Skip to main content
A user’s effective access in Gradial is calculated from three things:
  1. Primary organization role — the user’s platform-wide role: Owner, Admin, Member, or Viewer.
  2. Additional access (optional) — add-on permissions layered on top of the primary role: Brand Manager and Designer.
  3. Workspace role — what the user can do inside a specific workspace: Owner, Admin, Member, or Viewer.
Permissions combine across these layers — additional access and workspace roles add to a user’s primary organization role; they never replace it.
Looking to add someone to your team? See Adding Team Members for step-by-step instructions on inviting users and configuring workspace access.

Primary Organization Roles

Every user has exactly one primary organization role, set from Settings → People → Members. To see every role and who currently holds it, open Settings → People → Roles. Each role row can be expanded to show its members, and the list can be searched and filtered by scope (organization or workspace). Brand Manager and Designer appear here at the organization scope, alongside the four primary roles.
  • Organization Owners hold billing, organization deletion, and organization ownership transfer rights — permissions no other role has.
  • Organization Admins manage the organization day to day and can reach every standard workspace, but cannot delete the organization, manage billing, or transfer organization ownership.
  • Changing a user’s organization role changes their inherited access immediately.

Additional Access

A user may have their primary role plus one or both of these add-ons, assigned under Additional access in the role picker on the People page. They are organization-level add-ons — they are not workspace roles, and they don’t replace the primary role.
Design system creation, editing, and deletion is authorized at the organization level: Organization Owners, Organization Admins, and users with Designer additional access. Workspace membership alone — including Workspace Admin — does not grant design-system management.

Workspace Roles

Within a workspace, a user has one of four roles.

Public and Private Workspace Access

Public standard workspaces

Public standard workspaces are accessible to everyone in the organization:
  • Organization Members receive effective Workspace Member access.
  • Organization Viewers receive effective Workspace Viewer access.

Private standard workspaces

Access to a private standard workspace can come from any of these paths:
  • Direct membership — the user is added to the workspace individually
  • Custom workspace group — the user belongs to a group granted access (User Groups)
  • SCIM group mapping — the user belongs to an identity provider group mapped to the workspace (SCIM User Provisioning)
Exception: Organization Owners and Organization Admins can access every standard workspace — public or private — without direct membership. Removing a workspace grant does not remove an Organization Owner’s or Organization Admin’s inherited access.

Task Visibility and Explore Chat Privacy

Workspace access does not expose every conversation in a workspace:
  • Committed Tasks follow workspace access — anyone who can access the workspace can see them according to their workspace role.
  • Explore chats are creator-private. Another Workspace Member or Workspace Admin cannot view your Explore chat just because they can access the workspace.
  • Organization Owners and Organization Admins can read another user’s Explore chat for governance purposes, but that access is view-only — they cannot edit, delete, or add messages to it.

Managing Users

For step-by-step instructions on inviting users, granting workspace access, and changing roles, see Adding Team Members.

Quick Notes

  • A user’s effective access is the combination of their primary organization role, any additional access, and their workspace role.
  • Organization Owners and Admins don’t need to be added at the workspace level — they can access every standard workspace automatically.
  • Brand Manager and Designer are organization-level additional access, not workspace roles.
  • Organization ownership can be transferred by an Organization Owner. Workspace ownership can be transferred by a Workspace Owner, Workspace Admin, or Organization Admin.
  • To invite new users or modify access, see Adding Team Members.