Help center
Open dashboard

Understanding User Roles and Permissions in Atarim

Every role in Atarim, what each one can actually see and do, and the three separate layers of control that decide it.

Atarim team Updated 29 Jul 2026 · 11 min read
Getting Started
The Atarim role permissions matrix beside the workspace members table
Before you start

Relevant for

  • Agency admins assigning roles to staff and clients
  • Anyone unsure who can see what, or why two people see different things
  • Teams onboarding a client and deciding between a Website Owner account and a guest invite

Required knowledge

None. Some sections describe admin-only screens, but the role explanations are useful whatever your own role.

Tools & resources needed

  • No setup required to read this
  • An administrator account to change roles or permissions

Atarim organises access around one core distinction: are you on the agency side or the client side of a relationship? Five roles cover both sides.

On top of the roles sit two further layers — a workspace-wide capability grid, and per-project access controls. Understanding which layer is responsible for what is the difference between fixing an access problem in thirty seconds and hunting through the wrong screen.

In this guide you'll learn what each role can do, where to change someone's role, how the two permission layers work, and what a Website Owner account can and can't reach.

The Five Roles

Every person in Atarim holds exactly one of these. The internal value is what you’ll occasionally see in an export or an integration payload; the display name is what appears in the interface.

RoleWhat it means
OwnerThe workspace’s own account holder. Full access, including plan and billing screens.
AdministratorFull access to every settings screen, including plan and billing.
Team MemberInternal staff. Works on tasks and projects, but does not see People, Settings, Workflows or Analytics by default.
Website OwnerA client who holds their own account, with their own plan and their own small team.
CollaboratorThe lightest-weight role. Invited to one project, with the narrowest default access of any role.
Note
Team Member is stored internally as contributor, so you may occasionally see that word in an export or integration payload. In the interface the role is always shown as Team Member.

Step-by-Step Guide

Step 1: Knowing Which Layer Controls What

Three separate layers decide what someone can do. Most access confusion comes from checking the wrong one, so it’s worth learning the split before anything else.

LayerWhat it controlsWhere to change it
RoleBroad access — whether someone is an admin, staff, a client, or a guest.People screen
Workspace capabilitiesSpecific in-task abilities, per role, across the whole workspace.Settings > Workspace > User Permissions
Project accessWho can open one particular project, and how.That project’s Share panel
Site-level roleYour effective role on one specific website, which can differ from your workspace role.That site’s own team list
Tip
When someone says “I can’t do X”, work down the list. If they can’t see a whole screen it’s their role. If they can see the screen but not one control, it’s a workspace capability. If it only happens on one project, it’s project access.

What the User Permissions screen can’t change

The grid covers in-task capabilities. It does not cover which sidebar items a role can see — those are set at account level and don’t appear on that screen at all.

Warning
If you’re trying to give a Team Member access to Workflows, Analytics, People or Settings, you won’t find a row for it in User Permissions. Sidebar visibility isn’t configurable per workspace — contact Atarim support if your team needs one of those opened up.

Roles are also resolved per site

There’s a fourth layer that only surfaces occasionally. Your effective role is worked out per website rather than once for the whole workspace: if you own a site you’re treated as an Administrator on it, otherwise Atarim uses the role you were given on that specific site. Where no role exists for you on a site, it falls back to Collaborator — the most restricted option.

Note
This is why the same person can have broad access on one project and very little on another. It’s deliberate, not a glitch — but it does mean “what role is this person?” sometimes has more than one answer.

Step 2: Viewing and Changing Someone’s Role

Roles are managed from the People screen, which lists everyone in the workspace with their role beneath their name.

  • Select People in the sidebar to open Team Management.
  • Select a person’s name to open their profile. Four tabs appear: SettingsActivity FeedAssigned Projects, and Pending Invites.
  • Use the Settings tab to change their role, adjust notification preferences, or revoke access.
  • To bring someone new in, select Add Team Member.
  • Choose their role as you invite them — the picker describes each one rather than just naming it.
  • Three roles can be assigned from this invite:

    RoleDescribed in the invite as
    AdministratorA project manager or team member
    Team MemberA team member or contractor
    CollaboratorA stakeholder or client
    Note
    Website Owner isn’t in this list. Client accounts are created through the client flow rather than a workspace invite, so you can’t turn a workspace invite into a Website Owner account after the fact.
    Roles Are Shown and Changed From the People Screen
    Note
    If a teammate can’t see People in their sidebar at all, that’s expected rather than a bug — it’s restricted to the Account Holder and Administrators.
    Warning
    Administrators reach every settings screen, including Account & Billing — where plan changes and seat counts affect the whole workspace. Assign the role sparingly.

