You can change user permissions at any time after assigning them. Make changes from "User management" using one of three methods: changing permissions for one user at a time, changing multiple users together, or bulk changing with Excel.
For a list of what each permission level can do, see User permissions and permission slots. Operations are performed from a PC browser.
Who can change permissions
- Owner / Team Admin: Can change permissions for all users in the team
- Group Administrator: Can only change users in their assigned group. If the target user belongs to a group outside your jurisdiction, you cannot change their permissions
- Created user / View-only user / Guest: Cannot change permissions ("User management" is not displayed)
Additionally, the following rules apply.
- You cannot change your own permissions (you can change your display name and group affiliation yourself)
- You cannot grant a role higher than your own. Only an Owner can assign the Owner role
Change permissions one user at a time
- Open "User management" from the sidebar
- Click the target user to open "User details"
- Click the pencil icon next to "Permission"
- Select a new permission from the dropdown
- Click "Save"
The dropdown is divided into Organization member (Owner / Team Admin / Group Administrator / Created user / View-only user) and External user (Guest). Each option displays a description of the permission. Permissions you cannot select appear grayed out with an explanation of why.
When removing admin permissions
If you change from Owner, Team Admin, or Group Administrator to a lower permission level, a confirmation dialog appears. Review the permissions you will lose, then click "Change".
Change multiple users at once
- Select target users using the checkboxes on the left side of the user list
- Click "Change permissions" in the bar displayed at the top of the screen
- Select a new permission and click "Change"
If a Group Administrator performs this operation, users outside their jurisdiction are automatically excluded, and the number of excluded users is displayed in the bar.
Bulk change with Excel
Owner / Team Admin can bulk change user permissions using an Excel file. Use this when managing many users or reviewing permissions during organizational changes.
- Click "Bulk change" at the top of the "User management" screen
- Download the template file
- In the "User list" tab, change column C "Permission" from the dropdown
- Upload the saved file, review the contents, and import
If you are only reviewing permissions, use differential add mode (users not listed in the sheet remain unchanged). Instructions for how to complete the file are in the "How to use" tab in the template.
Impact on permission slots
Owner / Team Admin / Group Administrator / Created user / View-only user share the same permission slot. Changing permissions between these five roles does not change the number of accounts consumed.
Guest is a separate slot. When changing from organization member to guest or from guest to organization member, the consumed slots are exchanged. If the target slot has reached its limit, the change cannot be made and a plan offer is displayed.
For information on how slots work, see Understanding user limits and permission slots. For information on guests, see What is guest invitation.
When you cannot make changes
No pencil icon appears next to the permission
This occurs when you have opened your own "User details," or (if you are a Group Administrator) the target user belongs to a group outside your jurisdiction. Request an Owner or Team Admin to change your own permissions.
"*You cannot select a higher permission level than your own" is displayed
You cannot assign a permission higher than your own. If assigning the Owner role, have an Owner perform the operation.
"*Cannot demote because this is the last owner" is displayed
A team must have at least one Owner. First change another user to Owner, then demote this user.
"* Email-free accounts cannot be made owners" is displayed
You cannot assign the Owner role to an email-free account. To make an account an Owner, first switch it to an account that logs in with an email address (How to change account information).
Cannot make an inviting user an Owner
You cannot assign the Owner role to a user who is still being invited and has not logged in yet. Make the change after they log in and join the team.
Reflection after change
Permissions are updated when you click "Save" or "Change". If the target user is logged in, the new permissions are reflected when they reload the screen.
Changes to permissions are recorded in the audit log (Export audit log as CSV).