> For the complete documentation index, see [llms.txt](https://docs.unitlab.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.unitlab.ai/documentation/collaboration/role-based-access.md).

# Role-based access

Built-in roles provide understandable starting points for least privilege. Effective access still depends on workspace, project, workflow, assignment, and resource state.

### Before you make the change

* List the actions each persona needs and does not need.
* Separate administrative ownership, operations management, annotation, and independent review.
* Identify any sensitive data or model-management restrictions.

![Unitlab role-based access settings](https://292810646-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FGjVLUz4wthGkGlRKM6rM%2Fuploads%2Fae9ur8IvUdY0Oj98kTAD%2Froles-permissions.png?alt=media\&token=605e99b1-c6d9-4642-8d2f-b724c50790ab)

*Review the effective capability across permission groups rather than relying on a role name alone.*

### Understand the product behavior

Built-in roles include:

* Owner;
* Manager;
* Member;
* Annotator;
* Reviewer.

Administrators can also create custom roles for workspace-specific access patterns.

Roles can be configured to permit assignment as an Annotator or Reviewer.

Workspace role and project position are different:

* **Workspace role** controls tenant-wide capabilities.
* **Project position** determines eligibility for annotator or reviewer workflow stages.

Owner, Manager, and custom roles use the administrative branch by default. Member, Annotator, and Reviewer are assignment-scoped and see only the stage queues and work items for which they are eligible.

### Assign the minimum role

{% stepper %}
{% step %}

#### 1. Choose the closest built-in role

Start with Owner, Manager, Member, Annotator, or Reviewer according to current responsibilities.
{% endstep %}

{% step %}

#### 2. Add project scope

Assign only the projects needed for the work.
{% endstep %}

{% step %}

#### 3. Confirm workflow eligibility

Check the stages and actions available to the role.
{% endstep %}

{% step %}

#### 4. Test with the real account

Verify both expected access and important denied actions.
{% endstep %}

{% step %}

#### 5. Review periodically

Revalidate when responsibility, project scope, or employment status changes.
{% endstep %}
{% endstepper %}

### Decisions that affect production

| Decision  | Production guidance                                                  |
| --------- | -------------------------------------------------------------------- |
| Owner     | Reserve for accountable workspace administration and recovery.       |
| Manager   | Use for operational management without unnecessary ownership rights. |
| Annotator | Limit to assigned annotation work and applicable collaboration.      |
| Reviewer  | Preserve independent review capability and avoid hidden conflicts.   |

### Continue the operating flow

* Create a custom role only for a durable gap.
* Document project and stage assignments.
* Include role review in offboarding and production-readiness checks.
