WorkOS by Befocusy WorkOS Help center

Who can do what: permissions summary by module

This summary gathers the permissions of every module in one place. Each module article gives more detail. What you see here applies equally to the app, to Kairos and to the MCP server (Claude or ChatGPT): they act with your same permissions and can neither see nor do anything more.

The roles

  • Owner: full control of the account.
  • Technical contact: a mark added to a person for technical setup. It can be anyone, with any role.
  • Supervisor: manages their direct reports.
  • Member: normal use of the app.

In this guide, manager means Owner or Technical contact.

Tasks

Anyone can open and read a task. What they can change depends on their level in it:

  • Manager and assignee: everything, including completing, discarding and deleting.
  • Participant: the content, comments, adding attachments and their own time.
  • Anyone else: read and comment only.

Every task has an assignee (it cannot be created or left without one). Older tasks with none are edited only by managers, from the No assignee scope. A Supervisor can change the assignee of their reports' tasks. More detail in "Who can edit a task".

Projects and services

Anyone can open and read a project. To change it:

  • Manager and assignee: header and content, linking tasks, documents, notes and contacts.
  • Participant: upload attachments and collaborate with email and calendar.
  • Managers only: change the assignee and participants, the companies, the Service tab, "Depends on" and commercial information capture.

Managers create projects and, if your administrator allows it, so do Supervisors. The assignee is mandatory. The Others scope is read-only for anyone who is not a manager.

Agenda

  • Meetings: only seen by the assignee (edits) or a participant (read-only). Nobody else, not even the Owner.
  • Calendar events: only exist if you have your own calendar connected and enabled in Agenda. Without one there is no Events tab or "New event".

Inbox

It only exists if you have a channel of your own connected (an email account, WhatsApp or personal Slack). Without one, the Inbox icon disappears and Kairos cannot touch email either.

Wiki, Digital Garden and Documents

  • Adding articles, tabs and topic groups to the Wiki, and creating topics in the Digital Garden: managers only.
  • Moving a note (Move button): only its owner. To Wiki also requires being a manager; To document only requires being the note's owner.
  • Managing document types and commercial information capture: managers only.
  • The rest (editing, visibility, favorites) depends on each record's owner and participants.

Catalogs

Services, Task types and Profiles: everyone sees the list, but opening, creating and editing is for managers only.

Social networks and publications

  • With Social networks checked, the user connects and uses their personal networks. Unchecking it from the administration panel disconnects their personal accounts.
  • With Manages company, they see and create company publications even without Social networks. The Owner always can.
  • Newsletter and WordPress (Integrations): managers only.

Settings

Each module's settings and simulation mode belong to the Technical contact. So does reconnecting Notion. The Inbox configurator only opens with an email account of your own connected. The Copy Notion link button is only seen by people with technical control.

Tip: if an option you expected is missing, check your role first and whether you have the channel or calendar connected. It is almost always the reason.