> For the complete documentation index, see [llms.txt](https://guides.tability.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://guides.tability.io/docs/become-a-tability-power-user/features/kpis/manage-kpi-access.md).

# Manage KPI access

Each KPI has its own access settings. Global workspace access, direct person grants, and team grants combine to determine what someone can do.

{% hint style="info" %}
KPI permissions are independent from plan and KPI View permissions. Access to a plan or View does not automatically provide access to the KPIs inside it.
{% endhint %}

## Global workspace access

Every KPI has one global access mode:

| Workspace access                             | What it means                                                                                                  |
| -------------------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| **Everyone can edit**                        | Workspace members can view and edit the KPI.                                                                   |
| **Everyone can view**                        | Workspace members can view the KPI. Editing requires a direct or team edit grant.                              |
| **Only invited people and teams can access** | Only people with a direct grant, members of a granted team, and workspace owners or admins can access the KPI. |

The lock beside a KPI name represents this global setting:

* No lock means everyone can edit.
* A standard lock means everyone can view, but editing is restricted.
* A red lock means workspace-wide access is disabled.

The lock describes global access, not your personal permission. Someone with a direct or team grant may still be able to edit a locked KPI.

## Give a person or team access

1. Open the KPI.
2. Open the **More** menu (`...`).
3. Select **Manage access**.
4. Set access for **Everyone in this workspace**.
5. Under **People** or **Teams**, select **Add person** or **Add team**.
6. Grant **Can edit** or **Can view** access.

Use the same dialog to change or remove an existing grant.

## How effective access is calculated

Tability combines all applicable grants and uses the strongest one:

* **Edit** is stronger than **View**.
* A direct person grant and a team grant can both apply.
* A stronger grant is not reduced by a weaker global setting.

For example, if everyone can view a KPI and the Sales team has edit access, members of the Sales team can edit it.

## Role rules

* Workspace **owners** and **admins** can always view and edit every KPI in their workspace.
* Workspace members with a **read-only** role can view KPIs granted to them but cannot change them.
* An **IT admin** follows the KPI's normal grants and does not automatically bypass them.
* The KPI creator receives a direct edit grant.
* Assigning a KPI owner gives that person a direct edit grant.

Tability protects restricted KPIs from being left without an editor. Add another editor before removing or reducing the final edit grant.

## Set the default for new KPIs

Workspace owners and admins can choose the starting global access for new KPIs:

1. Open **Workspace settings**.
2. Open the **Workflow** settings.
3. Find **Default KPI permissions**.
4. Choose the default access mode.

This setting affects only KPIs created after the change. An editor can still choose a different access mode while creating or editing a KPI.

## Sharing links does not change access

The KPI panel includes sharing and copy-link actions. A link does not grant access: the recipient must already be a workspace member with permission to view the KPI.

## KPIs inside plans and Views

KPI access continues to apply wherever the KPI appears:

* A plan only shows attached KPIs the viewer can access.
* A KPI View silently omits KPIs the viewer cannot access.
* To attach a KPI, an editor must be able to edit the plan or View and view the KPI.
* Removing a KPI attachment does not delete the KPI.

See [Add KPIs to plans](/docs/become-a-tability-power-user/features/kpis/add-kpis-to-plans.md) and [Create and use KPI Views](/docs/become-a-tability-power-user/features/kpis/kpi-views.md) for the complete workflows.
