---
title: "User Role Management and Permissions | Orangescrum"
description: "Decide who can see and change what: over 160 permissions, roles that change per project, client and guest access, 2FA, SAML SSO, and LDAP."
canonical: https://www.orangescrum.com/user-role-management
---

# User Role Management and Permissions | Orangescrum

> For the complete documentation index, see [llms.txt](https://www.orangescrum.com/llms.txt).

[Home](/) / [Features](/features) / User Roles

User roles and permissions

# Roles and Permissions That Let You _Invite Everyone Safely_

Unlimited users is only useful if you can control what they see. Give clients, contractors, and stakeholders access to exactly their part and nothing else.

Available in[Cloud](/pricing "Cloud - included")[Self-Hosted](/self-hosted "Self-Hosted - included")[Open Source](/open-source/free-download "Open Source - included")

[Start Free Trial →](/sign-up?utm_source=website&utm_medium=feature&utm_content=user-role-management)[Book a Demo](https://calendly.com/orangescrum)

Free forever plan · No credit card required · Set up in minutes

## What is user role management?

User role management decides what each person can see and do. A role groups a set of permissions, and people are given a role rather than permissions one by one, which is what keeps access manageable as a team grows. In Orangescrum a permission is a single action inside a module, roles are built from those actions, and the same person can hold a different role in every project.

The problem

## Why access control _becomes a problem_

Sharing means over sharing

The only way to show a contractor one project is to give them the workspace.

✓ Access scoped to the projects they are on.

Per seat pricing forces bad choices

People are left out to save money, so they work outside the tool.

✓ Unlimited users, controlled by role.

Leavers keep access

Nobody is sure what someone could reach, so nobody cleans up.

✓ Roles make access obvious and removable.

What you get

## Control _at the level you need it_

Grouped the way access is actually managed: the roles, the permissions inside them, where they apply, how groups inherit them, the people, the outsiders, how everyone signs in, and what gets recorded.

01Roles

-   ### Five to start with
    
    Owner, admin, user, client, and guest ship configured, so access works before anybody sets anything up.
    
-   ### As many of your own as you need
    
    Create custom roles with their own names, short codes, and permission sets.
    
-   ### Put them in groups
    
    Organise your custom roles into named role groups instead of one long list.
    
-   ### Rename and regroup
    
    Change a role's name, its modules, its group, and the people on it, all from one screen.
    
-   ### Delete safely
    
    Deleting a custom role clears it from everyone who had it, and the five built in roles cannot be deleted at all.
    
-   ### Assign in bulk
    
    Pick a role and move a list of people onto it in one action, with the seat count checked as you go.
    

02Permissions

-   ### Over 160 of them
    
    Every action is its own permission, from creating a task to seeing a project's budget, across two dozen modules.
    
-   ### A grid you can read
    
    Roles across the top and modules down the side, with each permission marked as view, manage, or delete.
    
-   ### A whole module at once
    
    Tick every permission in a module for a role, or switch the module off for that role entirely.
    
-   ### Mine against everyone's
    
    Viewing, editing, deleting, and archiving each split into your own work and all work, so a contributor is not an administrator.
    
-   ### Hide the commercials
    
    Customer name, budget, default rate, tolerances, and cost approval are each a separate right on a project.
    
-   ### Nothing is allowed by default
    
    A permission that has not been granted is denied, so a new role starts closed rather than open.
    
-   ### Hand over the settings too
    
    Twenty-five separate rights cover who may manage labels, task types, custom fields, workflows, cost settings, and roles themselves. Available in Cloud.
    

03Scope

-   ### A different role per project
    
    The same person can run one project, contribute to another, and never see a third.
    
-   ### Set it from either end
    
    Assign roles to everyone on a project, or set one person's role across all their projects.
    
-   ### It applies as you move
    
    Permissions are worked out for the project you are in, falling back to your company role where a project has no override.
    

04Groups

-   ### Teams
    
    Group people into teams with their own members, and report on what a team is carrying.
    
-   ### Business units
    
    Model departments and divisions as business units, and filter people and work by them.
    
