Inviting your team and choosing roles

Candor has four workspace roles plus a project-level membership layer. The combination determines what each teammate can see and do. Here’s the practical breakdown.

The four workspace roles

Owner

Full control. Can invite or remove anyone (including other Owners and Admins), grant any role, transfer ownership, change workspace settings, toggle the MFA policy, and delete the workspace. Owners always see every project.

Admin

Most things an Owner can do, with three exceptions: Admins can’t delete the workspace, can’t invite or remove Owners or other Admins, and can’t transfer ownership. They can invite Editors and Viewers, change workspace settings, manage projects, and toggle the MFA policy. Admins also see every project.

Editor

Can create projects, and can edit, delete, run interviews in, and invite members to any project they’re a member of. That includes projects someone else created and added them to, not only their own. Editors only see projects they’re explicitly added to as members. They don’t see every project in the workspace by default.

Viewer

Read-only access to projects they’re explicitly added to. Viewers can’t create projects, edit anything, or invite anyone. Useful for stakeholders who want to see findings without changing them.

Workspace role vs project membership

Two layers, different purposes. The workspace role determines what someone can do. Project membership determines which projects they see.

  • Owners and Admins see every project in the workspace automatically. No need to add them.
  • Editors and Viewers only see projects they’re added to as members. Add them from the project detail page.

Project membership is binary: you’re a member or you’re not. It doesn’t change someone’s capabilities; their workspace role still gates what they can do once they’re in. So a Viewer added to a project can see it but can’t edit it, while an Editor added to a project can edit it.

Who can manage billing

Owners and Admins, both of them. Billing is deliberately not Owner-only, so a single person isn’t a bottleneck on adding a project slot or updating a card. Editors and Viewers don’t see the Billing tab at all. See Plans and billing for what’s in there.

Inviting someone

From Settings → Team, invite by email address and pick a role. The role dropdown only shows roles you’re allowed to grant. Owners can grant any role; Admins can grant Editor or Viewer.

The invitee receives an email with a setup link. Clicking it lands them on a setup form where they enter their first name, last name, and a password (12+ characters). Once they finish setup, they’re in the workspace with the role you assigned.

One constraint worth knowing before you send an invite: an account belongs to exactly one workspace. If the person you invite already has a Candor account in another workspace, the invite is blocked rather than silently adding them to a second one. They’ll need to use a different email address, or leave their existing workspace first.

Changing someone’s role

On the team page, each member has a role dropdown. You can promote or demote them in place. The same can-grant rules apply: Admins can’t change another Admin’s role, and only Owners can demote or promote to Owner.

Removing someone

Click Remove next to a member. A confirmation dialog asks you to confirm. Once removed they lose access to every project in the workspace immediately. Their data (audit events, usage) stays in your workspace history; only their access is revoked. You can re-invite them later.

Transferring ownership

Owners can transfer ownership to another Owner or Admin via Transfer ownership. There’s a checkbox to also demote yourself to Admin in the same step (otherwise you stay an Owner alongside the new one). The workspace always has at least one Owner; the transfer preserves that invariant.

Requiring two-factor for everyone

Owners and Admins can flip a workspace-wide MFA toggle on the team settings page. When on, every member without MFA gets prompted to enrol on next sign-in and can’t use the app until they do. Members with MFA already are unaffected. The toggle reads: Require two-factor authentication for everyone in this workspace.

Deleting the workspace

Owner-only. Available under the team settings Danger zone. Deletes every project, persona, interview, and report in the workspace permanently for every member. The dialog requires you to type the workspace name to confirm. Cannot be undone.

Where to go next

Common questions

Start from what they need to do, not from seniority. Someone who will run research needs Editor: that covers creating projects, editing them, running interviews, and adding other people to the projects they're in. Someone who only needs to read findings gets Viewer. Admin is for people who should manage the workspace itself, meaning inviting and removing teammates, changing workspace settings, and handling billing. Owner adds the things that should be rare: transferring ownership, promoting people to Owner or Admin, and deleting the workspace. Most teams need one or two Owners and mostly Editors.

Almost always project membership rather than their role. Owners and Admins see every project in the workspace automatically. Editors and Viewers only see projects they've been explicitly added to as members, which you do from the project itself. So an Editor with the right role can still be looking at an empty dashboard until someone adds them. The quick diagnostic: a project missing from their list is a membership problem, and a button missing inside a project they can already see is a role problem.

Not to a second workspace. An account belongs to exactly one workspace, so if the email you're inviting already has a Candor account, the invite is blocked rather than quietly adding them to yours. They have two options: use a different email address for your workspace, or leave their existing one first. Worth checking before you promise someone access, because the block happens at invite time rather than when they click the link.

Their access to every project ends immediately. What they produced does not disappear: the projects, personas, interviews, and reports stay exactly where they are, and the workspace history that records their activity is retained. Only the person's access is revoked. You can re-invite them later, though they come back as a new invite rather than a restored account, so you pick their role again and re-add them to the projects they need.

Owners and Admins can require two-factor for the whole workspace from the team settings page. Turning it on doesn't sign anyone out. Members who already have two-factor set up notice nothing. Members who don't get sent to an enrolment screen the next time they load a page in the app, and they finish setup before they can continue. Nothing is lost, but tell the team before you flip it, because someone without their phone to hand is stuck until they have it.

More FAQs →

Candor is in development.

Be the first to know when it launches.

No spam. Just a note when Candor is ready. Powered by Highline Beta.