit card required to start