RefractTrack Permissions and Roles: Difference between revisions
Nerdofepic (talk | contribs) No edit summary |
Nerdofepic (talk | contribs) No edit summary |
||
| Line 37: | Line 37: | ||
* [[RefractTrack_Users|Users]] | * [[RefractTrack_Users|Users]] | ||
* [[RefractTrack_Projects|Projects]] | * [[RefractTrack_Projects|Projects]] | ||
[[Category:RefractTrack]] | |||
Revision as of 03:36, 3 September 2026
Permissions and Roles
Not everyone on a team needs (or should have) the same level of access. RefractTrack lets an admin control, in fine detail, exactly what each teammate can see and do — from full admins down to a playtester who can only submit bug reports.
What can be controlled
Access can be granted separately for each area of the app, including:
- Tasks — viewing, creating, editing content, moving between columns, reviewing, archiving, cloning, and deleting
- Comments — viewing, posting, and editing
- Attachments — viewing, uploading, and removing files
- Projects — viewing, creating, editing, and deactivating
- Stages and Groups — viewing and managing a project's columns and tags
- Saved lists — viewing and managing bulk-create lists
- Export and import — backing a project up or bringing data in
- Themes and branding — changing the app's look and name
- Users and roles — managing teammates and the roles they can be assigned
Broader access always includes the narrower access it depends on — for example, being able to create tasks automatically means being able to view them too, so nobody ends up able to create something they can't then see.
Roles make this easy
Rather than setting every permission by hand for every person, an admin can define named roles — like "Reporter" or "Team Lead" — as reusable presets, then apply one to a teammate in a single click. Applying a role copies its permissions onto that person at that moment; if the role is edited later, it won't retroactively change anyone it was already applied to, so nobody's access shifts under them unexpectedly. Individual permissions can still be fine-tuned per person afterward, on top of whatever role they started from.
Admins see everything
A full admin account bypasses these checks entirely and always has complete access — including to anything added in a future update, with nothing extra to configure.
Access can be limited per project
For sensitive actions — working with tasks, comments, attachments, and backups — access can also be limited to specific projects. That means someone can be fully trusted to edit tasks in general, but still not see a project they haven't been given access to. Reporting a bug through the simplified ticket form works the other way around: by default a reporter can't submit anywhere until they're explicitly given access to at least one project, so a brand-new reporter account can't accidentally end up able to file into everything.
Managing columns, tags, and saved lists, on the other hand, is a broader, team-wide grant rather than something scoped per project — someone either can manage these across the board, or they can't; it's just which project's columns or tags they happen to be looking at that changes from page to page.