Permissions are scoped to a workspace. Most use module:action:resource; some established keys have a different shape. A write permission does not automatically grant read access. The live Settings → Permissions view shows your grants; the team permission dialog shows the available catalogue.

Permission What it allows
account:admin:team Add or remove members and grant or revoke permissions
account:api:access Allows creating API tokens and authorising OAuth integrations
account:read:team View team members and their permissions
account:read:teams View teams and membership
account:write:teams Catalogue key for team writing; it does not by itself authorise the current team-management endpoints. Updates, deletion and member changes require account:admin:team; team creation currently requires a platform operator
audit:read:entity View the audit log for a record. Does not by itself grant access to the record — you must also be able to read the record itself
casemanagement:read:cases View cases: the case list, each case’s details, and looking a case up by external key
casemanagement:read:interactions View case interactions, including restricted case interactions shown on a contact’s activity
casemanagement:write:cases Create, edit, and close cases; link and unlink external services; register case external keys
casemanagement:write:interactions Record interactions against cases and register interaction external keys
donorfy:config:change Configure the Donorfy integration settings
dotdigital:settings:change Configure the Dotdigital integration settings
engage:read:forms View Engage forms, their settings and embed codes
engage:read:submissions View the submissions received by Engage forms
engage:write:forms Create, edit, publish and archive Engage forms, and rotate their embed keys
events:read:events View events and their details. Payments and touchpoints linked to an event are shown only with relationships:read:fundraisingactivities and relationships:read:touchpoints respectively; the rest are counted as hidden
events:write:events Create, edit, cancel, and delete events. Does not include viewing them — grant events:read:events as well
exporter:run:exports Run exports and download your own export files
fileattachments:read:attachments View file attachments and generate download URLs
fileattachments:write:attachments Upload, attach, and delete files
finance:read:ledger View the finance ledger (journal entries for every payment)
impact:read:outcomes View programme outcome frameworks, indicators, measurements, impact dashboards and funder reports. Also requires programmes:read:programmes
impact:write:outcomes Create and edit outcome frameworks, indicators and measurements, record measurements, and create and edit funder reports. Also requires programmes:read:programmes
importer:execute:import Upload files and run data import jobs
importer:manage:mappings Create, edit, and delete column mapping templates
integrations:manage Enable and disable import integrations (Ticket Tailor, JustGiving, Dotdigital, Mailchimp)
justgiving:settings:change Configure the JustGiving integration settings
mailchimp:settings:change Configure the Mailchimp integration and manage audience and field mappings
memberships:admin:types Create, edit, and archive membership types
memberships:read:memberships View memberships and the membership types your organisation offers
memberships:write:memberships Create, edit, cancel, and renew memberships, and add or remove the members they cover. Does not include viewing them
notifications:read:targets View the workspace’s Slack and Microsoft Teams notification channels, including their webhook addresses
notifications:write:targets Add, edit, and delete the workspace’s Slack and Microsoft Teams notification channels
pipeline:read:funnel View funnel entries, the contacts linked to them, and the funnel settings
pipeline:write:funnel Create and change funnel entries — edit, move stage, park and unpark, qualify and unqualify, link and unlink contacts, log touchpoints, and request next actions. Logging touchpoints also needs relationships:write:touchpoints; changing the funnel settings also needs account:admin:team
pipeline:read:opportunities View pipelines and the opportunities in them, with their contacts
pipeline:write:opportunities Create, edit, move, close and reopen opportunities and link their contacts, and change pipelines and their stages. Editing a pipeline’s stages also needs account:admin:team
programmes:admin:programmes Archive programmes
programmes:read:fundraiser Fundraiser-facing read-only view: active/seeking-funding programmes with terms and open funding needs
programmes:read:programmes View programmes, terms of restriction, and funding needs (programme staff)
programmes:write:programmes Create and edit all programme entities (programmes, terms, funding needs)
relationships:admin:settings Manage Relationships settings: lookup lists, subtypes, custom fields, consent purposes and payment settings
relationships:manage_contact_access Restrict which teams or users can see specific fields on a contact
relationships:read:contacts View contacts, organisations, and things
relationships:read:fundraisingactivities View fundraising activities and payments
relationships:read:touchpoints View touchpoint activity on contacts
relationships:write:contacts Create, edit, and delete contacts, organisations, and things
relationships:write:fundraisingactivities Create, edit, and delete fundraising activities and payments
relationships:write:touchpoints Log new touchpoints against contacts
sponsorship:admin:config Set a sponsorship programme’s configuration: who is sponsored, where the money goes, amounts, sponsors per sponsorable, communication and the profile fields
sponsorship:approve:sponsorables Approve or reject sponsorables submitted for review
sponsorship:read:audit View the audit trail of who viewed or changed a sponsorable
sponsorship:read:identity See who a sponsorable is: the linked contact and the field partner
sponsorship:read:sponsorables View sponsorship programmes, their configuration, and sponsorables, groups and consent records. Identifying details also need sponsorship:read:identity
sponsorship:write:sponsorables Create and edit sponsorables, groups, profile versions and consent records, and submit sponsorables for review. Does not include viewing them
sysadmin:admin Full platform administration — reserved for ThirdSectorBee staff
tasks:read:tasks View tasks you can access, follow or unfollow them, and look them up by external key
tasks:write:tasks Create, edit, complete, and delete tasks you can access, and register their external keys. Changing an existing task also needs tasks:read:tasks
taxes:admin:giftaid Create Gift Aid claims and move them through submission to HMRC; link claims to external systems
taxes:read:giftaid View Gift Aid declarations, claims and the Gift Aid summary
taxes:write:giftaid Create and cancel Gift Aid declarations, check payment eligibility, and link declarations to external systems
tickettailor:settings:change Configure the TicketTailor integration and manage event-to-activity mappings
tickettailor:sync:initiate Trigger a sync from TicketTailor (full or scoped to a single event)
workerbees:admin:automations Create, edit, pause, and delete worker bee automations. An automation can only use actions whose permissions its author also holds (for example notifications:read:targets to post to Slack or Teams, relationships:read:contacts to email or text a contact)
workerbees:read:automations View worker bee automations, their run history, and the actions available to them
zapier:hooks:manage Let a Zapier connection subscribe Zaps to the events your organisation has allowed
zapier:settings:change Choose which events are sent to Zapier and pause or resume sending

