Roles and permissions
Beta: Roles and permissions are in early testing and aren't on by default. We turn them on for each organization by hand. Want to try them? Contact support@tato.co.
Tato records the meetings, notes and documents behind your client work, and not everyone in your organization needs to see all of it. Roles and permissions let you keep each project's content visible only to the people working on it, and decide who can change or share it.
Access in Tato works at three main levels:
- Organization roles decide whether someone can use Tato and whether they can manage the account.
- Project roles decide what someone can see and change inside a project.
- Activity roles decide what someone can do with a single activity, such as a meeting, note, document or email.
Reports have their own roles, which are set on each report.
A role at one level doesn't carry over to another, with one exception: your project role gives you a matching role on every activity filed in that project. That's why project members can read the project's meetings.
No organization role gives access to project or activity content on its own. An organization Admin who isn't a member of a project can't see what's inside it.
Organization roles
Every person in your organization has one organization role. You set it in Organization settings → Members.
| Role | Summary |
|---|---|
| No access | Tato knows about them, for example because they joined a meeting, but they can't sign in or see anything. |
| Viewer | Can sign in and use Tato: chat, the meeting list, dashboards, the skill library and people. |
| Editor | Viewer, plus can create things that don't belong to a project, such as activities and automations. |
| Admin | Manages the organization: people, projects, groups, integrations and organization settings. |
| Owner | Admin, plus security and compliance settings, and can make other people Admin or Owner. |
| Capability | Viewer | Editor | Admin | Owner |
|---|---|---|---|---|
| Sign in, use chat, see the meeting list and dashboards | Yes | Yes | Yes | Yes |
| Create personal skills, and use skills shared with the whole organization | Yes | Yes | Yes | Yes |
| Connect their own calendar and edit their own profile | Yes | Yes | Yes | Yes |
| Create and delete activities that aren't filed in a project | Yes | Yes | Yes | |
| Create, edit and run automations | Yes | Yes | Yes | |
| Review project suggestions in the Inbox for activities they took part in | Yes | Yes | Yes | |
| Review project suggestions in the Inbox for every activity | Yes | Yes | ||
| Create projects | Yes | Yes | ||
| Archive any project | Yes | Yes | ||
| Manage the members of any project, including project Admins | Yes | Yes | ||
| Add and deactivate people, and edit their details | Yes | Yes | ||
| Create, edit and delete groups | Yes | Yes | ||
| Give someone the No access, Viewer or Editor role | Yes | Yes | ||
| Share any activity, and edit its participants | Yes | Yes | ||
| Manage agents, organization skills, meeting types and organization integrations | Yes | Yes | ||
| Manage the Tato assistant calendar | Yes | Yes | ||
| See usage statistics, export data and contact Tato support | Yes | Yes | ||
| Give someone the Admin or Owner role | Yes | |||
| See the audit log | Yes | |||
| Manage allowed email domains and who can sign in | Yes | |||
| Manage connectors, the Tato MCP server and MCP clients | Yes |
To access a project's activities and details, an organization Admin needs a project role. They can open any project from Organization settings → Projects and add themselves, or anyone else, as a member. The audit log records it.
Project roles
Every member of a project has one project role. You set it in Project settings → Members. A person can have a different role in each project.
| Role | Summary |
|---|---|
| Viewer | Can see everything in the project but can't change anything. The default when you add someone. |
| Editor | Does the hands-on work: edits the project's activities and records, and adds people. |
| Admin | Runs the project: sets it up, manages its integrations and members, and can archive it. |
People who aren't members of a project can't see it or its content, unless an activity from the project has been shared with them directly, in which case they can only see that activity.
| Capability | Viewer | Editor | Admin |
|---|---|---|---|
| See the project, its activities, RAID log, scope, topics, tickets and documents | Yes | Yes | Yes |
| See the project context, its integrations and their status | Yes | Yes | Yes |
| See the list of project members | Yes | Yes | Yes |
| Use project skills and agents | Yes | Yes | Yes |
| Change their own notification settings for the project | Yes | Yes | Yes |
| Edit the project's activities | Yes | Yes | |
| Create and delete activities, and file activities into or out of the project | Yes | Yes | |
| Create and edit RAID items, scope items, topics, tags and tickets | Yes | Yes | |
| Upload, edit and delete documents | Yes | Yes | |
| Create, edit and delete project skills and automation routines | Yes | Yes | |
| Open project settings, edit the project's details and see its change history | Yes | Yes | |
| Add members and set their role to Viewer or Editor | Yes | Yes | |
| Share any of the project's activities, and edit their participants | Yes | ||
| Edit the project context and methodology | Yes | ||
| Connect and configure project integrations, such as Azure DevOps or SharePoint | Yes | ||
| Make someone a project Admin, or change an Admin's role | Yes | ||
| Remove members and edit their titles | Yes | ||
| Archive the project | Yes |
Project Editors can add people and change roles, but only up to Editor, and they can't change the role of a project Admin. Only a project Admin or an organization Admin can give the Admin role.
