TeamRetro Roles and Permissions
TeamRetro manages user permissions and roles at three levels:
- Within each account
- Within each team
- Within each meeting (retrospective, health check or estimation)
This document summarizes what these roles represent and the permissions each have.
Account Roles
TeamRetro defines four roles at the account level - Owner, Administrator, User + Insights (enterprise only) and User. The Owner role is automatically assigned to the user who initially created the account. By default, all additional users added to an account have only the User role.
| Owner | Administrator |
User + Insights (enterprise-only) |
User (default) |
|
| Manage billing, subscription, and transactions | YES | - | - | - |
| Change the account subdomain | YES | - | - | - |
| Change the account name, logo, and branding | YES | YES | - | - |
| Delete the account | YES | - | - | - |
| Give another user the Owner role | YES | - | - | - |
| Create and view account-level API keys | YES | - | - | - |
| Set up SCIM provisioning | YES | - | - | - |
| Set allowed email domains and allowed IP ranges | YES | - | - | - |
| Set a custom "Request New Team" message and URL | YES | - | - | - |
| Set up SAML single sign-on and require SSO | YES | YES | - | - |
| Manage AI and feature settings | YES | YES | - | - |
| Manage team policies (team list visibility, transparency) | YES | YES | - | - |
| Turn team API keys and connected apps on or off | YES | YES | - | - |
| Manage roles and permissions settings | YES | YES | - | - |
| Manage account users (view, add, change roles, remove) | YES | YES | - | - |
| Manage all teams (view, create, edit, remove, archive) | YES | YES | - | - |
| View account-wide insights and reports | YES | YES | YES | - |
| View a list of all teams | YES | YES | YES | YES (depends on Team Policies) |
| Be a team member | YES | YES | YES | YES |
Team API keys are created in each team's settings by Team Admins or Account Administrators, once team API keys are turned on for the account.
Only the Account Owner can:
- change the account subdomain
- manage billing, the subscription, and transactions
- create and view account-level API keys
- set up SCIM provisioning
- set allowed email domains
- set allowed IP ranges
- set a custom "Request New Team" message and URL
- delete the account
- give another user the Owner role
Account Administrators can manage everything else in Account → Settings.
Team Roles
Team Members may be assigned the additional Admin role, granting them privileges to manage membership of the team and create new meetings. Each team must have at least one admin.
|
|
Administrator |
Member (default) |
Observer (enterprise-only) |
| Invite team members(new users will be added as Account Users) | YES | - | - |
| View team members | YES | YES | YES |
| Promote members to admin role | YES | - | - |
| Remove team members | YES | - | - |
| Start a meeting | YES | - (team setting) | - |
| Delete finished retrospective meetings | YES | - | - |
| Participate in any team meeting | YES (as Facilitator) | YES (as Participant) | YES (as Observer) |
| Use the AI assistant (trAI) | YES | YES | - |
| Create, edit, delete team actions | YES | YES (team setting) | - |
| Manage team options(name, logo, integrations, etc) | YES | - | - |
| Delete the team | YES | - | - |
A row marked "team setting" shows the default. A Team Admin can change it in the team's Roles & Permissions settings.
Meeting Roles
Meeting Participants may be granted the Facilitator role, giving them tools to drive the meeting activities. Each activity must have at least one Facilitator. By default, only the Team Admin who started the activity has the Facilitator + Participant role.
A facilitator-only participant runs the meeting and joins the discussion, but doesn't add ideas, votes, ratings, estimates, poll answers or standup updates.
|
Facilitator Only |
Facilitator + Participant (default for meeting creator) |
Participant (default for team members) |
Guest (enterprise-only) |
Observer (enterprise-only) |
|
| Will be automatically added as team member if invited | YES | YES | YES | - | - |
| Invite participants | YES | YES | - | - | - |
| Manage participant roles | YES | YES | - | - | - |
| Modify meeting settings (topics, brainstorm style, group permissions, action permissions, etc) | YES | YES | - | - | - |
| Move the meeting between steps (Brainstorm, Group, Vote, Discuss, etc...) | YES | YES | - | - | - |
| Set an activity timer | YES | YES | - | - | - |
| Add ideas | - | YES | YES | YES | - |
| Edit own ideas | - | YES | YES | YES | - |
| Edit others' ideas | YES | YES | - | - | - |
| Comment on ideas | YES | YES | YES | YES | - |
| Vote | - | YES | YES | YES | - |
| Add reactions | YES | YES | YES | YES | - |
| Group / ungroup ideas | YES | (depends on retro settings) | (depends on retro settings) | (depends on retro settings) | - |
| Add / edit / remove actions | YES | (depends on meeting settings) | (depends on meeting settings) | (depends on meeting settings) | - |
| Answer Check In / Check Out questions | - | YES | YES | YES | - |
| Close a meeting | YES | YES | - | - | - |
| Anonymity | (depends on meeting settings) | (depends on meeting settings) | (depends on meeting settings) | (depends on meeting settings) | Named |
AI assistants
An AI assistant, whether trAI or your own assistant connected over MCP, acts as you and has exactly your permissions. Some actions are also limited to certain meeting steps. See What AI assistants can do at each meeting step.