TeamRetro Roles and Permissions
TeamRetro manages user permissions and roles at three levels:
- Within each account
- Within each team
- Within each meeting (retrospective or health check)
This document summarizes what these roles represent and the permissions each have.
Account Roles
TeamRetro defines four roles at the account level - Owner, Administrator, User + Insights (enterprise only) and User. The Owner role is automatically assigned to the user who initially created the account. By default, all additional users added to an account have only the User role.
| Owner | Administrator |
User + Insights (enterprise-only) |
User (default) |
|
| Manage billing, subscription, and transactions | YES | - | - | - |
| Change the account name, subdomain, logo, and branding | YES | - | - | - |
| Delete the account | YES | - | - | - |
| Give another user the Owner role | YES | - | - | - |
| Create and view account-level API keys | YES | - | - | - |
| Set up SCIM provisioning | YES | - | - | - |
| Set allowed email domains and allowed IP ranges | YES | - | - | - |
| Set a custom "Request New Team" message and URL | YES | - | - | - |
| Set up SAML single sign-on and require SSO | YES | YES | - | - |
| Manage AI and feature settings | YES | YES | - | - |
| Manage team policies (team list visibility, transparency) | YES | YES | - | - |
| Turn team API keys and connected apps on or off | YES | YES | - | - |
| Manage roles and permissions settings | YES | YES | - | - |
| Manage account users (view, add, change roles, remove) | YES | YES | - | - |
| Manage all teams (view, create, edit, remove, archive) | YES | YES | - | - |
| View account-wide insights and reports | YES | YES | YES | - |
| View a list of all teams | YES | YES | YES | YES (depends on Team Policies) |
| Be a team member | YES | YES | YES | YES |
Team API keys are created in each team's settings by Team Admins or Account Administrators, once team API keys are turned on for the account.
Only the Account Owner can:
- change the account name, subdomain, logo, and branding
- manage billing, the subscription, and transactions
- create and view account-level API keys
- set up SCIM provisioning
- set allowed email domains
- set allowed IP ranges
- set a custom "Request New Team" message and URL
- delete the account
- give another user the Owner role
Account Administrators can manage everything else in Account → Settings.
Team Roles
Team Members may be assigned the additional Admin role, granting them privileges to manage membership of the team and create new meetings. Each team must have at least one admin.
|
|
Administrator |
Member (default) |
Observer (enterprise-only) |
| Invite team members(new users will be added as Account Users) | YES | - | - |
| View team members | YES | YES | YES |
| Promote members to admin role | YES | - | - |
| Remove team members | YES | - | - |
| Start a retrospective meeting | YES | - | - |
| Delete finished retrospective meetings | YES | - | - |
| Participate in any team retrospective or health check | YES (as Facilitator) | YES (as Participant) | YES (as Observer) |
| Use the AI assistant (trAI) | YES | YES | - |
| Create, edit, delete team actions | YES | YES | - |
| Manage team options(name, logo, integrations, etc) | YES | - | - |
| Delete the team | YES | - | - |
Retrospective / Health Check Roles
Retrospective / Health Check Participants may be granted the Facilitator role, giving them tools to drive the meeting activities. Each activity must have at least one Facilitator. By default, only the Team Admin who started the activity has the Facilitator + Participant role.
|
Facilitator Only |
Facilitator + Participant (default for meeting creator) |
Participant (default for team members) |
Guest (enterprise-only) |
Observer (enterprise-only) |
|
| Will be automatically added as team member if invited | YES | YES | YES | - | - |
| Invite participants | YES | YES | - | - | - |
| Manage participant roles | YES | YES | - | - | - |
| Modify retrospective / health check settings (topics, brainstorm style, group permissions, action permissions, etc) | YES | YES | - | - | - |
| Move the retrospective / health check between steps (Brainstorm, Group, Vote, Discuss, etc...) | YES | YES | - | - | - |
| Set an activity timer | YES | YES | - | - | - |
| Add ideas | - | YES | YES | YES | - |
| Edit own ideas | - | YES | YES | YES | - |
| Edit others' ideas | - | - | - | - | - |
| Comment on ideas | YES | YES | YES | YES | - |
| Vote | - | YES | YES | YES | - |
| Add reactions | - | YES | YES | YES | - |
| Group / ungroup ideas | YES | (depends on retro settings) | (depends on retro settings) | (depends on retro settings) | - |
| Add / edit / remove actions | YES | (depends on meeting settings) | (depends on meeting settings) | (depends on meeting settings) | - |
| Answer Check In / Check Out questions | - | YES | YES | YES | - |
| Close a retrospective | YES | YES | - | - | - |
| Anonymity | (depends on meeting settings) | (depends on meeting settings) | (depends on meeting settings) | (depends on meeting settings) | Named |
AI assistants
An AI assistant, whether trAI or your own assistant connected over MCP, acts as you and has exactly your permissions. Some actions are also limited to certain meeting steps. See What AI assistants can do at each meeting step.