Role-Based Access Control

Role-Based Access Control

Every member of an AB Projects project has exactly one of four roles — Owner, Admin, Member, or Viewer. Roles are per project: being an Admin in one project says nothing about your role in any other.

The four roles

RoleWork in tasks & wikiManage members & workflowOwnership & deletion
Owner Full Full, including granting Admin and removing Admins Transfers ownership; deletes the project (when unlinked)
Admin Full Changes Member/Viewer roles, removes members, configures workflow, integrations, and the Teams link No
Member Create, edit, assign, comment, complete No No
Viewer Read-only; can't be assigned tasks No No

Two Admin limits worth knowing: an Admin cannot grant the Admin role (in the role dropdown, the Admin option only appears for the Owner), and an Admin cannot remove another Admin — both are Owner-only.

Everyone starts as Member

Whether someone joins by the automatic Teams-channel sync or the Team page invite (see Adding or Removing Members), they join as Member. The sync never touches roles you've set afterward — a Viewer stays a Viewer through every future channel sync.

Changing a role

  1. Open the project's settings. Members are listed under Joined Members.
  2. Pick the new role from the dropdown under the person's name: Member, Viewer, or (Owner only) Admin. The change takes effect immediately and applies only to that project.

A few guardrails keep every project safely manageable:

  • A project can't lose its last Admin. Demoting the last Admin to Member is blocked.
  • No shortcut to Owner. Nobody can be promoted straight to Owner — ownership only moves through the transfer below.
  • Viewer promotions go one step at a time. A Viewer is promoted to Member first; Member to Admin is a separate (Owner-made) step.
  • Owners can't demote themselves with the role dropdown — that's what the ownership transfer is for.

Transferring ownership

In the project's settings, the Owner uses Step Down from Owner: pick a member to promote, choose whether they become Admin or Owner, and confirm with Yes, promote & step down. Both changes happen together — the chosen person is promoted and the previous Owner becomes a regular Member. Full walkthrough: Managing Project Settings.

Best practices

  • Keep at least two Admins on an active project, so management isn't bottlenecked on one person's availability.
  • Use Viewer for auditors, execs, and clients who should see progress but not edit — it's cleaner than asking them to “please not touch anything.”
  • Review Joined Members periodically together with the Teams channel roster — the channel is what drives membership in the first place.

Four roles, per-project scope, and a handful of guardrails: enough structure to keep access honest, without a permission matrix anyone has to study.

Published on 2025-07-07
Last updated on 2026-07-17
Version 7