Definition: Taskade security keeps your data private and your team in control. Role-based access gives every person exactly the permissions their job needs, encryption protects data in transit and at rest, and password protection plus audit trails guard anything you share. The result: the right people see the right things, and nobody sees more.
TL;DR: Taskade security runs on a 7-tier role-based access model: Owner, Maintainer, Editor, Commenter, Collaborator, Participant, Viewer. Higher roles inherit lower ones, so you grant the lightest permission that does the job. Pair it with password protection on shared links and encryption everywhere. Build a secure workspace free.
You already know who should see what. You do a version of this every time you BCC one person, lock a spreadsheet tab, or send a read-only link instead of an editable one. Role-based access turns that instinct into a setting you apply once, and it holds across every project, folder, and shared link.
What is role-based access in Taskade?
Role-based access means each teammate gets one of seven permission levels, and that level decides what they can do. Owner and Maintainer run the workspace, Editor and Commenter cover most contributors, and the lower three fit guests, voters, and read-only stakeholders. Pick the lightest role that lets someone do their job, and your workspace stays both secure and predictable.
Roles are the backbone of Taskade security. Encryption protects the data, but roles decide who can touch it. The two work together: a Viewer can read a project but never edit it, a Collaborator can run agents but never invite members, and only an Owner can manage billing or delete the workspace.
The 7 roles, top to bottom
Higher roles inherit everything below them, so a Maintainer can do everything an Editor can, plus invite and manage people. Read the table top to bottom and assign the lowest role that still lets each person finish their work.
| Role | What they can do | Best fit |
|---|---|---|
| Owner | Manage billing, transfer ownership, delete the workspace, full editing | Workspace founder, account holder |
| Maintainer | Invite or remove members, manage roles below them, full editing | Day-to-day workspace lead |
| Editor | Create, edit, and delete projects; run agents and automations; publish a Taskade Genesis app | Most teammates contributing daily |
| Commenter | Read everything, leave comments and suggestions, no direct edits | Reviewers and stakeholders giving feedback |
| Collaborator | Run agents and automations on shared projects, complete tasks, comment | Contractors and partners with scoped access |
| Participant | Complete assigned tasks, interact with checklists, comment | Voters, audience members, light contributors |
| Viewer | Read-only access | Observers and audit-only stakeholders |
People outside your workspace are never assigned a role. They reach a single project through per-project sharing or password protection instead, so a guest can join one project without seeing your billing, members, or anything else.
Who can do what
The permission ladder is strict: every role inherits the rights of the role beneath it and adds a few of its own. The diagram below reads top to bottom. Find the action you care about, then grant the lowest role that reaches it.
This action grid is the same picture in table form. Read down a column to see one role's full reach, or across a row to find the lowest role that allows an action.
| Action | Owner | Maintainer | Editor | Commenter | Collaborator | Participant | Viewer |
|---|---|---|---|---|---|---|---|
| View a project | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Comment | Yes | Yes | Yes | Yes | Yes | Yes | No |
| Complete an assigned task | Yes | Yes | Yes | No | Yes | Yes | No |
| Edit any task | Yes | Yes | Yes | No | No | No | No |
| Create a project | Yes | Yes | Yes | No | No | No | No |
| Run agents and automations | Yes | Yes | Yes | No | Yes | No | No |
| Publish a Taskade Genesis app | Yes | Yes | Yes | No | No | No | No |
| Invite a member | Yes | Yes | No | No | No | No | No |
| Manage billing | Yes | No | No | No | No | No | No |
| Delete the workspace | Yes | No | No | No | No | No | No |
There is no "Admin" role. Maintainer is the closest equivalent. If a teammate asks for admin access, give them Maintainer. For the full cascade across workspace, folder, and project, see User Roles & Permissions.
Set roles in the Members panel
Change a role in two clicks from the Members panel. The change takes effect immediately, and the member sees their new permissions on the next page load. Lowering a role is just as instant, so a demoted Collaborator loses edit rights right away.
