Roles and Permissions
How roles interact with projects, seats and approvals.
The seven workspace roles and the full capability matrix are in User roles and permissions. This page covers how roles interact with the rest of DonorDesk.
Workspace role vs project assignment
- Your workspace role (set on the Team page by an Admin) defines what you can do.
- Your project assignments (project → Team) define which projects you work on and your project role there.
Seats
Seats are counted by role. Full seats are every role except Viewer; Viewers have their own, larger allowance (Starter 2, Team and above unlimited). Give board members, donors and auditors the Viewer role.
Sensitive actions and who can take them
| Action | Who |
|---|---|
| Approve a report | Admin, Project Manager |
| Decide on flagged statements | Admin, Project Manager |
| Confirm sharing of confidential (Sensitive / Highly sensitive) evidence in an export | Admin, Grants Officer |
| Accept a high-severity compliance risk | Users with checklist permission, confirming authority |
| Delete evidence | Admin |
| Manage billing, team and settings | Admin |
| Manage AI Writing Style | Admin, Project Manager |
| View the audit log | Admin, Project Manager, Compliance Officer |
Separation of duties
A common setup is: Field Officers log activities and upload evidence; M&E Officers enter and verify indicators; Grants Officers draft and edit reports; Project Managers approve; Compliance Officers verify evidence and manage the checklist; Viewers export.
Changing roles
Admins change roles on Team. The screen shows what the person will gain and lose. Changes are audited. See How to change a role.