    Step 3: Setting Workspace-Wide Capabilities

    Beyond the broad role definitions, the User Permissions screen lets you override specific capabilities per role. The grid runs capabilities down the left and all five roles across the top.

  • From the main dashboard, select Settings.
  • Under Workspace, select User Permissions.
  • Find the capability you want to change. Where one has an information icon, hover it to read exactly what it controls.
  • Select or clear the checkbox under the role you want to change.
  • Confirm it saved — an Updating… badge appears beside the heading, followed briefly by a Saved! badge.
  • Fourteen Capabilities Across Five Roles
    Note
    There’s no Save button and no undo — each checkbox saves as you change it. Reverse a change by setting the checkbox back yourself.
    Warning
    Editing this grid requires a qualifying plan. If yours doesn’t include it, the checkboxes are still visible but selecting one opens an upgrade dialog instead of changing anything.

    What a Clarity Test actually is

    One capability on that grid is worth explaining, because the name is easy to misread. A Clarity Test is an AI check that scores how clear a task is and suggests how to make it easier to action — it works on the wording of the task, not on the website.

    Note
    Not to be confused with Microsoft Clarity, the third-party heatmap tool that appears as the Heatmaps default in The Stack. Same word, entirely unrelated feature.

    Step 4: Controlling Access to a Single Project

    Every project has its own access controls, separate from the workspace-wide defaults. They live in the project’s Share panel, which has three tabs.

  • Open the project and select the share option.
  • Use Team Members to add internal staff to this project.
  • Use Guests and Clients to invite someone by email address. Add an optional note explaining why you’re inviting them, then send.
  • Use Manage Access to set who can view the project.
  • Under General Access, choose between Anyone with the link and Only people with access.
  • Review the People with Access list, and remove anyone who no longer needs it.
  • Project sharing screen showing the Team Members section for adding internal staff to the project.
    Team Members
    Guests and Clients
    Manage Access
    Warning
    The Manage Access tab only appears if you’re an administrator on that site. Team Members and Collaborators see the other two tabs but not this one, so they can invite people without being able to change who can view the project.
    Tip
    Guests invited here don’t need an account or a login — they get a link scoped to that one project. Reserve it for people who genuinely don’t need an ongoing relationship, since there’s no automatic upgrade path from a guest link to a full client account.

    Step 5: Understanding Website Owner Accounts

    Website Owners are clients who hold their own Atarim account rather than being guests on yours. They run on a separate plan with its own caps, described in the plan itself as a “minimal website-owner experience scoped to managing up to five websites with an AI agency.”

    LimitWebsite Owner plan
    ProjectsUp to 5
    SeatsUp to 10 — 1 owner plus 9 team
    Workspaces1
    AI credits2,000

    They keep the collaboration essentials: AI chat with Claro, AI reviews and approvals, the Chrome extension, the WordPress plugin, image and URL-based collaboration, annotations, page approvals, and attachments.

    Agency-side features are not included. A Website Owner account has no access to white labeling, analytics, workflows and automations, forms, multiple workspaces, Kanban boards, the shared email inbox, canned responses, time tracking, task tags, project stages, integrations, or the Atarim API.

    A client invite creates a Website Owner account and allocates AI credits to it from your agency’s own pool. Atarim describes it in the dialog as: “Invite a client to your agency and allocate credits from your pool. If they already have an Atarim account they can accept right away, otherwise they will be prompted to register first.”

    Before you start

    Check your credit balance first. You must keep at least 1,000 credits in reserve, and the smallest allocation you can make to a client is also 1,000 — so you need more than 1,000 credits available before the form will let you do anything. An agency sitting on exactly 1,000 credits cannot invite anyone.

    Sending the invite

  • From the Projects screen, select Add a Client.
  • The Invite a Client dialog opens.
  • In Email, enter the client’s address. This is the only required field.
  • In Name, enter the client’s business name — the placeholder shows the expected format, Client Co. Optional, up to 255 characters.
  • In Credits, set how many AI credits to allocate. Leave it blank to use the default of 2,000.
  • Select Send Invite.
  • Wait for the confirmation message reading Client invitation created.
  • Do not close the dialog yet. It stays open deliberately, showing a shareable redemption link — copy it before you dismiss the dialog.
  • Invite Client dialog showing the email, name and credits fields with Add Client button
    Set the AI credit allocation
    Note
    If the client already has an Atarim account they can accept immediately. If not, they are prompted to register first, then land in their own Website Owner account.
    Tip
    The Add Client button stays disabled until you have entered an email address, so if it looks unresponsive, check that field first.

