Roles

Understanding Roles & Permissions

Last updated September 15, 2026  ·  4 min read

Every account in PMS has exactly one role, and that role determines what they can see and do across the whole organization. Permission checks happen throughout the app wherever an action is taken, rather than through one central permissions page; this article is the closest thing to that overview.

The Roles, from Most to Least Access

  • Admin: Full access to everything, including organization-wide settings and the ability to manage other Admins and Managers.
  • Manager: Nearly the same day-to-day operational access as an Admin (projects, tasks, team management), but can’t create or resign Admin/Manager accounts and can’t permanently delete users.
  • Team Lead: A regular team member with added authority specifically over Deliverables (can approve, reject, and pause deliverables they didn’t create) and team-level reporting.
  • Member: The standard role; works on assigned tasks and projects, without management-level permissions.
  • Guest: A separate account type entirely for people outside your core team, scoped to specific projects. Covered in the Team Members section.

What an Admin Can Do

Admin is the highest level of access in your organization. Anything Managers can do, Admins can also do, plus a handful of things reserved for Admins only.

  • Creating or editing other Admin and Manager accounts. Managers can’t do this.
  • Resigning an Admin or Manager account.
  • Permanently deleting a user (Managers can only request a deletion).
  • Everything Managers can do: managing projects, tasks, teams, visibility, and reviewing/approving work across the organization.

What a Manager Can Do

Managers have almost all the same day-to-day powers as Admins, with a few sensitive actions carved out.

  • Create, edit, and manage projects, tasks, and teams including setting project visibility and access credentials.
  • Approve, reject, and review submitted tasks and deliverables.
  • Invite and edit team members, and add or manage guests.
  • Resign a Member, Team Lead, or Guest (but not an Admin or Manager).

What Managers can’t do: create Admin or Manager accounts, resign an Admin or Manager, or permanently delete a user (they can only request deletion). For nearly everything else in the app, Manager and Admin are treated the same.

What a Team Lead Can Do

Team Lead sits between Member and Manager; it’s still a regular working role, but with specific added authority over Deliverables and reporting.

  • Approving, rejecting, and pausing Deliverables, even ones they didn’t personally create, as long as they hold the Team Lead role.
  • A dedicated team view in Reports, showing performance across their team rather than just their own work.
  • Being eligible to be set as a specific team’s leader, which also makes them the default assignee when that team is attached to a new project.

This extra authority is concentrated on Deliverables specifically for Tasks; the same approve/reject actions are generally restricted to a task’s own creator, an Admin/Manager, or the right person in a delegation chain, not to Team Leads broadly. Being a Team Lead is an org-wide role, but being “the” leader of a specific team is a separate, additional step.

What a Member Can Do

Member is the standard, default role focused on doing assigned work rather than managing other people’s.

  • Work on tasks and deliverables assigned to them: acknowledge, pause/resume, submit, and comment.
  • Create their own Self Tasks.
  • View projects they’re a member of, or have been given visibility into.
  • Delegate a task to someone else, if that task allows it.

Members generally can’t approve or reject other people’s submitted work, edit project-level settings, or manage other users; those actions are reserved for Team Lead (Deliverables only), Manager, or Admin.

What a Guest Can Do (and How It’s Different)

Guest isn’t just a restricted version of Member; it’s a genuinely separate account type, meant for people outside your core organization.

  • Guests are scoped to specific projects they’re explicitly added to, rather than being invited into the organization broadly.
  • Guest accounts are managed through their own dedicated actions: invite, resend invitation, reset password, suspend/reactivate, rather than the standard user edit flow.
  • A Guest’s access can be switched on or off (suspended/reactivated) independently, without going through resignation or deletion.

Good to know:

  • A person has one role at a time; role and team membership are separate things. Being a project’s Team Lead specifically also requires being added as that team’s leader.
  • If someone needs full working access across multiple projects long-term, a regular Member account is usually the better fit. Guest is meant for narrower, project-specific access.
Still stuck? Contact our support team and we'll help you sort it out.