Permissions are scoped to a workspace. Most use module:action:resource; some established keys have a different shape. A write permission does not automatically grant read access. The live Settings → Permissions view shows your grants; the team permission dialog shows the available catalogue.
| Permission | What it allows |
|---|---|
account:admin:team |
Add or remove members and grant or revoke permissions |
account:api:access |
Allows creating API tokens and authorising OAuth integrations |
account:read:team |
View team members and their permissions |
account:read:teams |
View teams and membership |
account:write:teams |
Catalogue key for team writing; it does not by itself authorise the current team-management endpoints. Updates, deletion and member changes require account:admin:team; team creation currently requires a platform operator |
audit:read:entity |
View the audit log for a record. Does not by itself grant access to the record — you must also be able to read the record itself |
casemanagement:read:cases |
View cases: the case list, each case’s details, and looking a case up by external key |
casemanagement:read:interactions |
View case interactions, including restricted case interactions shown on a contact’s activity |
casemanagement:write:cases |
Create, edit, and close cases; link and unlink external services; register case external keys |
casemanagement:write:interactions |
Record interactions against cases and register interaction external keys |
donorfy:config:change |
Configure the Donorfy integration settings |
dotdigital:settings:change |
Configure the Dotdigital integration settings |
engage:read:forms |
View Engage forms, their settings and embed codes |
engage:read:submissions |
View the submissions received by Engage forms |
engage:write:forms |
Create, edit, publish and archive Engage forms, and rotate their embed keys |
events:read:events |
View events and their details. Payments and touchpoints linked to an event are shown only with relationships:read:fundraisingactivities and relationships:read:touchpoints respectively; the rest are counted as hidden |
events:write:events |
Create, edit, cancel, and delete events. Does not include viewing them — grant events:read:events as well |
exporter:run:exports |
Run exports and download your own export files |
fileattachments:read:attachments |
View file attachments and generate download URLs |
fileattachments:write:attachments |
Upload, attach, and delete files |
finance:read:ledger |
View the finance ledger (journal entries for every payment) |
impact:read:outcomes |
View programme outcome frameworks, indicators, measurements, impact dashboards and funder reports. Also requires programmes:read:programmes |
impact:write:outcomes |
Create and edit outcome frameworks, indicators and measurements, record measurements, and create and edit funder reports. Also requires programmes:read:programmes |
importer:execute:import |
Upload files and run data import jobs |
importer:manage:mappings |
Create, edit, and delete column mapping templates |
integrations:manage |
Enable and disable import integrations (Ticket Tailor, JustGiving, Dotdigital, Mailchimp) |
justgiving:settings:change |
Configure the JustGiving integration settings |
mailchimp:settings:change |
Configure the Mailchimp integration and manage audience and field mappings |
memberships:admin:types |
Create, edit, and archive membership types |
memberships:read:memberships |
View memberships and the membership types your organisation offers |
memberships:write:memberships |
Create, edit, cancel, and renew memberships, and add or remove the members they cover. Does not include viewing them |
notifications:read:targets |
View the workspace’s Slack and Microsoft Teams notification channels, including their webhook addresses |
notifications:write:targets |
Add, edit, and delete the workspace’s Slack and Microsoft Teams notification channels |
pipeline:read:funnel |
View funnel entries, the contacts linked to them, and the funnel settings |
pipeline:write:funnel |
Create and change funnel entries — edit, move stage, park and unpark, qualify and unqualify, link and unlink contacts, log touchpoints, and request next actions. Logging touchpoints also needs relationships:write:touchpoints; changing the funnel settings also needs account:admin:team |
pipeline:read:opportunities |
View pipelines and the opportunities in them, with their contacts |
pipeline:write:opportunities |
Create, edit, move, close and reopen opportunities and link their contacts, and change pipelines and their stages. Editing a pipeline’s stages also needs account:admin:team |
programmes:admin:programmes |
Archive programmes |
programmes:read:fundraiser |
Fundraiser-facing read-only view: active/seeking-funding programmes with terms and open funding needs |
programmes:read:programmes |
View programmes, terms of restriction, and funding needs (programme staff) |
programmes:write:programmes |
Create and edit all programme entities (programmes, terms, funding needs) |
relationships:admin:settings |
Manage Relationships settings: lookup lists, subtypes, custom fields, consent purposes and payment settings |
relationships:manage_contact_access |
Restrict which teams or users can see specific fields on a contact |
relationships:read:contacts |
