Roles and permissions
Roles
| Role | Scope | Can |
|---|---|---|
| Public filler | One public form | Fill it in and submit it, with no account |
| Member | A team | Sign in and fill the team's private forms |
| Admin | A team | Everything a workspace administrator does: build forms, read submissions, send for signature, spend credit |
| Owner | A team | Everything an admin can, plus run the team itself |
| You, in your personal workspace | Your personal workspace | Everything an owner can, alone |
| CivicPort community admin | A CivicPort community's workspace | Everything an admin can, for that community |
Roles belong to a workspace. You can be the owner of one team, an admin of another and a member of a third. See workspaces.
What each role can do in a team
| Action | Public filler | Member | Admin | Owner |
|---|---|---|---|---|
| Fill a public form | Yes | Yes | Yes | Yes |
| Fill the team's private forms | Yes | Yes | Yes | |
| See the team and its member list | Yes | Yes | Yes | |
| See members' email addresses | Yes | Yes | ||
| Build, edit, publish and archive forms | Yes | Yes | ||
| Read submissions | Yes | Yes | ||
| Reveal a sensitive field, with the reveal logged | Yes | Yes | ||
| Send documents and submissions for signature | Yes | Yes | ||
| Import a PDF | Yes | Yes | ||
| See the credit balance and its history | Yes | Yes | ||
| Buy credit, and move it between workspaces they administer | Yes | Yes | ||
| See, rotate and switch off the member join code | Yes | Yes | ||
| Invite people as members | Yes | Yes | ||
| Remove members | Yes | Yes | ||
| Set the team's branding | Yes | Yes | ||
| See, rotate and switch off the admin join code | Yes | |||
| Invite people as admins | Yes | |||
| Remove admins | Yes | |||
| Change anyone's role | Yes | |||
| Transfer ownership | Yes | |||
| Delete the team | Yes | |||
| Leave the team | Yes | Yes | No. Transfer ownership first |
Details: teams, join codes, invites, members, branding, credits.
Being sent something to sign
Anyone can be sent a document to sign, whether or not they have an account or belong to the workspace that sent it. It is not a role. See signatures.
Personal workspaces
Everyone has a personal workspace, and nobody else can join it. You are its only administrator, so everything in the owner column applies to you there, except the parts about other people. Personal workspaces have no join codes, invites or branding.
CivicPort community admins
If you administer a community in CivicPort, you administer that community's workspace in FormsUI too, with the same reach an admin has over a team.
- CivicPort decides who is an admin. Forms does not keep its own list, so someone removed as an admin in CivicPort loses access in Forms as well.
- The community's team is shown read-only in Forms, with no join codes, invites, role changes or removals. Manage admins in CivicPort.
- The community's forms, submissions and credit belong to the community, not to any one admin.
- The community is branded by its own settings in CivicPort, not by team branding.
- Residents of the community can fill its private forms.
What nobody can do
- Remove a team's owner, or leave as owner. Ownership has to be transferred.
- Have two owners. Ownership moves, it is never shared.
- Move credit out of a workspace they do not administer, or into one.
- Accept an invite addressed to a different email address.
- Read a sensitive field without the reveal being logged.
- Change a ledger entry. Entries are only ever added.