-   ### Attach one to a project
    
    Attach a team, a role group, or a business unit to a project and everyone in it gets access with the right role. Available in Self-Hosted.
    
-   ### A clear order of precedence
    
    Direct membership beats a team, which beats a role group, which beats a business unit, so inherited access is never ambiguous. Available in Self-Hosted.
    

05People

-   ### Invite one or many
    
    Invite a person with their role, projects, and teams set, or invite a whole batch at once with the seat limit checked for the batch.
    
-   ### Resend and accept
    
    Send an invitation again if it was missed, and people join by accepting it themselves.
    
-   ### Turn access on and off
    
    Activate, deactivate, or delete a member, and grant or revoke admin without editing a role.
    
-   ### Reset a password for someone
    
    An administrator can reset another person's password when they are locked out. Available in Self-Hosted and the Community Edition.
    
-   ### Hand over ownership
    
    The owner can transfer ownership of the workspace to somebody else. Available in Cloud.
    
-   ### Get the list out
    
    Export your user list to CSV for a review or an audit. Available in Self-Hosted and the Community Edition.
    

06Outside

-   ### A client role
    
    Clients are marked as clients and get a role built for people who should see progress and not internal detail.
    
-   ### A guest role with its own set
    
    Guest access is off until you turn it on, and guests get their own permission set kept separately from everyone else's.
    
-   ### Guests stay a minority
    
    Guests can take at most half of your plan's user allowance, so the workspace does not quietly fill with them.
    
-   ### Unlimited users
    
    No per seat cost, so access decisions are about security rather than budget.
    

07Sign in

-   ### SAML single sign-on
    
    Sign in through the SAML identity provider you already run, with your own metadata endpoint for registering Orangescrum.
    
-   ### Map their groups to your roles
    
    Turn an identity provider group into an Orangescrum role automatically, with a default role for anyone unmatched. Available in Self-Hosted.
    
-   ### LDAP and Active Directory
    
    Authenticate against your directory, switch a person between directory and normal login, and create their account on first sign in.
    
-   ### Google
    
    Sign in with a Google account, including one tap. Available in Cloud.
    
-   ### Orangescrum as the provider
    
    Other applications can sign in with Orangescrum over OpenID Connect, with discovery, key, token, and userinfo endpoints. Available in Self-Hosted.
    
-   ### Two factor authentication
    
    Turn on a second factor for the workspace, with a one time code by email and exemptions you set by role.
    
-   ### A password policy
    
    Require a password change on a schedule and stop people reusing recent passwords.
    
-   ### Security questions
    
    A question bank and per person answers, used for recovery and verification.
    

08Records

-   ### One audit log
    
    Work item, activity, authentication, and security events in one filterable log, exportable to CSV. Available in Self-Hosted.
    
-   ### Retention you set
    
    Define how long data is kept, preview what a policy would remove, then run it. Available in Self-Hosted.
    
-   ### Sign in attempts are throttled
    
    Repeated failed sign ins are slowed down rather than allowed to run freely. Available in Cloud.
    

How it works

## How to _set access up_

1

Decide the roles

Start from owner, admin, user, and client, and add your own where those do not fit.

2

Set what each can do

Work through the permission grid once, module by module, on the role rather than the person.

3

Add people to projects

Give each person a role on the projects they belong to, overriding their company role where needed.

4

Review it

Because access follows roles, checking who can reach what is a quick job rather than an audit.

Who it's for

## For teams with _people outside the team_

Agencies

Clients in their own project, seeing only their work.

[Learn more →](/client-management-software)

Regulated organisations

Access control you can evidence, on your own servers.

[Learn more →](/self-hosted)

Enterprises

SSO and directory sign in, so access follows the joiner and leaver process.

[Learn more →](/self-hosted/plugins)

Availability

## Which edition includes _what_

Orangescrum runs as managed cloud, self-hosted on your own servers, or as the open-source Community Edition. Here is exactly what each one includes.

