Skip to content

Roles & Permissions

Lithora has four membership roles. Three of them can write and cost a seat; the fourth — Guest — is read-only and free.

The four roles

Owner

Billable seat

Workspace scope

Full control, including billing and ownership transfer. Exactly one per workspace, and the person the seat invoice is charged to.

Admin

Billable seat

Team scope

Manages members, projects, integrations and team settings. Can publish and revoke public share links and permanently purge trashed items. Cannot access billing or transfer ownership.

Member

Billable seat

Team scope

The everyday role. Creates and edits work items, projects, docs and whiteboards, and can restore items from the Trash.

Guest

Free

Team scope

Read-only stakeholder — a client, an exec, a contractor. Can read what is shared with them and nothing else. Never consumes a billable seat.

Permission matrix

What each Lithora role is permitted to do
ActionOwnerAdminMemberGuest
View projects, work items and docsYesYesYesYes
Create or edit work itemsYesYesYesNo
Create or edit projectsYesYesYesNo
Delete to TrashYesYesYesNo
Restore from TrashYesYesYesNo
Permanently purge a trashed itemYesYesOwn items onlyNo
Invite members and guestsYesYesNoNo
Publish or revoke a public share linkYesYesProjects they createdNo
Manage integrations and automationsYesYesNoNo
Turn domain discovery on or offYesYesNoNo
Manage billing and seatsYesNoNoNo
Consumes a billable seatYesYesYesNo

The Guest role in detail

A guest is a full account with a login, scoped to the work you share with them — but with every write path closed.

  • Read-only, enforced server-side. Creating, editing and deleting are refused by the API, not just hidden in the interface. A guest cannot comment their way around it or drive a write through the AI agent.
  • Never billable. Guests are excluded from the seat count that builds your invoice, regardless of how active they are.
  • Capped per plan. 5 free guests per team on Pro, 25 per team on Scale. The cap keeps the role an expansion lever rather than a way to avoid paying for people who actually do the work.
  • No Trash access. Because restore and purge are write operations, the Trash is closed to guests entirely.
  • Promotable. If a guest starts doing real work, change their role to Member in Team Settings › Members. That converts them into a billable seat at the next seat realignment.

Guest or public link?

Invite a Guest when the person needs an account, a login, and continuing access. Use a public share link when they just need to look at one project without signing up at all.

Assigning and changing roles

  1. Open Team Settings › Members.
  2. Click Invite Member and enter the email address.
  3. Choose the role on the invite — Admin, Member or Guest. The role is applied when the invitation is accepted.
  4. To change an existing person's role, use the role dropdown next to their name in the same list.

Roles are scoped to a team, so the same person can be an Admin in Engineering and a Guest in Marketing. For invites, domain discovery and join requests, see Creating & Managing Teams.