Skip to main content

Roles and permissions

Roles​

RoleScopeCan
Public fillerOne public formFill it in and submit it, with no account
MemberA teamSign in and fill the team's private forms
AdminA teamEverything a workspace administrator does: build forms, read submissions, send for signature, spend credit
OwnerA teamEverything an admin can, plus run the team itself
You, in your personal workspaceYour personal workspaceEverything an owner can, alone
CivicPort community adminA CivicPort community's workspaceEverything an admin can, for that community

Roles belong to a workspace. You can be the owner of one team, an admin of another and a member of a third. See workspaces.

What each role can do in a team​

ActionPublic fillerMemberAdminOwner
Fill a public formYesYesYesYes
Fill the team's private formsYesYesYes
See the team and its member listYesYesYes
See members' email addressesYesYes
Build, edit, publish and archive formsYesYes
Read submissionsYesYes
Reveal a sensitive field, with the reveal loggedYesYes
Send documents and submissions for signatureYesYes
Import a PDFYesYes
See the credit balance and its historyYesYes
Buy credit, and move it between workspaces they administerYesYes
See, rotate and switch off the member join codeYesYes
Invite people as membersYesYes
Remove membersYesYes
Set the team's brandingYesYes
See, rotate and switch off the admin join codeYes
Invite people as adminsYes
Remove adminsYes
Change anyone's roleYes
Transfer ownershipYes
Delete the teamYes
Leave the teamYesYesNo. Transfer ownership first

Details: teams, join codes, invites, members, branding, credits.

Being sent something to sign​

Anyone can be sent a document to sign, whether or not they have an account or belong to the workspace that sent it. It is not a role. See signatures.

Personal workspaces​

Everyone has a personal workspace, and nobody else can join it. You are its only administrator, so everything in the owner column applies to you there, except the parts about other people. Personal workspaces have no join codes, invites or branding.

CivicPort community admins​

If you administer a community in CivicPort, you administer that community's workspace in FormsUI too, with the same reach an admin has over a team.

  • CivicPort decides who is an admin. Forms does not keep its own list, so someone removed as an admin in CivicPort loses access in Forms as well.
  • The community's team is shown read-only in Forms, with no join codes, invites, role changes or removals. Manage admins in CivicPort.
  • The community's forms, submissions and credit belong to the community, not to any one admin.
  • The community is branded by its own settings in CivicPort, not by team branding.
  • Residents of the community can fill its private forms.

What nobody can do​

  • Remove a team's owner, or leave as owner. Ownership has to be transferred.
  • Have two owners. Ownership moves, it is never shared.
  • Move credit out of a workspace they do not administer, or into one.
  • Accept an invite addressed to a different email address.
  • Read a sensitive field without the reveal being logged.
  • Change a ledger entry. Entries are only ever added.