Roles and permissions are in every edition. SAML and LDAP sign in are in Cloud and Self-Hosted.

| Capability | CloudManaged SaaS | Self-HostedOn-premise / private cloud | Open SourceCommunity Edition |

| Five built in roles and custom roles | ✓ | ✓ | ✓ |
| Permission grid across every module | ✓ | ✓ | ✓ |
| Per project roles | ✓ | ✓ | ✓ |
| Two factor authentication and password policy | ✓ | ✓ | ✓ |
| Teams and business units | Pro | ✓ | ✗ |
| Access inherited from a team or unit | ✗ | ✓ | ✗ |
| Client and guest access | ✓ | ✓ | ✗ |
| Settings administration permissions | ✓ | ✗ | ✗ |
| SAML 2.0 single sign-on | Premium | ✓ | ✗ |
| Identity provider group to role mapping | ✗ | ✓ | ✗ |
| LDAP and Active Directory | ✓ | ✓ | ✗ |
| OAuth identity provider for other apps | ✗ | ✓ | ✗ |
| Audit log and data retention policies | ✗ | ✓ | ✗ |
| Transition permissions on workflow | ✗ | ✓ | ✗ |

Frequently asked questions

## User roles and permissions _FAQ_

### Can I control what each person sees?

Yes, in detail. Every action is its own permission, there are over one hundred and sixty of them across two dozen modules, and they are granted on a role rather than person by person. Anything not granted is denied.

### What roles come with it?

Owner, admin, user, client, and guest are built in and cannot be deleted. On top of those you can create as many custom roles as you need and organise them into named role groups.

### Can somebody have a different role on different projects?

Yes, and this is the part most teams need. A project role overrides the company role, so the same person can lead one project, contribute to another, and have no visibility of a third. You can set it from the project or from the person.

### Can I give a client access without showing them everything?

Yes. There is a dedicated client role, and permissions such as customer name, budget, default rate, and cost approval are each separate, so a client sees progress on their own project without the commercial detail.

### What about guests?

Guest access is switched off until you enable it. Guests get their own permission set, stored separately from the other roles, and they can take up at most half of your plan's user allowance.

### Can access come from a team rather than a person?

In the Self-Hosted edition, yes. Attach a team, a role group, or a business unit to a project and everyone in it gets access with that group's role, with direct membership taking precedence over a team, then a role group, then a business unit.

### Does adding more users cost more?

No. Every plan includes unlimited users, so who gets access is a security decision rather than a budget one. That is the point of pairing unlimited users with real permissions.

### Is two factor authentication available?

Yes, in every edition including the free Community Edition. You turn it on for the workspace, exempt roles that do not need it, and pair it with a password policy that forces a change on a schedule and blocks reuse.

### Do you support SSO or LDAP?

Yes to both, and both are in Cloud and Self-Hosted. SAML 2.0 single sign-on lets people arrive through the identity provider you already run, and LDAP and Active Directory sign in authenticates against your directory. Self-Hosted also maps identity provider groups onto Orangescrum roles, and can act as an OpenID Connect provider for your other applications.

### Are roles in the open source edition?

Yes. The permission grid, custom roles, per project roles, and two factor authentication are all in the Community Edition. Client and guest access, teams and business units, SSO, and LDAP are not.

### Can I see who did what?

In the Self-Hosted edition there is a single audit log covering work item, activity, authentication, and security events, which you can filter and export to CSV, along with retention policies that control how long that data is kept.

### Can I stop people moving work to a status they should not?

Yes, in the Self-Hosted edition. Transition permissions on the workflow designer control who is allowed to make each status change, so sign off stays with the right people.

## Invite everyone, show them only their part

Role based permissions are in every edition, including the free Community Edition.

[Start Free Trial →](/sign-up?utm_source=website&utm_medium=feature&utm_content=user-role-management_cta)[Book a Demo](https://calendly.com/orangescrum)

## Related capabilities

[Client managementClient access in practice](/client-management-software)[Single sign-onSAML, LDAP, and OIDC](/single-sign-on)[Custom status workflowWho can move what](/custom-status-workflow)[PricingUnlimited users on every plan](/pricing)
