Roles & Permissions

In NocoDB, roles set what users or teams can do at three levels: Organization, Workspace and Base. Roles control access. They make sure that members and teams have the correct privileges for their responsibilities.

NocoDB uses this hierarchy:

Organization (Enterprise only)
└── Workspace
    └── Base

Organization-level roles control who can manage the org, its members and org-wide teams. Workspace and base roles control what users can do with data and collaboration features. These two layers are independent. The org role of a user does not change their workspace or base permissions. Their workspace or base roles do not change their org role.

Organization-level Roles

Organizations and organization-level roles are available on NocoDB Cloud (Enterprise plan) and the self-hosted Enterprise plan.

An Organization is at the top of the NocoDB hierarchy. It puts one or more Workspaces into one administrative unit. On Cloud, NocoDB creates an organization automatically when you upgrade a workspace to the Enterprise plan. On On-premise Enterprise, NocoDB automatically creates one default organization for the instance.

All users in an organization are Org Members. Each org member has one of three roles:

Org Viewer

  • Can access the workspaces and bases that they are invited to.
  • Cannot create new workspaces.
  • Cannot manage org-level settings, members or teams.

Org Creator

  • Has the same access as an Org Viewer. Can also create new workspaces in the organization.
  • Cannot manage org membership. Only the Org Admin can invite users to the organization or remove them.

Org Admin

  • Has full access to the organization, including all workspaces and bases.
  • Can do these tasks:
    • Manage org members (invite, remove, change roles).
    • Configure SSO and SCIM.
    • Manage domains.
    • Manage billing.
    • Update org settings (name, logo).
    • Create and manage org-level teams.
  • Has access to the Admin Panel.
Currently, each organization supports a single Org Admin — the user who creates the organization (or whose workspace is upgraded to Enterprise) is automatically assigned this role. Support for multiple Org Admins per organization is planned for a future release.
Org roles are separate from workspace and base roles. For example, a user can be an Org Viewer but a Workspace Creator — their org role does not restrict their workspace-level permissions.

Removing an Org Member

When you remove a member from the organization, NocoDB also removes the user from all workspaces, bases and teams in that organization. Only the Org Admin can remove members from the organization.

Workspace & Base Roles

You can give these roles at the workspace or base level:

  • Owner
  • Creator
  • Editor
  • Commenter
  • Viewer
  • No Access

There is also a special role, "Inherit". Refer to the section below.

A base role has priority over the workspace role. Roles are hierarchical: a higher role has all the permissions of the roles below it. This makes it flexible and clear to manage access across your workspace and bases. The sections below give the details of each role and its permissions.

Role Assignment

Roles set access privileges in NocoDB. You can give roles at two levels: Workspace and Base.

When you invite a member or team to a workspace with a role (for example, Editor), they get that level of access in all bases of the workspace. A base role can override this. Base owners or creators can change permissions at the base level for specific collaboration needs.

These two levels give detailed control. You get the same access across the workspace, and you can change it for each base.

Workspace roles do not automatically give access to Private Bases. A member must be explicitly invited to a Private Base to get access. Their workspace role does not change this. For more information, refer to the Private Bases documentation.

The sections below give the details of each role and its permissions.

Owner

  • NocoDB gives this role automatically to the person who creates a workspace or base. A workspace or base has exactly one Owner.
  • Has full administrative privileges. This includes deleting the workspace or base, and managing billing (at the workspace level).
  • Has full control of the schema (tables, fields, relationships) and all records.
  • Has full control of all views: collaborative views, locked views, their own personal views and the personal views of other users. Can lock or unlock any view, and can make any view the personal view of another user. Can manage view folders in the sidebar.
  • Has full toolbar access (Filter, Sort, Group By, field visibility, row color and others). NocoDB saves the changes on any view.
  • Can manage members, teams, automations, webhooks and integrations.
  • You can give the Owner role only to individual members. You cannot give this role to Teams.

