On Monday, Marta, the owner of a 14-person services company, prepares access for a new accountant in Task Manager. She pauses at “Recruitment”: should the accountant be able to see this Workspace at all? Marta starts by checking the global role and the list of Workspaces; she won't send the invitation until Friday.

Access in Task Manager requires three decisions

First, decide who will manage the whole app, who belongs to each Workspace and who can create new Tasks and Chats in them. A global role doesn't replace membership of a Workspace. Membership alone doesn't allow someone to start new Threads.

Task Manager has two global roles. The administrator can see and manage all Workspaces, Tasks and Chats, and has access to the app settings. Users can see only the Workspaces they're assigned to. The global administrator has full permissions in every Workspace - you can't limit them to one department by unticking a Workspace.

So Marta can keep overall management to herself and give the team manager Administrator permissions in their Workspace only. Global administrator is a role across the whole app; the Administrator field applies to one Workspace. With 14 people, it's then easier to answer “who can see Tasks?”: first check the global role, then the assigned Workspaces, and finally the participants in a specific Task or Chat. User roles in Task Manager explains this division in more detail.

Workspaces separate departments, but “Everything” doesn't show the whole company

A Workspace groups Tasks and Chats related to a project, team or topic. Regular users can see only the Workspaces they're assigned to; “Everything” brings together the Workspaces available to them, not every Workspace in the company.

On Tuesday, Marta lays out four Workspaces: “Accounting”, “Recruitment”, “Marketing” and “New website”. She assigns the accountant to the first, but not to Recruitment. Sending a link to a Task doesn't bypass this separation: anyone without access will see a message instead of the content. Search is also limited to what the user can access.

Three-column view showing a list of Workspaces, Tasks and an open conversation
The list of Workspaces on the left shows the work context; “Everything” brings together the Workspaces available to that person

To change the members of an existing Workspace, select the ⋮ icon on its card, then Edit Workspace and the “Assign users” section. You can see the ⋮ icon only next to Workspaces you manage. To create a new Workspace, select “+” next to “Workspaces”; this button is visible to global administrators and people with the “Can add Workspaces” permission. Without this permission, the button isn't shown. Find out more about how Workspaces are organised in the Workspaces in Task Manager overview.

Don't delete a Workspace just to remove it from someone's list. Deletion requires you to enter the exact name and can't be undone: it deletes Tasks, Chats, messages and attachment files from the disk. Workspaces can't be archived; you can move individual Tasks and Chats to the bin. If you only want to change one person's access, change their assignment.

Three fields in a Workspace determine who can start new Threads

In each Workspace, you set Administrator, Tasks and Chats permissions separately. These fields define the scope of Workspace management and the right to create new Tasks and Chats; they don't mean that a Workspace member can automatically see every Thread.

SettingWhat it allowsWhat it doesn't grant on its own
AdministratorManage this Workspace: add and remove participants, change settings, edit and delete other people's Tasks and ChatsAccess to other Workspaces
TasksCreate new TasksAccess to Tasks the person hasn't been added to
ChatsStart new ChatsAccess to Chats the person hasn't been added to

Without the “Tasks” permission, a person can still see Tasks they've been added to and post messages in them. Without the “Chats” permission, they can still read and write in Chats they've been added to. That's the difference between taking part in work and starting a new Thread.

In another example, on Wednesday Kasia from customer support is given Tasks and Chats permissions in the “Sales” Workspace. In “Marketing”, Marta can leave her as a member without permission to start new Threads, and she doesn't have to assign her to “Recruitment” at all. If you tick Administrator for a Workspace, the Tasks and Chats boxes are ticked automatically and locked. Ticking either permission adds the person to the Workspace; unticking the Workspace clears the entire row.

Users window with a table of Workspaces and the Administrator, Tasks and Chats columns
In each table row, set access to one Workspace, along with permission to manage it and create Threads

If someone cannot add Tasks or Chats in any Workspace they can access, the “Add task” and “Add chat” icons disappear from the top of the middle column. So the missing icon does not mean they cannot take part in a Task they have already been assigned to.

Module permissions do not replace access to Workspaces

You set module permissions when adding or editing a user, separately from their permissions in individual Workspaces. These cover adding Workspaces, AI in Tasks, AI in Chats, the AI Assistant window, Mail and Automations.

On Thursday, Marta gives Kasia access to AI in Chats, but not in Tasks. Kasia will then see AI options in Chats, while the “AI Assistant”, “Organise” and “Polish text” buttons will not appear in Tasks. A separate permission opens the AI Assistant window from the view menu. The AI Assistant only sees what that person has access to - asking it a question does not extend their permissions.

There is also an “AI Assistant with internet access” setting, which allows it to retrieve the content of websites. It is disabled by default; the global administrator always has this access. Mail, Files and Automations are part of the Pro plan, so do not assume they are available in the Standard plan. If you do not see n8n in the permissions screen, that does not necessarily mean there is a problem: it only appears once the administrator enables this experimental integration.

Administrators manage work, but cannot read private email

The global administrator can see all company Workspaces, Tasks and Chats, but cannot see anyone else’s mailbox, private Notes or conversations with the AI Assistant. The boundary between work in Workspaces and private content also applies to the company owner.

