Skip to main content

How team and access work

Everyone in your organization signs in with their own account. What each person can see and do comes from the roles they hold: on the whole organization, or on one project. A role is given to a person directly, or to a group they belong to. A control you have no role for isn't shown.

This page explains the ideas behind access. For the steps, see Invite a person and grant access, Create a group and Check what someone can access. For every control on the screen, see People, Groups and Your organization.

Terms​

TermMeaning
OrganizationYour company's space in Jaah. Its people, groups, projects, credentials and nodes all belong to it.
PersonOne account in your organization, listed on the People tab. It signs in with its Email.
GroupA set of people. Every role a group holds applies to each member.
EveryoneThe group every person in your organization belongs to. Jaah adds and removes its members.
RoleA named set of things a person may do, such as Project Developer.
ScopeWhat a role applies to: the organization, one project, or one model account.
SourceHow a person holds a role: Direct, Via a group, or Inherited from the organization.
Access requestAn ask for a role on something you can't open yet.

The roles​

Jaah has five roles. Two apply to the whole organization; three are project roles.

RoleWhat it allows
Org OwnerFull control of the organization, including who else is an owner.
Org AdminAdministers the organization: its projects, people, credentials and settings.
Project MaintainerRuns a project: its settings, worktrees, sessions, schedules and workflows.
Project DeveloperWorks on a project: creates and edits tasks and brings their own credentials.
Project ViewerReads a project: its tasks, worktrees and sessions.

Org Owner and Org Admin are granted only on the organization. A project role can be granted on one project, or on the whole organization, where it applies to every project. A project role can also be granted on a model account. Grant a role when you add a person, on their Access tab, or on the Access tab of the organization, project or account.

An organization with an email domain can give a Default role to people who join through it: None, Project Viewer or Project Developer.

Where a role comes from​

A person's roles add up from three places:

  • Direct — given to the person.
  • Via a group — given to a group they're in. Remove them from the group, and the role goes too.
  • Inherited from the organization — a role granted on the whole organization reaches each project.

A grant on a project can carry an Expires date; left empty, it never expires. To see every role a person holds and where it comes from, open their Access tab. To ask whether they may do one thing, and why, use Check access.

A person's states​

StateWhat it meansWhat moves it on
InvitedThe person is listed, but hasn't accepted the invitation yet. A hollow round mark, and the Account card reads Invited — hasn't accepted yet. Resend invitation sends the email again. Roles can be granted already; they apply on accepting.The person accepts: from the invitation email, or, if they already use Jaah, from their account menu.
DeclinedThe person turned the invitation down. A Declined tag beside the address, and the Account card reads Declined the invitation.Invite again sends a new invitation.
ActivatedThe person has signed in. A filled round mark, and the Account card reads Active.An Org Owner or Admin selects Disable account.
DisabledThe person is signed out and can't sign in. A Disabled tag beside the address.An Org Owner or Admin selects Enable account.

Deleting an account removes it and every group membership it had.

When you have no access​

Opening something you hold no role for shows a No access page with the address you're signed in with. When it's a project, a model account or your organization you can't open, the page offers Request access: pick the Role you need, add a Note (optional), and send it. Only project roles can be requested; Org Owner and Org Admin are only ever granted.

A request is Pending until someone who manages access there, an Org Owner, Org Admin or Project Maintainer, decides. They Approve or Deny it from the Requests tab on the Support page, and it becomes Approved or Denied. You're notified of the decision. Your own requests are in that tab's Mine box. See Support.