    What’s included

    They keep the collaboration essentials: AI chat with Claro, AI reviews and approvals, the Chrome extension, the WordPress plugin, image and URL-based collaboration, image annotations, responsive mode, design versions, page approvals, attachments, and the ability to edit and delete their own comments.

    What’s not included

    Agency-side features are outside the plan. A Website Owner account has no access to white labeling, analytics and reporting, workflows and automations, forms, multiple workspaces, Kanban boards, the shared email inbox, canned responses, time tracking, task tags, project stages, integrations, activity logs, or the Atarim API.

    Some task-level features are also excluded, and these are the ones a client will notice first. Website Owners cannot set task status or priority, and don’t have the task inbox, internal tasks, notes, starred tasks, list view, task filters, or the Clarity Test.

    Website Owner Dashboard View
    Warning
    These are plan-level feature flags, not soft guidance. A Website Owner account genuinely cannot reach the User Permissions or Project Permissions screens regardless of what role their individual users hold — both are switched off at the plan level.
    Note
    Website Owner accounts are set up through the client flow rather than a workspace invite, so they do not appear in your internal team list. Their own users are managed inside their account, not yours.
    Recommendation
    Use a Website Owner account when a client needs an ongoing home for their sites and their own small team. Use a guest invite when someone needs to leave feedback on one project and nothing more. Choosing guest for a long-term client means re-inviting them for every project.

    FAQs

    How many roles are there?

    Five: Owner, Administrator, Team Member, Website Owner, and Collaborator.

    What’s the difference between Owner and Administrator?

    Owner is the workspace’s own account holder. Both reach every settings screen including billing, so day to day they behave the same way.

    Which roles can I assign when inviting someone?

    Administrator, Team Member, or Collaborator. Website Owner accounts are created through the client flow instead.

    Why does someone have more access on one project than another?

    Roles are resolved per site. If you own a site you’re treated as an Administrator on it; otherwise Atarim uses the role you hold on that specific site, falling back to Collaborator where none exists.

    Why does an export say “contributor” when the interface says Team Member?

    Team Member is stored internally as contributor. It’s the same role — only the label differs.

    Can I change someone’s role after inviting them?

    Yes, from the People screen, within the constraints of the account type they were invited under.

    Is a Clarity Test the same as Microsoft Clarity?

    No. A Clarity Test is an AI check that scores how clear a task’s wording is. Microsoft Clarity is a third-party heatmap tool that appears as the Heatmaps default in The Stack. Unrelated.

    Can a Website Owner see other clients in my workspace?

    No. Their account only ever shows their own users and projects.

    Can a Website Owner configure permissions themselves?

    No. Both User Permissions and Project Permissions are switched off at the plan level for Website Owner accounts.

    Do guests need an account?

    No. A guest invite is a link scoped to a single project, with no login required.

    Can I upgrade a guest to a full client account later?

    Not automatically. You’d set them up as a client separately, so it’s worth deciding which one they need up front.

    Conclusion

    Knowing which role someone holds tells you most of what they can see and do. The five roles cover both sides of the agency-client relationship, and the capability grid on top lets you adjust specific abilities without changing anyone's role.

    The one thing worth carrying away is the three-layer split. Role decides which screens exist for someone, workspace capabilities decide which controls appear inside them, and project access decides which projects they apply to at all. Almost every "why can't they do this?" question resolves once you know which of the three you're looking at.

    Tips & best practices

    Additional advice Assign Administrator sparingly — it carries billing access, not just full feature access Check the User Permissions grid directly rather than assuming defaults; any administrator can have changed them Decide between a Website Owner account and a guest link up front — there's no automatic upgrade path from one to the other Audit the People with Access list on long-running projects; guests rarely get removed once the work is done When someone reports missing access, identify the layer first — role, workspace capability, or project — before changing anything Remember that hidden isn't broken. Two people on the same workspace will see different sidebars, and that's by design Don't hunt the User Permissions grid for sidebar access — it doesn't control that layer

    Related articles