2 min read

Permissions

Permissions control what team members and clients can see and do in Orka. Orka uses role-based access control (RBAC) to keep your data secure.

What is it?

Permissions define access levels for users. Each role has specific capabilities — from full admin access to read-only viewing.

Why does Orka use it?

  • Security — Team members only access what they need
  • Accountability — Clear roles mean clear responsibilities
  • Client safety — Clients see only their own projects
  • Compliance — Audit trails track who did what

How does it work?

Team roles

RoleCapabilities
OwnerFull access, billing, delete workspace
AdminManage team, projects, and settings
MemberEdit assigned projects and clients
ViewerRead-only access

Client access

Clients have separate permissions:

  • Portal access — View their own projects and invoices
  • File access — Download shared files
  • No admin access — Cannot manage workspace settings

When should you use it?

  • Admin — Workspace owners and managers
  • Member — Team members who do the work
  • Viewer — Clients, advisors, or stakeholders who need visibility

Common misconceptions

  • "Everyone needs Admin access" — No, use the principle of least privilege
  • "Clients can see other clients" — No, client access is scoped to their projects
  • "Permissions are rigid" — You can customize access per project and client