User permissions can be changed at any time after assignment. Changes are made from "User management", and there are three methods: changing one person at a time, changing multiple people together, or changing permissions in bulk with Excel.
For a list of what can be done for each permission level, see User permissions and account limit. Operations are performed from a PC browser.
Who can change permissions
- Owner / Team Administrator: Can change permissions for all users in the team
- Group Administrator: Can only change permissions for users in their own group. If the target user belongs to a group outside their jurisdiction, they cannot change it
- Created user / View-only user / Guest: Cannot change permissions (the "User management" option is not displayed)
Additionally, the following rules apply.
- You cannot change your own permissions (you can change your display name and group affiliation yourself)
- You cannot grant a role higher than your own. Only an Owner can assign the Owner role
Change one person at a time
- Open "User management" from the sidebar
- Click on the target user and open "User details"
- Click the pencil icon to the right of "Permission"
- Select a new permission from the dropdown
- Click "Save"
The dropdown is divided into "Organization member" (Owner / Team Administrator / Group Administrator / Created user / View-only user) and "External user" (Guest). Each option displays a description of the permission, unavailable permissions are grayed out with the reason shown next to them.
When removing admin permissions
When changing from Owner, Team Administrator, or Group Administrator to a lower permission level, a confirmation dialog will appear. After confirming the permissions that will be lost, click "Change".
Change multiple users at once
- Select target users using the checkbox on the left side of the user list
- Click "Change permissions" in the bar displayed at the top of the screen
- Select the new permission and click "Change"
If a Group Administrator performs this operation, users outside their jurisdiction are automatically excluded from the target, and the number of excluded people is displayed in the bar.
Change permissions in bulk with Excel
Owners and Team Administrators can change user permissions together using an Excel file. Use this when you have many users or when you need to review permissions as part of an organizational change.
- Click "Bulk change" at the top of the "User management" screen
- Download the template file
- Change column C "Permission" from the dropdown in the "User list" tab
- Upload the saved file, check the contents, and import
If you only want to review permissions, use "Differential add mode" (users not included in the sheet will remain unchanged). The file format instructions are included in the "How to use" tab within the template.
Impact on account count
Owner / Team Administrator / Group Administrator / Created user / View-only user are all counted together as the same account count. Even if you change permissions among these five, the number of accounts consumed does not change.
Guests are counted separately from the account count. When changing from an organization member to a guest or from a guest to an organization member, which count it falls into is switched. If the target has reached its limit, the change cannot be made and a plan notice is displayed.
For how accounts are counted, see Account limit and how to count, and for guests, see What is guest invitation.
When changes cannot be made
No pencil icon appears next to the permission
This occurs when you have opened your own "User details", or (in the case of a Group Administrator) when the target user belongs to a group outside your jurisdiction. To change your own permissions, request assistance from an Owner or Team Administrator.
"You cannot select a higher permission level than your own" is displayed
You cannot grant permissions higher than your own. If you want to assign the Owner role, have the Owner perform the operation.
"Cannot demote because this is the last owner" is displayed
A team must have at least one Owner. First change another user to Owner, then demote them.
"Email-free accounts cannot be made owners" is displayed
Email-free accounts cannot be assigned the Owner role. To make an account an Owner, first switch to an account that logs in with an email address (see How to change account information).
Cannot make an inviting user an Owner
Users who have not yet logged in (who are still being invited) cannot be assigned the Owner role. Make the change after they log in and join the team.
Reflection after changes
Permissions are updated when you click "Save" or "Change". If the target user is logged in, the new permissions will be reflected when they reload the screen.
Changes to permissions are recorded in the audit log (see Export audit log as CSV).