Definition: Taskade security keeps your data private and your team in control. Role-based access gives every person exactly the permissions their job needs, encryption protects data in transit and at rest, and password protection plus audit trails guard anything you share. The result: each person gets the access you granted, and you can test that access yourself before you share anything real.
TL;DR: Taskade security runs on role-based access from Owner to Viewer. Every level of access inherits the one below it, so you grant the lightest permission that does the job. Pair it with password protection on shared links and encryption everywhere. Build a secure workspace free.
You already know who should see what. You do a version of this every time you BCC one person, lock a spreadsheet tab, or send a read-only link instead of an editable one. Role-based access turns that instinct into a setting you apply once, and it holds across every project, folder, and shared link.
What is role-based access in Taskade?
Role-based access means each teammate holds one level of access, and that level decides what they can do. The top of the ladder runs the workspace and holds billing, the middle covers everyone who creates and edits every day, and the bottom fits guests, voters, and review-only stakeholders. Pick the lightest access that lets someone do their job, and your workspace stays both secure and predictable.
Roles are the backbone of Taskade security. Encryption protects the data, but roles decide who can touch it. The two work together: a Viewer can read a project but never edit it, someone with task-level access can complete assigned work but never restructure it, and only the Owner can transfer ownership or delete the workspace.
What each level of access can do
Every level inherits everything below it, so a level that manages people can also do everything a daily contributor can. Read the table top to bottom and grant the lightest access that still lets each person finish their work.
| Level of access | What it can do | Best fit |
|---|---|---|
| Owner | Manage billing, transfer ownership, delete the workspace, edit everything | Workspace founder, account holder |
| Workspace management | Manage billing, invite or remove members, change the access of everyone below, edit everything | Day-to-day workspace lead |
| Project editing | Create and edit projects, invite teammates, run agents and automations, publish a Taskade Genesis app | Most teammates contributing daily |
| Assigned work | Complete assigned tasks, tick checklists, comment | Voters, light contributors, task owners |
| Viewer | Read projects and leave comments | Observers and review-only stakeholders |
People outside your workspace are never assigned a level of workspace access. They reach a single project through per-project sharing or password protection instead, so a guest can join one project without seeing your billing, members, or anything else.
Who can do what
The permission ladder is strict: every level inherits the rights of the level beneath it and adds a few of its own. The diagram below reads top to bottom. Find the action you care about, then grant the lightest access that reaches it.
This action grid is the same picture in table form. Find the action you care about in the left column, then grant the access named beside it. Everything above that level can do it too.
| Action | The lightest access that allows it |
|---|---|
| Read a project and leave a comment | Viewer |
| Complete an assigned task or tick a checklist | Assigned work |
| Edit any task | Project editing |
| Create a project | Project editing |
| Run agents and automations | Project editing |
| Publish a Taskade Genesis app | Project editing |
| Invite a teammate | Project editing |
| Delete a project | Workspace management |
| Remove a member and manage billing | Workspace management |
| Transfer ownership or delete the workspace | Owner |
When a teammate asks for administrator access, grant the workspace-management level. It invites and removes people, changes the access of everyone beneath it, manages billing, and edits every project, while ownership transfer and workspace deletion stay with the Owner. For the full cascade across workspace, folder, and project, see User Roles & Permissions.
Set access in the Members panel
Change a level of access in two clicks from the Members panel. The change takes effect immediately, and the member sees their new permissions on the next page load. Lowering access is just as instant, so a demoted teammate loses edit rights right away.
┌─────────────────────────────────────────────────┐
│ Members · Acme Operations │
├─────────────────────────────────────────────────┤
│ Jordan R. Owner ▾ (you) │
│ Priya N. Manages people ▾ │
│ Marco D. Edits projects ▾ │
│ Audience Assigned tasks ▾ form responders │
│ Auditor Viewer ▾ read-only │
└─────────────────────────────────────────────────┘
▾ = click to change access • takes effect instantly
Set a project-level role when one project needs different access from the rest of the workspace. The workspace role is the inherited default, and a project role applies only inside that one project. A workspace Viewer can be given editing access on a single project they help with. A project role adds access rather than taking it away, so keep anything a member should not reach in a team folder they are not part of — folders are private by default.
