> For the complete documentation index, see [llms.txt](https://guides.tability.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://guides.tability.io/docs/become-a-tability-power-user/features/plans/plan-permissions.md).

# Plan permissions

Plan permissions control who can view or edit a plan and the items that belong to it, including objectives, outcomes, initiatives, check-ins, comments, and related activity.

To manage access:

1. Open the plan.
2. Select the lock or unlock icon beside the plan actions. Its tooltip summarises the current access level.
3. Use the **Manage plan permissions** modal to set the workspace default and add team or individual exceptions.

You need edit access to the plan to change its permissions. Team and individual plan permissions require a supported paid plan; Tability shows an upgrade message when the feature is unavailable.

### Permission levels

Plans have three permission levels:

| Permission | What it means                                         |
| ---------- | ----------------------------------------------------- |
| **Edit**   | Can view and make changes to the plan and its content |
| **View**   | Can view the plan and its content, but cannot edit    |
| **None**   | No access unless another permission grants access     |

Workspace owners and admins can access plans in the workspace regardless of plan-level permissions.

### How access is calculated

Plan access is additive. Tability checks all matching permissions and uses the strongest one.

Access can come from:

* **Everyone in the workspace**
* **Team permissions**
* **Individual person permissions**
* **Workspace owner/admin access**

The strongest permission wins:

* `Edit` beats `View`
* `View` beats `None`

For example:

* If Everyone has **View**, but a person has **Edit**, that person can edit.
* If Everyone has **None**, but a team has **View**, everyone in that team can view.
* If a person has **View**, but one of their teams has **Edit**, they can edit.
* Removing someone from a team removes the access they had through that team, unless they still have access another way.

### Everyone in this workspace

The **Everyone in this workspace** setting controls the default access for workspace members.

Use this when most people should have the same level of access.

The menu labels are:

* **can edit**: everyone in the workspace can edit the plan.
* **can view**: everyone in the workspace can view the plan.
* **has no access**: only explicitly added teams or people can access the plan.

### Team permissions

Team permissions let you give plan access to a whole team at once.

Under **Permissions**, use **Add team** to grant access to a team. When you add a team to a plan:

* All current team members get that permission.
* Future members added to the team also get that permission.
* Members removed from the team lose that team-based access.
* Team permissions are separate from simply linking a team to a plan for ownership or reporting.

This is the best option when access should follow an existing group, such as “Leadership”, “Marketing”, or “Product”.

### People permissions

Under **Permissions**, use **Add person** to grant access to an individual workspace member.

Use this when only a specific person needs access, or when someone needs stronger access than the rest of their team.

For example, you can give a team **View** access, then give one person on that team **Edit** access.

### Avoiding lockouts

When you restrict Everyone in the workspace to **View** or **No access**, Tability checks that there is still at least one explicit editor.

Explicit editors can come from:

* A person with **Edit** access
* A team with **Edit** access

If you are about to remove your own edit access, Tability asks you to confirm. Tability prevents you from restricting workspace-wide access when no explicit team or person editor remains.

### Missing permissions warning

Some plans include assigned owners, contributors, or reviewers. If **Everyone in this workspace** is set to **has no access** and one of those people does not have access, Tability shows a missing permissions warning. You can use **Add as viewer** to resolve an individual warning.

A person is considered covered if they have access through either:

* An individual permission
* A team permission from a team they belong to

### Recommended setup

For open plans:

1. Set **Everyone in this workspace** to **Can view** or **Can edit**.
2. Add individual or team **Edit** permissions only where needed.

For restricted plans:

1. Set **Everyone in this workspace** to **No access**.
2. Add the relevant teams with **View** or **Edit**.
3. Add individual people only for exceptions.
4. Make sure at least one team or person has **Edit** access.
