Last updated: 2026-03-19 · 4 min read

Understanding Roles and Permissions

In Terasu, permissions are managed at two levels: the Workspace level and the Room level. In addition, internal members and external members (customers) have access to different features.

Room member management screen

Internal vs. External Members

Members in Terasu fall into two broad categories.

TypeDescriptionHow they're invited
Internal membersYour sales team, who belong to the WorkspaceInvited to the Workspace
External membersCustomers and partners invited to a RoomInvited to a Room

This distinction lets you collaborate safely within the same Room while protecting the materials your sales team creates and internal information from customers.

Internal and external members have different permissions for files and pages. For details, see Managing Content Permissions.

Workspace Roles

These are permissions for the entire Workspace and apply only to internal members.

RoleDescription
OwnerHas full permissions for the Workspace, including billing management, member management, and settings changes
AdminCan invite members, manage Rooms, and change settings. Cannot manage billing
MemberCan create Rooms and edit content. Cannot change Workspace settings

Permission Matrix

ActionOwnerAdminMember
Change Workspace settingsYesYesNo
Invite/remove membersYesYesNo
Manage billing and plansYesNoNo
Create RoomsYesYesYes
Manage your own RoomsYesYesYes

Room Roles

These are permissions within each Room. They can be set independently of Workspace roles.

RoleApplies toDescription
Room ownerInternal members onlyFull permissions for the Room, including settings changes, member management, and deletion
EditorInternal and external membersCan view and edit content and upload files
ViewerInternal and external membersCan only view content

The Room owner role can only be assigned to internal members. External members (customers) cannot be granted Room owner permissions.

Permission Differences Between Internal and External Members

Even with the same "Editor" role, internal and external members can perform different actions.

ActionInternal (Owner)Internal (Editor)External (Editor)External (Viewer)
View public pagesYesYesYesYes
View internal-only pagesYesYesNoNo
Edit pagesYesYesDepends on page settingsNo
Edit/delete all filesYesYesNoNo
Edit/delete your own filesYesYesYesNo
Upload filesYesYesYesNo
View the org chartYesYesNoNo
View analytics reportsYesYesNoNo
Manage membersYesNoNoNo
Change Room settingsYesNoNoNo

You can set external members' page-editing permissions on a per-page basis. Set only the pages you want customers to fill in to "All members can edit." For details, see Managing Content Permissions.

Permission Hierarchy

Workspace admins and above can access every Room. Members can only access the Rooms they've been invited to.

The owner role can be transferred, but a Workspace must always have at least one owner.

Best Practices

  • Principle of least privilege: Grant only the minimum permissions necessary.
  • Regular reviews: Clean up members who have left the company or whose projects have ended.
  • Managing external members: Invite them per Room and remove them promptly once they're no longer needed.
  • Use internal-only pages: Set internal notes and strategy materials to "internal-only" so external members can't see them.
  • Tailor page-editing permissions: Set only the pages you want customers to fill in to "All members can edit."
Understanding Roles and Permissions | Help center