Understanding Roles & Permissions

Last updated: August 31, 2026

Background

Document Crunch uses a hierarchical, role-based permissions model that gives your organization precise control over who can view, edit, and manage content. Access is organized across three levels — Organization, Team, and Project — and permissions flow downward from one level to the next. Understanding how roles and inheritance work helps you confidently invite teammates and external collaborators while making sure the right people have the right access. Whether you are an admin setting up your workspace or a team member trying to understand what you can do, this article explains how the model works and what each role can and cannot do.

Things to Consider

  • There are three permission levels: Organization, Team, and Project. The Organization level has a single Admin role; the Team and Project levels each have Admin, Editor, and Viewer roles.

  • Permissions are hierarchical and inherit downward (Organization → Team → Project): your Team role sets your baseline on every project in that team, which can then be raised on individual projects (see the next two bullets). Access never flows upward — a project-level grant does not give access to the team or to other projects.

  • Organization Admins have full access to every team and every project in the organization, at all times.

  • Your Team role automatically applies to every project in that team by default — a Team Editor starts as an Editor on all of the team's projects, and a Team Viewer as a Viewer on all of them — unless they are elevated to a higher role on a specific project. For example, a user with Viewer access at the Team level assumes Viewer on every project, but can be adjusted up to Editor or Admin on an individual project.

  • A project-level role can elevate a Team Editor or Viewer on a specific project, but can never reduce their role below what they hold on the team. Team Admins are locked — they are always Admin on every project in the team.

  • A user can hold different roles on different teams within the same organization.

  • Every organization must always have at least one Organization Admin, and every team must always have at least one Team Admin. The system blocks any action that would remove the last admin of either type.

  • A single Document Crunch account can belong to multiple organizations — roles, teams, and content are fully isolated per organization with no cross-org visibility.

The Permissions Hierarchy

Document Crunch organizes access across three levels:

Organization → Team → Project

Each level inherits from the one above it:

  • Organization Admins can manage all settings, users, teams, and content everywhere in the organization.

  • A Team role is applied automatically to every project within that team as a baseline, and can be raised on individual projects (see Project-level overrides below).

  • A Project is the lowest level. A role granted only at the project level is scoped to that single project — it grants no access to the team or to any other project.

Project-level overrides (elevate only)

When a user has a Team role, a project assignment can raise their role on an individual project — but never lower it. Overrides are per-project and independent, so the same user can hold different elevated roles on different projects.

Team role

Roles they can hold on a project

Can they be lowered on a project?

Admin

Admin (locked)

No — always Admin on every project

Editor

Editor (inherited) or Admin

No

Viewer

Viewer (inherited), Editor, or Admin

No

Example: A Team Viewer can be elevated to Editor on Project A and to Admin on Project B at the same time, while remaining a Viewer on every other project in the team.

Role Definitions

Organization Admin

Organization Admins have the broadest access in the organization. They can update organization settings, invite and manage all organization users, and create or delete teams. Org Admins also have full access to all team and project content.

Note: Every organization must always have at least one Organization Admin. The system will block any action that would leave an organization without one.

Team Admin

Team Admins have full control within their assigned team(s). In addition to all Team Editor capabilities, they can update and delete team settings, invite and manage team users, create and delete projects, and move folders and documents. A Team Admin is automatically an Admin on every project in the team.

Note: Every team must always have at least one Team Admin. If the last Team Admin is being removed, another admin must be designated first.

Team Editor

Team Editors can do everything a Team Viewer can, plus create projects, upload and manage documents, create folders, apply and remove Playbooks and reviews, create markups and version comparisons, and manage tasks. They cannot manage users or team settings. A Team Editor is an Editor on every project in the team by default, and can be elevated to Admin on individual projects.

Team Viewer

Team Viewers have read-only access to the team's content. They can view, download, chat with, and share team documents. A Team Viewer is a Viewer on every project in the team by default, and can be elevated to Editor or Admin on individual projects.

Project Admin / Project Editor / Project Viewer

Project roles carry the same capabilities as their Team equivalents, but scoped to a single project. They are used in two ways: to give someone access to one specific project without granting team-wide access, or to elevate a Team Editor or Viewer on a particular project. Project roles cannot reduce a user below their team role.