Understanding user roles & permissions
How access works in eTool — your personal account, organisation membership, and project access.
Before you begin
This article is for anyone who uses eTool: new users getting oriented, Organisation Admins setting things up, and teams evaluating how access works before subscribing.
eTool access works across three layers:
- Your personal eTool account — your individual login and personal workspace.
- Organisation access — whether your account belongs to an organisation, and what organisation-level access you have.
- Project access — which projects you can access, and what you can do within them.
This article explains how these layers work together. For the detailed rules and actions within each layer, see the related articles linked throughout.
Jump to the following sections in this post:
- Before you begin
- The eTool access model
- Your eTool account
- Organisation access
- Project access
- How access layers work together
- Where to go next
- Related articles
The eTool access model
Think of access in eTool as a set of layers:
Personal account → Organisation membership → Project access (including your role and permissions within a project)
Each layer controls something different, and having access at one layer doesn't automatically grant access at the next. For example:
- Having an eTool account doesn't automatically add you to an organisation.
- Belonging to an organisation doesn't automatically give you access to every project.
- Having access to a project doesn't necessarily mean you can edit it.
Your eTool account
Every eTool user has a personal account. This is what gets you your own Home dashboard, showing your own projects and activity, and it exists regardless of which plan you're on.
Your personal account exists independently of any organisation you belong to. A user can belong to multiple organisations while still maintaining a single personal account.
Organisation access
An organisation is a shared workspace where teams manage users, projects, settings, and organisation-level features. To work within an organisation, your personal account must first be added as a member of that organisation.
Within an organisation, there are two organisation-level roles:
Organisation Admin — manages the organisation itself: users and seats, the subscription, organisation settings and branding, security settings and integrations. An Organisation Admin can also manage Collaborators on any project assigned to the organisation, not just their own — this is the one place organisation-level and project-level access overlap. See Setting up your eTool organisation for the full list of what an Admin manages.
Everyone else — every other organisation member holds a seat (Specialist, Hotseat, or Read-only). A seat lets someone belong to the organisation, but on its own it doesn't grant access to any specific project. See Managing users & seats for more information.
Project access
Important: organisation access and project access are separate. Being a member of an organisation doesn't automatically give you access to the projects within it.
By default, every user starts every project as Not Involved — this is deliberate, since project data can be commercially sensitive, so access has to be explicitly granted rather than assumed.
Project access is managed at the Structure level, meaning permissions can be controlled for different parts of a project. From there, people can be assigned one of the following roles:
- Read Only — can view project information and run reports, but cannot make changes.
- Collaborator — can edit, and can submit the design for certification.
- Lead Author — one per Structure; also edits and can submit for certification, and is the role that gets reassigned when responsibility for a project changes hands.
Both Organisation Admins and Lead Authors can add Collaborators to a project — it isn't only an Admin's job.
See Project roles: Lead Author & Collaborators for the full detail, including what happens when a Lead Author changes.
How access layers work together {#}
Access issues often happen because these layers get confused. For example, a user may have an eTool account, belong to the organisation, and hold an active seat — but still not be able to open a project, because they haven't been added to that specific project.
Similarly, a user may be added to a project but only have read-only access, because their project role or seat status doesn't allow editing — for example, a Lead Author who hasn't requested Session Access for that session (see Managing users & seats).
Understanding which layer controls which type of access is the key to troubleshooting permissions in eTool. See Troubleshooting project access for common scenarios and fixes.
Where to go next
| If you want to... | Go to... |
|---|---|
| Add, remove, or reassign users and seats | Managing users & seats |
| Understand what Lead Authors and Collaborators can do | Project roles: Lead Author & Collaborators |
| Fix a project access issue | Troubleshooting project access |
| Understand organisation-level administration | Setting up your eTool organisation |
Related articles
- Managing users & seats
- Project roles: Lead Author & Collaborators
- Troubleshooting project access
- Setting up your eTool organisation