Roles and permissions

Playcode uses three roles - Viewer, Editor, and Admin - on both projects and workspaces. This is the reference for what each role allows, how the different ways of granting access combine, and how invitations work.

The three roles

A role can be granted on a single project (from its Share tab) or on a whole workspace (from Settings → People & teams). Same names, same idea: Viewers look, Editors build, Admins manage.

What roles allow in a project

CapabilityViewerEditorAdmin
Open the project and its previewYesYesYes
Read the AI chat historyYesYesYes
Edit code, files, and project settingsNoYesYes
Work with the AI agentNoYesYes
Share the project and change accessNoNoYes
Publish and unpublishNoNoYes
Delete the project or move it to another workspaceNoNoNo (owner only - see below)

What roles allow in a workspace

CapabilityViewerEditorAdmin
Open the workspace's team projectsYesYesYes
Edit team projectsNoYesYes
Create projects in the workspaceNoYesYes
Invite and remove members, change rolesNoNoYes
Create and manage teamsNoNoYes
Manage billing and the workspace planNoNoYes
Rename or delete the workspaceNoNoYes

A workspace role applies to the workspace's team projects - projects whose Access list gives Everyone at [workspace name] access. It never reaches projects marked No access (see "Invited-only projects" below) or anyone's Personal workspace.

The project owner

The person who created a project appears at the top of its People list as Owner. That is not a fourth role you assign - it simply marks the creator, who always keeps full control of the project:

  • Only the owner can delete the project or move it to another workspace (workspace admins can additionally return a member's project to that member's Personal workspace).
  • Only the owner can grant the Admin role on the project.

How access combines

Someone can have access to a project through several doors at once:

  • a direct share - they are listed in the project's People list,
  • a team - a team they belong to was added to the project,
  • Everyone at [workspace name] - the project is open to workspace members,
  • Anyone with the link - the public link allows viewing.

When these overlap, the most permissive one wins. If the workspace row says Can view but a person holds a direct Editor share, they can edit. Removing one grant never downgrades another: revoking a team's access does not touch a personal share the same person also holds.

Invited-only projects

Setting Everyone at [workspace name] to No access makes a project invited-only: only the owner and the people or teams named in its Share popup can open it. For everyone else in the workspace - including workspace admins - the project is simply not visible. Use this for drafts, experiments, or client work inside a shared workspace.

The public link

The Anyone with the link row is independent of everything above. A project can be invited-only for the workspace and still viewable by anyone holding the link, or open to the whole workspace with the link switched off. Owners can additionally allow link visitors to edit (Anyone with link can edit) or use the AI (Anyone with link can use AI, Pro). Turning the link off entirely is a Pro feature - see How to make a project private.

Guests: sharing outside your workspace

Sharing a project by email works for anyone, not just workspace members. A guest gets the role you picked on that one project, appears in its People list, and sees the project under Shared with me. Guests do not join your workspace and do not take up a workspace seat - invite as many project collaborators as you need.

Invitations: the lifecycle

  • Pending - an invitation sent to an email without a Playcode account waits in the People list (project invites) or the Invitations tab (workspace invites) until it is accepted.
  • Expiry - invitations expire after 7 days; each one shows its expiry date.
  • Copy invite link - grab the same link the email carries and deliver it yourself, for example when the email lands in spam.
  • Resend - issues a fresh link and a new 7-day window; the previous link stops working.
  • Role change - changing a pending invitation's role keeps the already-sent link valid; no need to resend.
  • Revoke - cancels the invitation; its link stops working.
  • Accept - the recipient opens the link, signs in or creates an account, and joins with the role you chose.

Who can share, publish, and delete

  • Share a project / change its access: the owner, the project's Admins, and the workspace's Admins. Project Admins can add existing Playcode users; email invitations to people without an account are sent by the owner or a workspace Admin.
  • Publish and unpublish: the owner, the project's Admins, and the workspace's Admins.
  • Delete or move a project: the owner. Workspace Admins can return a member's project to that member's Personal workspace - see Move a project to another workspace.
  • Manage members, teams, billing, workspace settings: workspace Admins.

Need more help?

Can't find what you're looking for? Chat with us or send us an email.