A Note is private unless you choose to share it - you can give someone read-only access or permission to edit it. Assigning a Note to a Workspace is a label, not a way to share it with that Workspace’s members. Mailboxes are private too; if several people use a shared company email address, each person connects it in their own account.

Conversations in the AI Assistant window remain private. When you ask the AI Assistant a question from within a Task or Chat, its reply is not shared with the other participants either: it is marked “JUST FOR YOU”. This distinction is useful when explaining to your team what administrator access means.

If you use Mail as a source of knowledge for AI, remember one more boundary. This option is disabled by default; an administrator can enable it, in which case the content is sent to the external model provider. The privacy of your mailbox from other users should not be confused with data being sent to an AI provider.

Invite new people - don’t send them a password

Add a new person in the Users window. Open it using the group icon in the top-left corner, next to the cog. On the “Add” tab, enter their details, choose a role and permissions, and the invited employee sets their own password.

On Friday, Marta enters the accountant’s email address, first name and surname, selects the User role and chooses the required module permissions. Further down, in the “Assign to Workspaces” table, she selects “Accounting” and sets the permissions for that Workspace. Once saved, the person receives an invitation email and sets a password when activating their account. Marta does not need to know or send them their password.

If the message does not arrive, select “Resend” next to that person in the user list. Administrators can also use the same button to send a link that lets the user set a new password themselves. The “List” tab lets you edit roles, account status and permissions in Workspaces later; the guide to adding users and setting roles walks you through this screen step by step.

The Users window with an account awaiting activation and the Resend button
For anyone who has not yet activated their account, you can resend the invitation

During installation, Task Manager creates a “Shared” Chat in the default “General” Workspace. Newly added users join it automatically, subject to their access to that Workspace. If you are just getting your team set up, follow the first-week plan for Task Manager.

When someone leaves, blocking and deactivating their account do different things

Deactivating an account prevents the user from logging in and frees up a licence seat, while preserving their data and Tasks. Blocking the account removes their sessions and remembered devices, but does not free up the seat - choose the right action based on whether you also need to reclaim a licence seat.

What happensDeactivation: “Active” switched offBlocking: “Account status” → “Blocked”
Licence seatFreed upRemains occupied
Login attempt“Incorrect email or password” messageA message saying the account has been blocked by an administrator
Active sessionThe user cannot log inSessions and remembered devices are cleared; the user is logged out the next time they click

On Monday the following week, Marta deactivates the departing employee’s account by switching off “Active” in their user settings. Their data and Tasks remain, and a new person can take their licence seat. If she needs to block an account while the user has an active session, she selects “Blocked” under “Account status”. However, she cannot block herself or another global administrator. She also cannot delete her own account or the last administrator’s account.

The licence counts active users. On the “Add” tab, you will see “Seats used: X / Y”; you can also check the status under Settings → Advanced → Licence. Once the limit is reached, you cannot add another person, activate an invited account or switch “Active” back on for a deactivated user until a seat is freed up or more seats are added. The Starter plan includes up to 8 people, Classic up to 20, and Max up to 35. The licence is perpetual, with a one-off fee based on the number of seats and 12 months of updates included.

For tomorrow, prepare an access list, not a list of exceptions

Tomorrow, open the Users window, go to the “List” tab and review access person by person. For each Workspace, ask: “Does this person need to see this Workspace?”

To start with, divide Workspaces according to the work their members actually need to do. In Marta’s 14-person company, “Accounting” and “Recruitment” can have separate member lists, a manager can manage their own Workspace, and everyone else can create Tasks and Chats only where they work. This is an example of a setup, not a rule for every company.

Your application data is stored on your own server, but choosing a server will not define access between employees. If you would like to see how it works first, open the Demo.

Frequently asked questions

Can the administrator see my emails and Notes?

No, the administrator can't see someone else's mailbox or Notes you haven't shared with them. They can't see your private conversations with the AI Assistant either; assigning a Note to a Workspace doesn't share it with anyone.

How do I stop someone from seeing a project?

Remove them from the project's Workspace: select ⋮ on the Workspace card → Edit Workspace → untick them in the “Assign users” section → Save. This applies to regular users; the global administrator has access to all Workspaces.

Can I set a password for a new employee?

No, new employees set their own password using the link in their invitation. If the email hasn't arrived, select “Resend” next to their name in the user list.

An employee has left - should I delete or deactivate their account?

Deactivate the account using the “Active” toggle if you want to keep the person's data and Tasks and free up a licence seat. Deactivated users can't log in.

What's the difference between blocking and deactivating an account?

Blocking clears sessions and remembered devices, logs the person out on their next click and doesn't free up a licence seat. Deactivation frees up a seat, and at login displays the standard “Invalid email or password” message.

Sources

  1. Task Manager, Users and Roles
  2. Task Manager, Workspaces
  3. Task Manager, Resources: Users and Roles
  4. Task Manager, Resources: Workspace
  5. Task Manager, Perpetual licence
  6. Task Manager, Installed on your own server

The Task Manager Team - we write about teamwork, AI in business and keeping tasks organised, using examples from Task Manager, software installed on your own server. Task Manager has been developed by Blue Creation Group (Piotr Łącz) since 2013 and is used by organisations including Neonet, the Military University of Technology and Polpharma - read customer reviews. We check our articles against the user guide and the latest version of the software.