Creator

  • Has full control of the workspace or base, except deletion. Only the Owner can delete.
  • Has full control of the schema (tables, fields, relationships) and all records.
  • Has full control of all views: collaborative views, locked views, their own personal views and the personal views of other users. Can lock or unlock any view, and can make any view the personal view of another user. Can manage view folders in the sidebar.
  • Has full toolbar access. NocoDB saves the changes on any view.
  • Can manage members (with the same role or a lower role), teams, automations, webhooks and integrations.
  • Good for administrators and key project leads.

Editor

  • Can add, edit and delete records in tables.
  • Cannot change the schema. Creators or Owners manage tables, fields and relationships.
  • Has full toolbar access (Filter, Sort, Group By, field visibility, row color and others). NocoDB saves the changes on any view that the editor can write to.
  • Can create, rename, duplicate and delete views. This applies to collaborative views and to their own personal views. Can change any collaborative view into a personal view that they own. Can change their own personal view back to collaborative.
  • Cannot do these tasks. On these views, the toolbar and menus are read-only.
    • Change or delete locked views.
    • Set the mode of a view to Locked.
    • Change or delete the personal views of other users.
    • Make a view the personal view of another user.
  • Cannot create, rename, recolor, reorder or delete view folders in the sidebar. Editors can still move views between existing folders.
  • Good for contributors who manage data every day.

Commenter

  • Can read records and their linked data. Cannot create, edit or delete records.
  • Can see and add comments on existing records.
  • Cannot change the schema, create or change views, or change the view configuration.
  • No toolbar access. Filter, Sort and Group By are not available.
  • Good for reviewers, or for collaborators who give feedback.

Viewer

  • Has read-only access to records, fields and comments.
  • Cannot create, edit or delete records. Cannot add comments.
  • Cannot change the schema, create or change views, or change the view configuration.
  • No toolbar access. Filter, Sort and Group By are not available.
  • Good for external stakeholders who must only see data.

No Access

  • Removes all access to a workspace or base.
  • At the workspace level, the user or team cannot access the bases in the workspace.
  • At the base level, the user or team cannot access that base only.

Inherit

"Inherit" is a special role. With it, users get their permissions from their team assignments in a workspace. It works like this:

LevelWhat Inherit does
WorkspaceThe user gets their role from their team assignments in the workspace.
BaseThe user gets the role set at the workspace level.
  • Inherit makes it more flexible to manage roles across many bases in a workspace.
  • Note: You cannot give the Inherit role directly at the workspace level.
Workspace role of the userTeam roleAccess in all bases of the workspace
InheritViewerViewer
No AccessEditorNo Access

Inherit is the only explicit role that lets a user get a role from team assignments. For all other roles, the explicit workspace role has priority over the team role.

If a user has the Inherit role in a base, their workspace role or team role sets their effective role. The effective role resolution rules below apply.

Effective Role Resolution

Organization-level roles do not participate in workspace or base role resolution. Org roles govern access to the Admin Panel and org-scoped operations only. Workspace and base access is resolved independently using the rules below.

NocoDB finds the effective permissions of a user in a base from explicit (individual) assignments and team assignments. It uses this order of precedence:

  1. Explicit individual role at Base (highest precedence)
  2. Best (most permissive) role among Team roles assigned at Base
  3. Explicit individual role at Workspace level other than "Inherit"
  4. Best (most permissive) role among Team roles assigned at Workspace
  5. No-access (default)

Notes

  • An explicit individual assignment always overrides a team role at the same level.
  • If an explicit assignment exists at the lower level (Base), it overrides the higher level (Workspace).
  • When more than one team role applies, NocoDB uses the most permissive role. For example, between Viewer and Editor, it uses Editor.

Base hierarchy:

Individual Base role > Team Base role > Individual Workspace role > Team Workspace role > No Access

Workspace hierarchy:

Individual Workspace role > Team Workspace role > No Access

When a user is in more than one team, their Team role is the highest (most permissive) role of all their team assignments.