Case management access is not implied by workspace membership. Only members of the superadmin team hold the four casemanagement: permissions automatically; everyone else needs them granted before they can open Cases. Each is separate: a write permission does not include the matching read permission.

Engage forms need engage:read:forms to open and engage:write:forms to change — grant both to form editors, because one does not include the other. Submissions contain what members of the public entered, so they have their own permission, engage:read:submissions. Connecting, onboarding or disconnecting Stripe for card payments requires account:admin:team; a form editor without it can still see whether card payments are available when building a form. Public forms, their submission and payment endpoints need no permission. Worker bees and notification channels are not open to every member. Viewing automations needs workerbees:read:automations or workerbees:admin:automations; creating, editing, pausing or deleting them needs workerbees:admin:automations. Viewing the workspace’s Slack and Teams channels needs notifications:read:targets, and changing them needs notifications:write:targets.

sysadmin:admin cannot be assigned through the workspace settings UI. It is granted to platform staff only.

Billing for your ThirdSectorBee subscription — the billing status and contacts, the plan, setting up billing and opening the Stripe billing portal — requires account:admin:team. Everyone still sees trial and payment-overdue banners. Payment statistics (giving dashboards, a contact’s or organisation’s giving totals) require relationships:read:fundraisingactivities, and a contact’s or organisation’s totals are shown only to people who can also see that contact or organisation.

Everyone in a workspace can see its member and team directory — names, email addresses, team names and which teams they are in themselves — so that tasks, cases and records can be assigned. account:read:team additionally shows members’ roles and other users’ direct permissions; account:read:teams shows what each team grants and its full membership. Removing members from the workspace or a team, and deleting teams, requires account:admin:team — and you can only remove a team’s permissions from people if you hold all of them yourself.

Who can change permissions

Users with account:admin:team manage grants through Settings → Team → Manage → Permissions. They can grant only permissions they hold. See Invite a team member for direct, inherited and denied permissions.