---
id: KB-ET-005
url: https://app.codecontract.io/help/your-workspace/what-permissions-to-give-each-person
idioma: en
categoria: espacio-de-trabajo
subcategoria: usuarios
audiencia: administrador
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-ET-002, KB-AD-002, KB-ET-013]
citadoPor: [KB-PR-007, KB-ET-008, KB-AD-005, KB-AD-006, KB-ET-010, KB-AD-008, KB-ET-016, KB-ET-021, KB-ET-007, KB-PS-005]
enLaApp: https://app.codecontract.io/settings/members
---

# What permissions to give each person

_Neither everyone an administrator nor everyone read-only: the split that works._

**Responde a:** configure user permissions · what role should i give a colleague · limit what someone can do · team permissions

Both extremes fail for the same reason: nobody stops to think who needs what. Everyone an administrator ends in an accidental deletion; everyone read-only ends with one person doing eight people's work.

## The split that usually works

| Profile | Can | Cannot |
| --- | --- | --- |
| Administrator | Everything, including settings and permissions | — |
| Manager | Create processes, launch sends, approve | Change organisation settings |
| Contributor | Work on their own items, upload and respond | Delete, or touch other people's processes |
| Read-only | View and download their own material | Change anything |

## Two practical rules

- Two administrators, not one and not five. With one, if they lose access nobody can fix it; with five, nobody feels responsible.
- Delete permission does the most damage and is needed least day to day. Grant it sparingly.

> [!IMPORTANT]
> An external adviser or accountancy firm does not need to administer your account. Give them read access to their own scope and nothing more: it is your information, not theirs.

> [!NOTE]
> Permissions get reviewed when someone changes role, not only when they join. A promotion leaves old permissions that no longer fit.

> [!WARNING]
> If you use teams, a broad permission in one team should not reach another team's documents. Check the scope, not just the level.

**Can I give access to only one project?**

Yes, scoped by team or by folder.

**Can I see who did what?**

Yes, every action carries its author.

**Can a contributor invite others?**

No, and it is better that way.

## Ejemplos

**A twenty-person company has all twenty as administrators.**

- Keeps two administrators
- Four area managers
- The rest as contributors within their team

→ Nobody loses the ability to work and the risk of someone deleting a whole case by accident disappears.

**Broad permissions are granted so nobody is blocked.**

- Grants what each role needs

→ The block clears without opening more than necessary.

**An intern can see sensitive documentation.**

- Reviews what belongs to each role

→ Sensitive material stays where it should.

**Nobody has reviewed permissions in two years.**

- Schedules a periodic review

→ Access reflects today's organisation.

**An external party asks for access to the whole folder.**

- Grants access to the file they need

→ They see theirs and nothing more.

**Somebody leaves and their permissions stay active.**

- Revokes access on their last day

→ The account reflects who works here.