To stop someone from seeing a project, remove them from it. They lose access to the project's activities straight away, except activities that were shared with them directly.
Organization Admins and Owners can always manage the members of any project, even if they aren't members themselves. If a project loses all of its Admins, an organization Admin can assign a new one.
Activity roles
An activity is a single item in Tato: a meeting, note, document or email. Every person who can see an activity has one activity role on it.
| Role | Summary |
|---|---|
| Viewer | Can open the activity and see its title, content, participants and projects. |
| Editor | Viewer, plus can edit the activity's title and content. |
| Admin | Editor, plus can share the activity, choose what each person can do, and edit participants. |
| Capability | Viewer | Editor | Admin |
|---|---|---|---|
| Open the activity and see it in lists and search | Yes | Yes | Yes |
| Edit the title and content | Yes | Yes | |
| Share the activity with people or groups | Yes | ||
| Change someone's role on the activity | Yes | ||
| Edit the list of participants | Yes |
Activity roles only cover the activity itself. Risks, decisions, action items and other items drawn from an activity belong to the project. To see or change them, you need a project role.
Filing an activity into a project and deleting it also depend on project roles:
- To file an activity into or out of a project, you need to be able to see the activity and be an Editor or Admin on each project you add or remove.
- To delete an activity, you need to be an Editor or Admin on one of its projects. If the activity isn't in any project, you need the Editor organization role or higher.
How your activity role is set
Nobody assigns activity roles from a list, the way project roles are set. Tato sets your role based on your participation in the activity and your role on the project it's filed in. If more than one applies, you get the highest.
| How you're connected to the activity | Role you get |
|---|---|
| You created it | Admin |
| You spoke in or attended the meeting | Editor |
| You were invited to the meeting but didn't attend | Viewer |
| It's filed in a project where you're an Admin | Admin |
| It's filed in a project where you're an Editor | Editor |
| It's filed in a project where you're a Viewer | Viewer |
| Someone shared it with you, or with a group you're in | The role chosen when sharing (Viewer by default) |
For example, a project Viewer who also spoke in the meeting is an activity Editor. Because project Editors are activity Editors, they can edit their project's activities but can't share them. Project Admins are activity Admins, so they can share any activity in their project.
A role set by sharing with you directly replaces the role you'd get from attending the meeting. This means an activity Admin can raise or lower an attendee's role.
Sharing an activity
Activity Admins and organization Admins can share an activity:
- Open the activity and select Share.
- Search for a person or group and add them.
- Choose their role: Viewer, Editor or Admin.
The share dialog shows where each person's access comes from:
- Projects the activity is filed in. Access from a project shows as Set by the project. To change it, change the person's role in that project.
- Participants: the people who were in the meeting, and the person who created the activity. An activity Admin can change what each of them can do.
- Direct assignment: people the activity was shared with. An activity Admin can change their role or remove them.
You can't change your own role.
Removing access to an activity
Removing someone from an activity takes away their direct share, the access they had from attending the meeting, and any access from a group share. It doesn't take away access from:
- a project the activity is filed in
- having created the activity
You can't keep a project member out of a single activity in their project. If they shouldn't see it, file the activity somewhere else, or remove them from the project.
Editing an activity's participants changes the names shown on it, not who has access. To change access, use the share dialog.
Report roles
Reports and report templates are shared on their own, with three roles:
| Role | What they can do |
|---|---|
| Viewer | Read the report. |
| Editor | Edit the report and share it. |
| Publisher | Approve and publish the report. |
Report roles are set on each report and nowhere else. Being an Editor in your organization or a project doesn't make you an Editor on a report.
Defaults
| Situation | Default |
|---|---|
| Someone signs in with SSO for the first time | Organization role No access, until an Admin changes it |
| An Admin adds a person in Organization settings → Members | Organization role Viewer |
| You create a project | You become its project Admin |
| You add someone to a project | Project role Viewer |
| You share an activity | Activity role Viewer |
| Someone is deactivated | They can't sign in and lose all access |
Audit log
Every change to who can access what is recorded in the audit log, which Owners can see in Organization settings → Audit logs. Each entry shows who made the change, who it affected, and which project or activity it was about. Names are kept as they were at the time, so renaming something later doesn't change the history.
The audit log records when:
- an activity is shared with a person or group, and the role it gives
- a share on an activity is removed
- the role a share gives is changed
- someone is added to or removed from a project
- someone's project role is changed
- an activity is filed into a project, giving the project's members access
If you used Tato before roles and permissions
When your organization moved to the new roles:
- Organization roles stayed the same. The Owner role is new: Tato works with each organization to choose its Owners when roles and permissions are turned on.
- Project roles were set from each person's previous organization role. For example, an organization Admin who was a member of a project is now an Admin on that project.
- Activity roles were set from meeting roles. Meeting owners became Admins, attendees became Editors and invitees became Viewers.
Organization Admins who weren't members of a project no longer see that project's content. They can add themselves to it from Organization settings → Projects.
Have questions about roles in your organization? Reach out to your Tato contact or support@tato.co.