Roles & Permissions
In NocoDB, roles set what users or teams can do at three levels: Organization, Workspace and Base. Roles control access. They make sure that members and teams have the correct privileges for their responsibilities.
NocoDB uses this hierarchy:
Organization (Enterprise only)
└── Workspace
└── BaseOrganization-level roles control who can manage the org, its members and org-wide teams. Workspace and base roles control what users can do with data and collaboration features. These two layers are independent. The org role of a user does not change their workspace or base permissions. Their workspace or base roles do not change their org role.
Organization-level Roles
An Organization is at the top of the NocoDB hierarchy. It puts one or more Workspaces into one administrative unit. On Cloud, NocoDB creates an organization automatically when you upgrade a workspace to the Enterprise plan. On On-premise Enterprise, NocoDB automatically creates one default organization for the instance.
All users in an organization are Org Members. Each org member has one of three roles:
Org Viewer
- Can access the workspaces and bases that they are invited to.
- Cannot create new workspaces.
- Cannot manage org-level settings, members or teams.
Org Creator
- Has the same access as an Org Viewer. Can also create new workspaces in the organization.
- Cannot manage org membership. Only the Org Admin can invite users to the organization or remove them.
Org Admin
- Has full access to the organization, including all workspaces and bases.
- Can do these tasks:
- Manage org members (invite, remove, change roles).
- Configure SSO and SCIM.
- Manage domains.
- Manage billing.
- Update org settings (name, logo).
- Create and manage org-level teams.
- Has access to the Admin Panel.
Removing an Org Member
When you remove a member from the organization, NocoDB also removes the user from all workspaces, bases and teams in that organization. Only the Org Admin can remove members from the organization.
Workspace & Base Roles
You can give these roles at the workspace or base level:
- Owner
- Creator
- Editor
- Commenter
- Viewer
- No Access
There is also a special role, "Inherit". Refer to the section below.
A base role has priority over the workspace role. Roles are hierarchical: a higher role has all the permissions of the roles below it. This makes it flexible and clear to manage access across your workspace and bases. The sections below give the details of each role and its permissions.
Role Assignment
Roles set access privileges in NocoDB. You can give roles at two levels: Workspace and Base.
When you invite a member or team to a workspace with a role (for example, Editor), they get that level of access in all bases of the workspace. A base role can override this. Base owners or creators can change permissions at the base level for specific collaboration needs.
These two levels give detailed control. You get the same access across the workspace, and you can change it for each base.
Workspace roles do not automatically give access to Private Bases. A member must be explicitly invited to a Private Base to get access. Their workspace role does not change this. For more information, refer to the Private Bases documentation.
The sections below give the details of each role and its permissions.
Owner
- NocoDB gives this role automatically to the person who creates a workspace or base. A workspace or base has exactly one Owner.
- Has full administrative privileges. This includes deleting the workspace or base, and managing billing (at the workspace level).
- Has full control of the schema (tables, fields, relationships) and all records.
- Has full control of all views: collaborative views, locked views, their own personal views and the personal views of other users. Can lock or unlock any view, and can make any view the personal view of another user. Can manage view folders in the sidebar.
- Has full toolbar access (Filter, Sort, Group By, field visibility, row color and others). NocoDB saves the changes on any view.
- Can manage members, teams, automations, webhooks and integrations.
- You can give the Owner role only to individual members. You cannot give this role to Teams.
Creator
- Has full control of the workspace or base, except deletion. Only the Owner can delete.
- Has full control of the schema (tables, fields, relationships) and all records.
- Has full control of all views: collaborative views, locked views, their own personal views and the personal views of other users. Can lock or unlock any view, and can make any view the personal view of another user. Can manage view folders in the sidebar.
- Has full toolbar access. NocoDB saves the changes on any view.
- Can manage members (with the same role or a lower role), teams, automations, webhooks and integrations.
- Good for administrators and key project leads.
Editor
- Can add, edit and delete records in tables.
- Cannot change the schema. Creators or Owners manage tables, fields and relationships.
- Has full toolbar access (Filter, Sort, Group By, field visibility, row color and others). NocoDB saves the changes on any view that the editor can write to.
- Can create, rename, duplicate and delete views. This applies to collaborative views and to their own personal views. Can change any collaborative view into a personal view that they own. Can change their own personal view back to collaborative.
- Cannot do these tasks. On these views, the toolbar and menus are read-only.
- Change or delete locked views.
- Set the mode of a view to Locked.
- Change or delete the personal views of other users.
- Make a view the personal view of another user.
- Cannot create, rename, recolor, reorder or delete view folders in the sidebar. Editors can still move views between existing folders.
- Good for contributors who manage data every day.
Commenter
- Can read records and their linked data. Cannot create, edit or delete records.
- Can see and add comments on existing records.
- Cannot change the schema, create or change views, or change the view configuration.
- No toolbar access. Filter, Sort and Group By are not available.
- Good for reviewers, or for collaborators who give feedback.
Viewer
- Has read-only access to records, fields and comments.
- Cannot create, edit or delete records. Cannot add comments.
- Cannot change the schema, create or change views, or change the view configuration.
- No toolbar access. Filter, Sort and Group By are not available.
- Good for external stakeholders who must only see data.
No Access
- Removes all access to a workspace or base.
- At the workspace level, the user or team cannot access the bases in the workspace.
- At the base level, the user or team cannot access that base only.
Inherit
"Inherit" is a special role. With it, users get their permissions from their team assignments in a workspace. It works like this:
| Level | What Inherit does |
|---|---|
| Workspace | The user gets their role from their team assignments in the workspace. |
| Base | The user gets the role set at the workspace level. |
- Inherit makes it more flexible to manage roles across many bases in a workspace.
