Roles and Permissions That Let You Invite Everyone Safely
Unlimited users is only useful if you can control what they see. Give clients, contractors, and stakeholders access to exactly their part and nothing else.
Free forever plan · No credit card required · Set up in minutes
What is user role management?
User role management decides what each person can see and do. A role groups a set of permissions, and people are given a role rather than permissions one by one, which is what keeps access manageable as a team grows. In Orangescrum a permission is a single action inside a module, roles are built from those actions, and the same person can hold a different role in every project.
Why access control becomes a problem
Control at the level you need it
01Roles
Five to start with
Owner, admin, user, client, and guest ship configured, so access works before anybody sets anything up.
As many of your own as you need
Create custom roles with their own names, short codes, and permission sets.
Put them in groups
Organise your custom roles into named role groups instead of one long list.
Rename and regroup
Change a role's name, its modules, its group, and the people on it, all from one screen.
Delete safely
Deleting a custom role clears it from everyone who had it, and the five built in roles cannot be deleted at all.
Assign in bulk
Pick a role and move a list of people onto it in one action, with the seat count checked as you go.
02Permissions
Over 160 of them
Every action is its own permission, from creating a task to seeing a project's budget, across two dozen modules.
A grid you can read
Roles across the top and modules down the side, with each permission marked as view, manage, or delete.
A whole module at once
Tick every permission in a module for a role, or switch the module off for that role entirely.
Mine against everyone's
Viewing, editing, deleting, and archiving each split into your own work and all work, so a contributor is not an administrator.
Hide the commercials
Customer name, budget, default rate, tolerances, and cost approval are each a separate right on a project.
Nothing is allowed by default
A permission that has not been granted is denied, so a new role starts closed rather than open.
Hand over the settings too
Twenty-five separate rights cover who may manage labels, task types, custom fields, workflows, cost settings, and roles themselves. Available in Cloud.
03Scope
A different role per project
The same person can run one project, contribute to another, and never see a third.
Set it from either end
Assign roles to everyone on a project, or set one person's role across all their projects.
It applies as you move
Permissions are worked out for the project you are in, falling back to your company role where a project has no override.
04Groups
Teams
Group people into teams with their own members, and report on what a team is carrying.
Business units
Model departments and divisions as business units, and filter people and work by them.
Attach one to a project
Attach a team, a role group, or a business unit to a project and everyone in it gets access with the right role. Available in Self-Hosted.
A clear order of precedence
Direct membership beats a team, which beats a role group, which beats a business unit, so inherited access is never ambiguous. Available in Self-Hosted.
05People
Invite one or many
Invite a person with their role, projects, and teams set, or invite a whole batch at once with the seat limit checked for the batch.
Resend and accept
Send an invitation again if it was missed, and people join by accepting it themselves.
Turn access on and off
Activate, deactivate, or delete a member, and grant or revoke admin without editing a role.
Reset a password for someone
An administrator can reset another person's password when they are locked out. Available in Self-Hosted and the Community Edition.
Hand over ownership
The owner can transfer ownership of the workspace to somebody else. Available in Cloud.
Get the list out
Export your user list to CSV for a review or an audit. Available in Self-Hosted and the Community Edition.
06Outside
A client role
Clients are marked as clients and get a role built for people who should see progress and not internal detail.
A guest role with its own set
Guest access is off until you turn it on, and guests get their own permission set kept separately from everyone else's.
Guests stay a minority
Guests can take at most half of your plan's user allowance, so the workspace does not quietly fill with them.
Unlimited users
No per seat cost, so access decisions are about security rather than budget.
07Sign in
SAML single sign-on
Sign in through the SAML identity provider you already run, with your own metadata endpoint for registering Orangescrum.
Map their groups to your roles
Turn an identity provider group into an Orangescrum role automatically, with a default role for anyone unmatched. Available in Self-Hosted.
LDAP and Active Directory
Authenticate against your directory, switch a person between directory and normal login, and create their account on first sign in.
Google
Sign in with a Google account, including one tap. Available in Cloud.
Orangescrum as the provider
Other applications can sign in with Orangescrum over OpenID Connect, with discovery, key, token, and userinfo endpoints. Available in Self-Hosted.
