User Permissions

    Control what each person in your workspace can reach.

    Intermediate2 min readUpdated 13 Sep 2026

    Permissions come from roles

    Each team member's role determines what they can see and do. Full detail is in Roles and Permissions.

    The principle

    Give the least access that lets someone do their job. Most data incidents are not attacks — they are an ordinary mistake made by someone who had a permission they did not need.

    In practice

    • Billing — restrict to whoever owns the budget.
    • Contacts — restrict to people running campaigns. Contact data is the most sensitive thing in the workspace.
    • Exports — remember that anyone who can read results can take a copy of them.
    • Team management — the ability to invite is the ability to grant access. Keep it narrow.

    Enforcement

    Permissions are enforced on the server, not just by hiding buttons. A user who has not been granted something cannot reach it by typing a URL.

    Watching changes

    Permission changes appear in Workspace → Activity, with who made them and when. Review it after any change to who is on the team.

    Tip — Diary a quarterly access review. It takes ten minutes and is the only reliable way to stop permissions accumulating.

    Was this article helpful?

    Still need help?

    Tell us what you were trying to do and we will get back to you.

    Contact SurveyKar support