Skip to main content

Permissions and User Role-Based Access

Customize levels of access for different team member accounts

Written by Naomi Fleishour

If you are part of a larger organization, you may have several team members who only need access to specific parts of the app. When you have multiple user accounts, you can control exactly what each person can see and do in the Prospero app with granular permissions settings. This allows each person access and edit only the resources relevant to them.

Manage Permissions

To change permission and access settings, go to Settings and click on the Members tab. When inviting new members to your organization, you can select the permissions they will receive once they join the organization. Click the ... next to a user to edit their permissions.

You can also deactivate or reactivate a user from the Members tab. Deactivating a user disables their account and removes them from your organization's billing plan.

Permissions can also be preset by creating User Roles that you define once and can assign to any number of users. Any user can be assigned any role, setting their permissions automatically.

💡 Create a user role for stage or production managers of a specific project, with editing permission only for the project they're involved in. Assign the role when their account is created, then deactivate the account at the end of the project.

Create User Role-Based Permissions

User Roles let you set permissions once for each type of team member instead of configuring every account individually. Create separate permission sets for production managers, scheduling coordinators, front-of-house, or guest artists.

To create a role, go to Settings > Members, scroll to the bottom of the page, and click Create Role.

Select the permissions the role will be able to access and save. You can now assign users to the role, and they will immediately inherit the role's permissions.

When inviting new members to your organization, assign them a role and their permissions will be set automatically the moment they join.

ℹ️ User Roles are separate from Project Roles (like "Director" or "Stage Manager"), which are used to plan projects and staff events. User Roles define permissions and access to the app. For more on project roles, see A Guide to Roles and Role Groups.

Individual User Overrides

Need an exception for one person? Open that user's permissions from the Members tab and change any of their settings at the individual user level without changing the overarching User Role. Overrides apply only to that user without affecting anyone else assigned to that role.

Editing Permissions

Permissions are presented in a grid. The same permissions grid is used whether you're defining a User Role or setting permissions for an individual user. Each row indicates a section of the app. These sections are categorized into Settings, Entities, and Project Events. Columns represent the permission levels that can be set for each section, from least permissive to most permissive:

  • No Access - Blocks access completely to the selected section of the app.

  • Read - Allows a user to access and view the selected section of the app, but no other actions can be taken.

  • Edit - Allows a user to edit existing data in the selected section of the app, but prevents adding new data.

  • Create - Allows a user to edit and create new data in the selected section of the app, but it cannot be removed once the data is created.

  • Delete - Grants a user full access to the selected section of the app: editing, creating, and deleting data.

The Default level of access set in the top row will be the fallback access level if one is not set for a particular section.

Settings

Permissions can be edited to grant or limit access to the Organization, Membership, Billing, and Calendar Integrations settings tabs.

  • The organization name, customizable namespace for view links, and org logo can be edited from the Organization tab.

  • Members can be invited, deactivated, and have their permissions edited from the Membership tab.

  • Payment method, plan info, billing details, and invoice history can be accessed in the Billing tab.

  • Third-party calendar integrations with Google Calendar and Outlook Calendar can be edited from the Integrations tab.

Note: Functionally, there are only two levels of access for Billing and Organization: Read and Edit. Edit, Create, and Delete are all the same level of access for Billing and Organization since data fields cannot be added or removed, only changed.

Resources

You can set access to read-only, edit, add, and delete data for each of the app's different resources: Projects, People and Groups, Locations, Items and Collections, Consumables, Tags, Files, Views, and Customers.

ℹ️ At any level of access, all members can create shareable personal views that are visible only to them and not to other members of the organization. Only organization views are restricted by permissions.

Project Events

Under Events, each Project has an access level for its events. Adjust the permissions to give users access only to the events that are relevant to their projects, or give them broad editing abilities for the organization's entire calendar.

💡 A stage manager might have Read access for every production by default, and Delete access only for the production they’re currently working on.

Bookings and Portals

Within each booking portal, an admin is assigned to handle requests and receive notifications for that specific portal. You can limit access to other admin users through permissions for individual portals.

Questions?

Contact the Prospero team at hello@prosperoapp.com or chat with us in the app.

Did this answer your question?