- Note: You cannot give the Inherit role directly at the workspace level.
| Workspace role of the user | Team role | Access in all bases of the workspace |
|---|---|---|
| Inherit | Viewer | Viewer |
| No Access | Editor | No Access |
Inherit is the only explicit role that lets a user get a role from team assignments. For all other roles, the explicit workspace role has priority over the team role.
If a user has the Inherit role in a base, their workspace role or team role sets their effective role. The effective role resolution rules below apply.
Effective Role Resolution
NocoDB finds the effective permissions of a user in a base from explicit (individual) assignments and team assignments. It uses this order of precedence:
- Explicit individual role at Base (highest precedence)
- Best (most permissive) role among Team roles assigned at Base
- Explicit individual role at Workspace level other than "Inherit"
- Best (most permissive) role among Team roles assigned at Workspace
- No-access (default)
Notes
- An explicit individual assignment always overrides a team role at the same level.
- If an explicit assignment exists at the lower level (Base), it overrides the higher level (Workspace).
- When more than one team role applies, NocoDB uses the most permissive role. For example, between Viewer and Editor, it uses Editor.
Base hierarchy:
Individual Base role > Team Base role > Individual Workspace role > Team Workspace role > No Access
Workspace hierarchy:
Individual Workspace role > Team Workspace role > No Access
When a user is in more than one team, their Team role is the highest (most permissive) role of all their team assignments.
Roles for Teams
A team gives access to a group of users, which makes access easier to manage. When you give a team a workspace or base role:
- All team members get that role automatically.
- An explicit individual role overrides the team role.
- You can invite a team at the workspace level and at the base level, for wider or more limited access.
- You cannot give a team the Owner role.
- You cannot give a team the Inherit role at the workspace level.
For more information about Teams and collaboration, refer to:
Workspace level permissions
The person who creates the workspace automatically becomes the Workspace owner. A workspace can have only one Owner. Members get access to the bases in a workspace from their workspace roles. When a member joins a workspace, their workspace role applies automatically to all bases in that workspace. A base role can override this.
| Task | Owner | Creator | Editor | Commenter | Viewer |
|---|---|---|---|---|---|
| Invite member to workspace (*1) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Create workspace invite link (*1) | ✔️ | ✔️ | ✔️ | ||
| Manage member access to workspace (*2) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Remove member access from workspace (*3) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| View members in workspace | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Create a new base | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Access existing bases at assigned roles | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Delete Workspace | ✔️ | ️ | |||
| Billing & upgrade options | ✔️ | ️ |
(*1) Members can invite others with the same role or a lower role.
(*2) Members can manage access for others with the same role or a lower role.
(*3) Members can remove others with the same role or a lower role.
Base level permissions
Collaboration
| Task | Owner | Creator | Editor | Commenter | Viewer |
|---|---|---|---|---|---|
| Invite member to base (*1) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Create base invite link (*1) | ✔️ | ✔️ | ✔️ | ||
| Manage member access to base (*2) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Remove member access from base (*3) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| View members in a base | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Share base | ✔️ | ✔️ | |||
| Share view | ✔️ | ✔️ |
(*1) Members can invite others with the same role or a lower role.
(*2) Members can manage access for others with the same role or a lower role.
(*3) Members can remove others with the same role or a lower role.
Table & view operations
| Task | Owner | Creator | Editor | Commenter | Viewer |
|---|---|---|---|---|---|
| Add / modify / delete table | ✔️ | ✔️ | |||
| Add / modify / delete fields | ✔️ | ✔️ | |||
| Add / modify / delete views (*1) | ✔️ | ✔️ | ✔️ | ||
| Lock / unlock a view | ✔️ | ✔️ | |||
| Assign a view as another user's personal view | ✔️ | ✔️ | |||
| Add / modify / delete view folders | ✔️ | ✔️ | |||
| Hide / un-hide / reorder fields | ✔️ | ✔️ | ✔️ | ️ | ️ |
| Add / modify / delete sort | ✔️ | ✔️ | ✔️ | ️ | ️ |
| Add / modify / delete filters | ✔️ | ✔️ | ✔️ | ️ | ️ |
| Add / modify / delete group-by | ✔️ | ✔️ | ✔️ | ️ | ️ |
| Add / modify / delete row colour | ✔️ | ✔️ | ✔️ | ️ | ️ |
| Add / modify / delete cell colour | ✔️ | ✔️ | ✔️ | ️ | ️ |
(*1) Editors have full CRUD on collaborative views and on their own personal views. They can change any collaborative view into a personal view that they own. Editors cannot change or delete locked views. They cannot set the mode of a view to Locked. They cannot change or delete the personal views of other users. Editors can still move any view between existing sections in the sidebar. Creators and owners keep all these abilities.
Record operations
| Task | Owner | Creator | Editor | Commenter | Viewer |
|---|---|---|---|---|---|
| Add / modify / delete record | ✔️ | ✔️ | ✔️ | ||
| View & add comment on a record | ✔️ | ✔️ | ✔️ | ✔️ | |
| View record | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| Manage record-level security | ✔️ | ✔️ |
Automations & advanced
| Task | Owner | Creator | Editor | Commenter | Viewer |
|---|---|---|---|---|---|
| Add / modify / delete Webhook | ✔️ | ✔️ | |||
| ERD (Project & Table relations) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| API Snippet | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
| API Token | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ |
Availability
- Teams are available on NocoDB Cloud (Business plan and above) and licensed self-hosted deployments (Scale plan and above).
Last updated on