---
title: "User Roles and Permissions"
description: "Every account in your organisation is an administrator, a member or a guest. See what each one may do, and how an administrator changes someone's role."
category: administration-security
section: users-and-access
tags: [permissions]
type: Reference
lastUpdated: 2026-08-06
locale: en
canonical: https://support.talkspirit.com/en/administration-security/user-roles
---

# User Roles and Permissions


## User Roles and Permissions

Every account in your organisation holds exactly one role: **Administrator**, **Member** or **Guest**. You can read it in the **Role** column of **Administration > Users**, and an organisation administrator changes it from that same screen. **Owner** is an extra status carried on top of Administrator, and **Suspended** is an account status rather than a role.

![The Users page in Administration, with the Role column showing Admin, Member and Owner badges](/images/administration-security/user-roles/01-administration-users-role-column.png)

## What each role may do

| Role | Badge in the list | What it gives |
| --- | --- | --- |
| **Administrator** | `Admin` | Full control of the organisation, including users, settings and billing |
| **Member** | `Member` | Reads everything shared with the organisation, and creates projects, meetings and goals |
| **Guest** | `Guest` | No organisation-wide access. A guest sees only what its access scope grants |

These badges are the ones the **Users** page in Administration shows. The **Members** app labels the same accounts differently: it shows only `Admin` or `User`, so a guest appears there as `User`. If you need to know whether someone is a guest, read the Role column in Administration rather than the one in Members.

Administrator is genuinely unrestricted: the permission engine grants an administrator every action on every resource type, at the highest priority of any rule in the product. A member gets a broad read of shared resources plus the right to create projects, meetings and goals. A guest is excluded from both of those grants, so nothing is visible to a guest by default.

There is no ranking of administrators. The account role has exactly these three values, so every administrator holds the same rights as every other one.

## Owner

The owner is the account responsible for the organisation and its subscription. Ownership sits on top of the Administrator role, so the list shows two badges, `Admin` and `Owner`, on the same row.

Only an owner can grant or revoke ownership, and an organisation can never be left without one. If an account is the last owner who can still sign in, the product refuses to demote it, suspend it, anonymise it or remove its owner status.

## A user role is not a Structure role

Talkspirit uses the word "role" for two unrelated things, and mixing them up is the most common source of confusion here.

- The **user role** on this page is an account level. It applies to the whole organisation and lives in **Administration > Users**.
- A **role** in the **Structure** app is a named piece of work inside a circle. The per-circle statuses **Circle Admin** and **Decision Maker** belong to that world and are set from the circle's Members tab.

Neither side implies the other. An organisation administrator is not automatically a circle admin or a decision maker, and a circle admin has no organisation-wide rights at all.

## Change someone's role

You need administrator rights.

1. Go to **Administration > Users**.
2. Find the person in the list and open the actions menu at the end of their row.
3. Choose **Set as Administrator**, **Set as Member** or **Set as Guest**.
4. Promoting someone to administrator asks you to confirm before it applies.

![The row actions menu on a member, offering Set as Administrator, Set as Guest, Suspend and Suspend and anonymize](/images/administration-security/user-roles/02-member-row-level-actions.png)

Four rules the screen enforces, so the menu you see depends on the row:

- **One step at a time.** The ladder is guest, then member, then administrator. A guest cannot become an administrator in a single move: set them as Member first, then as Administrator.
- **You cannot change your own role.** The role items are hidden on your own row, and the server refuses a self-demotion or a self-guesting even if the request reaches it.
- **Administrators cannot be suspended or anonymised from the interface.** On an administrator's row those items are absent, with a note explaining the prerequisite: set the person as Member first. This is an interface rule rather than a server one — the mutation itself refuses only three things: suspending yourself, an already-anonymised account, and the last operable owner.
- **Only an owner sees the ownership items.** An administrator who is not an owner cannot promote anyone to owner.

![The row actions menu on an administrator, offering only Set as Member with a note that administrators cannot be suspended or anonymised](/images/administration-security/user-roles/03-administrator-row-actions.png)

## Guests and their access scope

**Set as Guest** creates the most restricted kind of guest: no organisation-wide read, and no access to the organisation chart.

Wider guest access is chosen when the guest is invited, not afterwards. The invitation dialog offers an **Access scope** with three options: See the holarchy, access one group, or access more than one group. A guest given chart access can browse circles and roles but still gets no general read of the organisation.

If you need to widen an existing guest's access, the practical route is to set them as Member, or to invite them again with the scope you want.

## Suspended is a status, not a role

Suspending an account takes it offline without changing its role, and the Role column shows `Suspended` in place of the usual badge while it lasts. Restoring the account brings the previous role back.

## Delegated administration in classic Talkspirit

Groups, Newsfeed, Homepage, Library and the newsletter are still served by classic Talkspirit, which keeps its own delegated administrator roles: group administrator, user administrator, homepage administrator, newsletter administrator and library administrator. They are granted in the classic administration console, not in **Administration > Users**, and they are separate from the three account roles above.

## What's next

- [The user administrator role in Talkspirit](/en/administration-security/the-user-administrator)
- [Manage email invitations for new members](/en/administration-security/manage-email-invitations-for-new-members)
- [Editing, suspending, restoring or removing a member](/en/administration-security/how-to-edit-suspend-restore-or-delete-a-member-from-my-organization)
- [Who are Circle Admins?](/en/structure-governance/who-are-circle-admins)
- [What is a decision maker of a circle?](/en/structure-governance/what-is-a-decision-maker-of-a-circle)