Two factor authentication
Turn on a second factor for the workspace, with a one time code by email and exemptions you set by role.
A password policy
Require a password change on a schedule and stop people reusing recent passwords.
Security questions
A question bank and per person answers, used for recovery and verification.
08Records
One audit log
Work item, activity, authentication, and security events in one filterable log, exportable to CSV. Available in Self-Hosted.
Retention you set
Define how long data is kept, preview what a policy would remove, then run it. Available in Self-Hosted.
Sign in attempts are throttled
Repeated failed sign ins are slowed down rather than allowed to run freely. Available in Cloud.
How to set access up
For teams with people outside the team
Which edition includes what
| Capability | CloudManaged SaaS | Self-HostedOn-premise / private cloud | Open SourceCommunity Edition |
|---|---|---|---|
| Five built in roles and custom roles | ✓ | ✓ | ✓ |
| Permission grid across every module | ✓ | ✓ | ✓ |
| Per project roles | ✓ | ✓ | ✓ |
| Two factor authentication and password policy | ✓ | ✓ | ✓ |
| Teams and business units | Pro | ✓ | ✗ |
| Access inherited from a team or unit | ✗ | ✓ | ✗ |
| Client and guest access | ✓ | ✓ | ✗ |
| Settings administration permissions | ✓ | ✗ | ✗ |
| SAML 2.0 single sign-on | Premium | ✓ | ✗ |
| Identity provider group to role mapping | ✗ | ✓ | ✗ |
| LDAP and Active Directory | ✓ | ✓ | ✗ |
| OAuth identity provider for other apps | ✗ | ✓ | ✗ |
| Audit log and data retention policies | ✗ | ✓ | ✗ |
| Transition permissions on workflow | ✗ | ✓ | ✗ |
User roles and permissions FAQ
Can I control what each person sees?
Yes, in detail. Every action is its own permission, there are over one hundred and sixty of them across two dozen modules, and they are granted on a role rather than person by person. Anything not granted is denied.
What roles come with it?
Owner, admin, user, client, and guest are built in and cannot be deleted. On top of those you can create as many custom roles as you need and organise them into named role groups.
Can somebody have a different role on different projects?
Yes, and this is the part most teams need. A project role overrides the company role, so the same person can lead one project, contribute to another, and have no visibility of a third. You can set it from the project or from the person.
Can I give a client access without showing them everything?
Yes. There is a dedicated client role, and permissions such as customer name, budget, default rate, and cost approval are each separate, so a client sees progress on their own project without the commercial detail.
What about guests?
Guest access is switched off until you enable it. Guests get their own permission set, stored separately from the other roles, and they can take up at most half of your plan's user allowance.
Can access come from a team rather than a person?
In the Self-Hosted edition, yes. Attach a team, a role group, or a business unit to a project and everyone in it gets access with that group's role, with direct membership taking precedence over a team, then a role group, then a business unit.
Does adding more users cost more?
No. Every plan includes unlimited users, so who gets access is a security decision rather than a budget one. That is the point of pairing unlimited users with real permissions.
Is two factor authentication available?
Yes, in every edition including the free Community Edition. You turn it on for the workspace, exempt roles that do not need it, and pair it with a password policy that forces a change on a schedule and blocks reuse.
Do you support SSO or LDAP?
Yes to both, and both are in Cloud and Self-Hosted. SAML 2.0 single sign-on lets people arrive through the identity provider you already run, and LDAP and Active Directory sign in authenticates against your directory. Self-Hosted also maps identity provider groups onto Orangescrum roles, and can act as an OpenID Connect provider for your other applications.
Are roles in the open source edition?
Yes. The permission grid, custom roles, per project roles, and two factor authentication are all in the Community Edition. Client and guest access, teams and business units, SSO, and LDAP are not.
Can I see who did what?
In the Self-Hosted edition there is a single audit log covering work item, activity, authentication, and security events, which you can filter and export to CSV, along with retention policies that control how long that data is kept.
Can I stop people moving work to a status they should not?
Yes, in the Self-Hosted edition. Transition permissions on the workflow designer control who is allowed to make each status change, so sign off stays with the right people.
Invite everyone, show them only their part
Role based permissions are in every edition, including the free Community Edition.