> For the complete documentation index, see [llms.txt](https://guides.tability.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://guides.tability.io/docs/become-a-tability-power-user/features/plans/plan-permissions.md).

# Plan permissions

Plan permissions control who can view or edit a plan and the items that belong to it, including objectives, outcomes, initiatives, check-ins, comments, and related activity.

You can manage access from the plan’s **Manage permissions** modal.

<figure><img src="/files/6PAffxjuRLliZgxm6ALy" alt=""><figcaption></figcaption></figure>

### Permission levels

Plans have three permission levels:

| Permission | What it means                                         |
| ---------- | ----------------------------------------------------- |
| **Edit**   | Can view and make changes to the plan and its content |
| **View**   | Can view the plan and its content, but cannot edit    |
| **None**   | No access unless another permission grants access     |

Workspace owners and admins can access plans in the workspace regardless of plan-level permissions.

### How access is calculated

Plan access is additive. Tability checks all matching permissions and uses the strongest one.

Access can come from:

* **Everyone in the workspace**
* **Team permissions**
* **Individual person permissions**
* **Workspace owner/admin access**

The strongest permission wins:

* `Edit` beats `View`
* `View` beats `None`

For example:

* If Everyone has **View**, but a person has **Edit**, that person can edit.
* If Everyone has **None**, but a team has **View**, everyone in that team can view.
* If a person has **View**, but one of their teams has **Edit**, they can edit.
* Removing someone from a team removes the access they had through that team, unless they still have access another way.

### Everyone in this workspace

The **Everyone in this workspace** setting controls the default access for workspace members.

Use this when most people should have the same level of access.

Options:

* **Can edit**: everyone in the workspace can edit the plan.
* **Can view**: everyone in the workspace can view the plan.
* **No access**: only explicitly added teams or people can access the plan.

### Team permissions

Team permissions let you give plan access to a whole team at once.

When you add a team to a plan:

* All current team members get that permission.
* Future members added to the team also get that permission.
* Members removed from the team lose that team-based access.
* Team permissions are separate from simply linking a team to a plan for ownership or reporting.

This is the best option when access should follow an existing group, such as “Leadership”, “Marketing”, or “Product”.

### People permissions

People permissions let you grant access to individual workspace members.

Use this when only a specific person needs access, or when someone needs stronger access than the rest of their team.

For example, you can give a team **View** access, then give one person on that team **Edit** access.

### Avoiding lockouts

When you restrict Everyone in the workspace to **View** or **No access**, Tability checks that there is still at least one explicit editor.

Explicit editors can come from:

* A person with **Edit** access
* A team with **Edit** access

If you are about to remove your own edit access, or reduce access in a way that could lock you out, Tability will show a confirmation.

### Missing permissions warning

Some plans include assigned owners, contributors, or reviewers. If a plan is restricted and one of those people does not have access, Tability may show a missing permissions warning.

A person is considered covered if they have access through either:

* An individual permission
* A team permission from a team they belong to

### Recommended setup

For open plans:

1. Set **Everyone in this workspace** to **Can view** or **Can edit**.
2. Add individual or team **Edit** permissions only where needed.

For restricted plans:

1. Set **Everyone in this workspace** to **No access**.
2. Add the relevant teams with **View** or **Edit**.
3. Add individual people only for exceptions.
4. Make sure at least one team or person has **Edit** access.