┌──────────────────────────────────────────────┐
│ Members · Acme Operations │
├──────────────────────────────────────────────┤
│ Jordan R. Owner ▾ (you) │
│ Priya N. Maintainer ▾ │
│ Marco D. Editor ▾ │
│ Sam K. Commenter ▾ │
│ Contractor Collaborator ▾ single project │
│ Audience Participant ▾ form responders │
│ Auditor Viewer ▾ read-only │
└──────────────────────────────────────────────┘
▾ = click to change role • takes effect instantly
Set a project-level override when the workspace role is too tight or too loose. The workspace role is the floor, and the project role applies only inside that one project. A workspace Viewer can be promoted to Collaborator on a single project they help with, and a workspace Collaborator can be locked to read-only on a sensitive one.
How encryption and privacy controls work
Taskade encrypts your data in transit and at rest, and the people in your workspace decide who can read it. Encryption is the lock on the door, role-based access is the guest list, and password protection is the second lock you add to anything you share publicly.
- Encryption in transit and at rest keeps data protected as it moves and while it is stored.
- Workspace isolation keeps each workspace separate, so data never bleeds between organizations.
- Data ownership and export stay with you: export your data for migration or backup at any time, and remove it on request.
- Audit trails log who did what, so you can review access and changes after the fact.
- Password protection adds a passphrase gate on shared links for projects, agents, forms, and automations. See Password Protection for the full setup.
Security for AI agents and automations
AI in Taskade runs inside the same permission model as everything else. Agents and automation workflows only act on projects the assigning role can reach, so a Collaborator's agent never touches data that the Collaborator cannot see. Reliable automation workflows execute with the same scoped access, and outbound connections to outside services run securely.
When you publish a Taskade Genesis app, secrets matter. Saved API keys power 100+ bidirectional integrations but are never exposed to the people who use your app, and a pre-publish check flags any key that would leak. End users sign in with built-in email logins, and Business plans and above add custom domains with automatic SSL plus enterprise sign-on. App users see your app, never your workspace, billing, or other projects.
How plans extend security
Every plan includes role-based access, encryption, and password protection. Higher plans add controls that larger teams need. Custom domains with automatic SSL and built-in end-user logins start on Business; single sign-on is an Enterprise control.
| Capability | Where it starts |
|---|---|
| 7-tier role-based access | Every plan, including Free |
| Password protection on shared links | Every plan |
| Custom domains with automatic SSL | Business and above |
| Built-in end-user logins for Taskade Genesis apps | Business and above |
| Single sign-on (SSO) | Enterprise |
See the full pricing breakdown for what each tier includes.
Frequently asked questions
Does Taskade have an Admin role?
No. Taskade uses a 7-tier model, and Maintainer is the closest equivalent to admin. If a teammate asks for admin access, assign Maintainer. It can invite members, manage roles below it, and edit every project, which covers almost everything people mean by "admin."
How do role-based permissions work across workspace, folder, and project?
The workspace role is the floor. A folder or project can override it for a single space, either tighter or looser. A workspace Viewer can be promoted to Collaborator on one project, and a Collaborator can be locked to read-only on a sensitive one. See User Roles & Permissions.
Can people outside my workspace see my data?
Only what you deliberately share. Non-members are never assigned a workspace role. They reach a single project through per-project sharing or a password-protected link, and they never see your billing, members, or other projects. Add password protection for an extra gate.
Is my data encrypted?
Yes. Taskade encrypts data in transit and at rest, isolates each workspace, and keeps audit trails of access and changes. You own your data, can export it for backup or migration, and can request its removal.
How do AI agents and automations stay secure?
Agents and automation workflows inherit the permissions of the role that runs them, so they only touch projects that role can reach. In published Taskade Genesis apps, saved API keys stay private and a pre-publish check flags any secret that would leak.
Which security features come with paid plans?
Every plan includes role-based access, encryption, and password protection. Business and above add custom domains with automatic SSL and built-in end-user logins, while single sign-on is an Enterprise control.
Build it in Taskade: a secure client portal
Picture a member portal you can hand to clients without worrying about who sees what. You describe it to Taskade Genesis in plain English, and it builds a live app: clients sign in with their own email, each sees only their own records, and your team works behind the scenes at Editor or Maintainer level. A password-protected link covers anyone you invite for a one-off review, and a reliable automation emails an update the moment a status changes. Owners hold billing and deletion, Viewers get read-only audit access, and nobody ever sees a permission they were not granted. Start building a secure portal free.
Related concepts: Password Protection · Security & Sharing · Workspaces · Roles and Permissions · Taskade Genesis Auth · Custom Domains