View contacts, organisations, and things |
relationships:read:fundraisingactivities |
View fundraising activities and payments |
relationships:read:touchpoints |
View touchpoint activity on contacts |
relationships:write:contacts |
Create, edit, and delete contacts, organisations, and things |
relationships:write:fundraisingactivities |
Create, edit, and delete fundraising activities and payments |
relationships:write:touchpoints |
Log new touchpoints against contacts |
sponsorship:admin:config |
Set a sponsorship programme’s configuration: who is sponsored, where the money goes, amounts, sponsors per sponsorable, communication and the profile fields |
sponsorship:approve:sponsorables |
Approve or reject sponsorables submitted for review |
sponsorship:read:audit |
View the audit trail of who viewed or changed a sponsorable |
sponsorship:read:identity |
See who a sponsorable is: the linked contact and the field partner |
sponsorship:read:sponsorables |
View sponsorship programmes, their configuration, and sponsorables, groups and consent records. Identifying details also need sponsorship:read:identity |
sponsorship:write:sponsorables |
Create and edit sponsorables, groups, profile versions and consent records, and submit sponsorables for review. Does not include viewing them |
sysadmin:admin |
Full platform administration — reserved for ThirdSectorBee staff |
tasks:read:tasks |
View tasks you can access, follow or unfollow them, and look them up by external key |
tasks:write:tasks |
Create, edit, complete, and delete tasks you can access, and register their external keys. Changing an existing task also needs tasks:read:tasks |
taxes:admin:giftaid |
Create Gift Aid claims and move them through submission to HMRC; link claims to external systems |
taxes:read:giftaid |
View Gift Aid declarations, claims and the Gift Aid summary |
taxes:write:giftaid |
Create and cancel Gift Aid declarations, check payment eligibility, and link declarations to external systems |
tickettailor:settings:change |
Configure the TicketTailor integration and manage event-to-activity mappings |
tickettailor:sync:initiate |
Trigger a sync from TicketTailor (full or scoped to a single event) |
workerbees:admin:automations |
Create, edit, pause, and delete worker bee automations. An automation can only use actions whose permissions its author also holds (for example notifications:read:targets to post to Slack or Teams, relationships:read:contacts to email or text a contact) |
workerbees:read:automations |
View worker bee automations, their run history, and the actions available to them |
zapier:hooks:manage |
Let a Zapier connection subscribe Zaps to the events your organisation has allowed |
zapier:settings:change |
Choose which events are sent to Zapier and pause or resume sending |
Case management access is not implied by workspace membership. Only members of the superadmin team hold the four
casemanagement:permissions automatically; everyone else needs them granted before they can open Cases. Each is separate: a write permission does not include the matching read permission.
Engage forms need
engage:read:formsto open andengage:write:formsto change — grant both to form editors, because one does not include the other. Submissions contain what members of the public entered, so they have their own permission,engage:read:submissions. Connecting, onboarding or disconnecting Stripe for card payments requiresaccount:admin:team; a form editor without it can still see whether card payments are available when building a form. Public forms, their submission and payment endpoints need no permission. Worker bees and notification channels are not open to every member. Viewing automations needsworkerbees:read:automationsorworkerbees:admin:automations; creating, editing, pausing or deleting them needsworkerbees:admin:automations. Viewing the workspace’s Slack and Teams channels needsnotifications:read:targets, and changing them needsnotifications:write:targets.
sysadmin:admincannot be assigned through the workspace settings UI. It is granted to platform staff only.
Billing for your ThirdSectorBee subscription — the billing status and contacts, the plan, setting up billing and opening the Stripe billing portal — requires
account:admin:team. Everyone still sees trial and payment-overdue banners. Payment statistics (giving dashboards, a contact’s or organisation’s giving totals) requirerelationships:read:fundraisingactivities, and a contact’s or organisation’s totals are shown only to people who can also see that contact or organisation.
Everyone in a workspace can see its member and team directory — names, email addresses, team names and which teams they are in themselves — so that tasks, cases and records can be assigned.
account:read:teamadditionally shows members’ roles and other users’ direct permissions;account:read:teamsshows what each team grants and its full membership. Removing members from the workspace or a team, and deleting teams, requiresaccount:admin:team— and you can only remove a team’s permissions from people if you hold all of them yourself.
Who can change permissions
Users with account:admin:team manage grants through Settings → Team → Manage → Permissions. They can grant only permissions they hold. See Invite a team member for direct, inherited and denied permissions.