Roles & Permissions
Lithora has four membership roles. Three of them can write and cost a seat; the fourth — Guest — is read-only and free.
The four roles
Owner
Billable seatWorkspace scope
Full control, including billing and ownership transfer. Exactly one per workspace, and the person the seat invoice is charged to.
Admin
Billable seatTeam scope
Manages members, projects, integrations and team settings. Can publish and revoke public share links and permanently purge trashed items. Cannot access billing or transfer ownership.
Member
Billable seatTeam scope
The everyday role. Creates and edits work items, projects, docs and whiteboards, and can restore items from the Trash.
Guest
FreeTeam scope
Read-only stakeholder — a client, an exec, a contractor. Can read what is shared with them and nothing else. Never consumes a billable seat.
Permission matrix
| Action | Owner | Admin | Member | Guest |
|---|---|---|---|---|
| View projects, work items and docs | Yes | Yes | Yes | Yes |
| Create or edit work items | Yes | Yes | Yes | No |
| Create or edit projects | Yes | Yes | Yes | No |
| Delete to Trash | Yes | Yes | Yes | No |
| Restore from Trash | Yes | Yes | Yes | No |
| Permanently purge a trashed item | Yes | Yes | Own items only | No |
| Invite members and guests | Yes | Yes | No | No |
| Publish or revoke a public share link | Yes | Yes | Projects they created | No |
| Manage integrations and automations | Yes | Yes | No | No |
| Turn domain discovery on or off | Yes | Yes | No | No |
| Manage billing and seats | Yes | No | No | No |
| Consumes a billable seat | Yes | Yes | Yes | No |
The Guest role in detail
A guest is a full account with a login, scoped to the work you share with them — but with every write path closed.
- Read-only, enforced server-side. Creating, editing and deleting are refused by the API, not just hidden in the interface. A guest cannot comment their way around it or drive a write through the AI agent.
- Never billable. Guests are excluded from the seat count that builds your invoice, regardless of how active they are.
- Capped per plan. 5 free guests per team on Pro, 25 per team on Scale. The cap keeps the role an expansion lever rather than a way to avoid paying for people who actually do the work.
- No Trash access. Because restore and purge are write operations, the Trash is closed to guests entirely.
- Promotable. If a guest starts doing real work, change their role to Member in Team Settings › Members. That converts them into a billable seat at the next seat realignment.
Guest or public link?
Assigning and changing roles
- Open Team Settings › Members.
- Click Invite Member and enter the email address.
- Choose the role on the invite — Admin, Member or Guest. The role is applied when the invitation is accepted.
- To change an existing person's role, use the role dropdown next to their name in the same list.
Roles are scoped to a team, so the same person can be an Admin in Engineering and a Guest in Marketing. For invites, domain discovery and join requests, see Creating & Managing Teams.