Roles for Teams

A team gives access to a group of users, which makes access easier to manage. When you give a team a workspace or base role:

  • All team members get that role automatically.
  • An explicit individual role overrides the team role.
  • You can invite a team at the workspace level and at the base level, for wider or more limited access.
  • You cannot give a team the Owner role.
  • You cannot give a team the Inherit role at the workspace level.
If a team is invited at the workspace level, all its members receive that workspace role unless an individual or base-level role provides different access.

For more information about Teams and collaboration, refer to:

Workspace level permissions

The person who creates the workspace automatically becomes the Workspace owner. A workspace can have only one Owner. Members get access to the bases in a workspace from their workspace roles. When a member joins a workspace, their workspace role applies automatically to all bases in that workspace. A base role can override this.

TaskOwnerCreatorEditorCommenterViewer
Invite member to workspace (*1)✔️✔️✔️✔️✔️
Create workspace invite link (*1)✔️✔️✔️
Manage member access to workspace (*2)✔️✔️✔️✔️✔️
Remove member access from workspace (*3)✔️✔️✔️✔️✔️
View members in workspace✔️✔️✔️✔️✔️
Create a new base✔️✔️✔️✔️✔️
Access existing bases at assigned roles✔️✔️✔️✔️✔️
Delete Workspace✔️️
Billing & upgrade options✔️️

(*1) Members can invite others with the same role or a lower role.

(*2) Members can manage access for others with the same role or a lower role.

(*3) Members can remove others with the same role or a lower role.

Base level permissions

Collaboration

TaskOwnerCreatorEditorCommenterViewer
Invite member to base (*1)✔️✔️✔️✔️✔️
Create base invite link (*1)✔️✔️✔️
Manage member access to base (*2)✔️✔️✔️✔️✔️
Remove member access from base (*3)✔️✔️✔️✔️✔️
View members in a base✔️✔️✔️✔️✔️
Share base✔️✔️
Share view✔️✔️

(*1) Members can invite others with the same role or a lower role.

(*2) Members can manage access for others with the same role or a lower role.

(*3) Members can remove others with the same role or a lower role.

Table & view operations

TaskOwnerCreatorEditorCommenterViewer
Add / modify / delete table✔️✔️
Add / modify / delete fields✔️✔️
Add / modify / delete views (*1)✔️✔️✔️
Lock / unlock a view✔️✔️
Assign a view as another user's personal view✔️✔️
Add / modify / delete view folders✔️✔️
Hide / un-hide / reorder fields✔️✔️✔️️️
Add / modify / delete sort✔️✔️✔️️️
Add / modify / delete filters✔️✔️✔️️️
Add / modify / delete group-by✔️✔️✔️️️
Add / modify / delete row colour✔️✔️✔️️️
Add / modify / delete cell colour✔️✔️✔️️️

(*1) Editors have full CRUD on collaborative views and on their own personal views. They can change any collaborative view into a personal view that they own. Editors cannot change or delete locked views. They cannot set the mode of a view to Locked. They cannot change or delete the personal views of other users. Editors can still move any view between existing sections in the sidebar. Creators and owners keep all these abilities.

Record operations

TaskOwnerCreatorEditorCommenterViewer
Add / modify / delete record✔️✔️✔️
View & add comment on a record✔️✔️✔️✔️
View record✔️✔️✔️✔️✔️
Manage record-level security✔️✔️
Record visibility can be further refined using Record-Level Security policies, which allow you to control which records each role, team, or user can access within a table.

Automations & advanced

TaskOwnerCreatorEditorCommenterViewer
Add / modify / delete Webhook✔️✔️
ERD (Project & Table relations)✔️✔️✔️✔️✔️
API Snippet✔️✔️✔️✔️✔️
API Token✔️✔️✔️✔️✔️

Availability

  • Teams are available on NocoDB Cloud (Business plan and above) and licensed self-hosted deployments (Scale plan and above).

Last updated on

Latest product updates?See Changelog
Stay in the loop? Follow us onLinkedInLinkedInYouTubeYouTubeXX