# Roles and permissions

Each member holds one role, for the whole organization.

## The three roles you start with

### Administrator

Everything. Administrator is the only locked role: it cannot be edited, renamed or deleted.

### Collaborator

The working role, with 37 permissions.

- Creates, edits and deletes items, attachments, comments, time logs, workload allocations, capacity entries and baselines.
- Reads types, fields, views, users and teams.
- Does not manage views, users, teams, types, fields or roles.

### Reader

The following-along role, with 19 permissions.

- Reads items, types, fields, views, users, teams, attachments, time logs, allocations, capacity and baselines.
- May write comments and set its own notification preferences.
- Nothing else.

Collaborator and Reader are ordinary roles. An administrator can rename, re-tune or delete them.

## Where permissions are set

**Settings → Organization → Roles** is a grid with one row per thing that can be permitted, and one column per role. [Open in Teamhood](https://app.teamhood.com/go/settings/roles) See [Create a role](../create-a-role/).

## Assigning a role

Roles are assigned on **Settings → Organization → Users**, in the Role column. [Open in Teamhood](https://app.teamhood.com/go/settings/users)

Only an administrator may change a person's role. If you move your own role away from Administrator, only another administrator can give the role back.

## What roles do not decide

- **Which views you see.** A view has its own audience. See [Who can see a view](../view-access/).
- **Whether the organization is open at all.** If everyone is locked out, the cause is billing rather than permissions. See [What happens when a subscription lapses](../../subscription/what-happens-when-a-subscription-lapses/).

## Next

- [Create a role](../create-a-role/)
- [Why was my request refused?](../why-was-my-request-refused/)