How encryption and privacy controls work
Taskade encrypts your data in transit and at rest, and the people in your workspace decide who can read it. Encryption is the lock on the door, role-based access is the guest list, and password protection is the second lock you add to anything you share publicly.
- Encryption in transit and at rest keeps data protected as it moves and while it is stored.
- Workspace isolation keeps each workspace separate, so data never bleeds between organizations.
- Data ownership and export stay with you: export your data for migration or backup at any time, and remove it on request.
- Audit trails log who did what, so you can review access and changes after the fact.
- Password protection adds a passphrase gate on shared links for projects, agents, forms, and automations. See Password Protection for the full setup.
Security for AI agents and automations
AI in Taskade runs inside the same permission model as everything else. Agents and automation workflows only act on projects the assigning role can reach, so an agent run at task level never touches data that person cannot see. Reliable automation workflows execute with the same scoped access, and outbound connections to outside services run securely.
When you publish a Taskade Genesis app, secrets matter. Saved API keys power 100+ bidirectional integrations but are never exposed to the people who use your app, and a pre-publish check flags any key that would leak. End users sign in with built-in email logins, and Business plans and above add custom domains with automatic SSL plus enterprise sign-on. App users see your app, never your workspace, billing, or other projects.
How plans extend security
Every plan includes role-based access, encryption, password protection, and built-in end-user logins for published apps. Higher plans add controls that larger teams need. Custom domains with automatic SSL and SAML single sign-on both start on Business; SCIM user provisioning is an Enterprise control.
| Capability | Where it starts |
|---|---|
| Role-based access from Owner to Viewer | Every plan, including Free |
| Password protection on shared links | Every plan |
| Custom domains with automatic SSL | Business and above |
| Built-in end-user logins for Taskade Genesis apps | Every plan, including Free |
| SAML single sign-on (SSO) | Business and above |
| SCIM user provisioning | Enterprise |
See the full pricing breakdown for what each tier includes.
Frequently asked questions
Who can manage members and billing in Taskade?
The Owner holds billing, ownership transfer, and workspace deletion. The level directly below the Owner covers everything people usually mean by administrator access: it invites and removes people, changes the access of everyone beneath it, manages billing, and edits every project. Grant that level to whoever runs the workspace day to day.
How do role-based permissions work across workspace, folder, and project?
The workspace role is the inherited default. A folder or project can give someone a different role inside that one space, and that role applies only there. A workspace Viewer can be given editing access on one project. Access granted lower down adds to the workspace role rather than removing it, so restrict a space by keeping it in a team folder the person is not part of — folders are private by default. See User Roles & Permissions.
Can people outside my workspace see my data?
Only what you deliberately share. Non-members are never assigned a workspace role. They reach a single project through per-project sharing or a password-protected link, and they never see your billing, members, or other projects. Add password protection for an extra gate.
Is my data encrypted?
Yes. Taskade encrypts data in transit and at rest, isolates each workspace, and keeps audit trails of access and changes. You own your data, can export it for backup or migration, and can request its removal.
How do AI agents and automations stay secure?
Agents and automation workflows inherit the permissions of the role that runs them, so they only touch projects that role can reach. In published Taskade Genesis apps, saved API keys stay private and a pre-publish check flags any secret that would leak.
Which security features come with paid plans?
Every plan includes role-based access, encryption, password protection, and built-in end-user logins for published apps. Business and above add custom domains with automatic SSL and SAML single sign-on, while SCIM user provisioning is an Enterprise control.
Build it in Taskade: a secure client portal
Picture a member portal you can hand to clients without worrying about who sees what. You describe it to Taskade Genesis in plain English, and it builds a live app: clients sign in with their own email, you match each client's records to that sign-in so they open their own, and your team works behind the scenes with full editing access. Test a second client account, and one that matches nothing, before you publish real data. A password-protected link covers anyone you invite for a one-off review, and a reliable automation emails an update the moment a status changes. Owners hold billing and deletion, and Viewers get read-only audit access inside the workspace. Start building a secure portal free.
Related concepts: Password Protection · Security & Sharing · Workspaces · Roles and Permissions · Taskade Genesis Auth · Custom Domains