Roles and permissions
What owners, editors and viewers can do in a workspace, how a collaborator on a single form differs, and who can change plans and API keys.
Workspaces
Forms live in a workspace. When you sign up you get a personal workspace, and you can create more. Each workspace has its own members, forms, saved themes, question bank and plan. The workspace switcher at the top of the sidebar changes which one you are looking at. See Members and invitations for setting one up.
The three roles
Every member of a workspace has one role.
- Owner: manages people, settings and sharing, and can do everything an editor can.
- Editor: builds forms and works with responses.
- Viewer: reads forms and responses.
A workspace can have several owners, and it always has at least one.
What each role can do
| Action | Viewer | Editor | Owner |
|---|---|---|---|
| Open forms, read responses, export them | Yes | Yes | Yes |
| Open a form in the builder, read-only | Yes | Yes | Yes |
| Create, duplicate and edit forms | No | Yes | Yes |
| Preview, publish, restore versions | No | Yes | Yes |
| Change Settings: open and close, limits, notifications | No | Yes | Yes |
| Manage webhooks | No | Yes | Yes |
| Star, tag, grade and delete responses | No | Yes | Yes |
| Comment in the builder, use the question bank and saved themes | No | Yes | Yes |
| Read the Activity log | No | Yes | Yes |
| Custom link, password, results link on a form | No | No | Yes |
| Invite collaborators to one form | No | No | Yes |
| Move a form to the trash, restore it, delete it forever | No | No | Yes |
| Invite members, change roles, remove members | No | No | Yes |
| Rename or delete the workspace | No | No | Yes |
| Start a trial or change the plan | No | No | Yes |
Everyone can leave a workspace, except the last owner.
The Activity log also needs a plan that includes it; see Default plan limits.
A collaborator on one form
You can give someone access to a single form without adding them to the workspace. On the form's Share tab, People with access invites them as an Editor or a Viewer.
- They see only the forms they were given, not the rest of the workspace.
- They can never be an owner of that form, so they cannot change its link, password or sharing.
- If they are also a workspace member, they get whichever of the two roles is higher.
API keys and roles
An API key acts as the person who made it and can never do more than that person. A viewer's key is read-only even if it was created with write access, and viewers can only create read-only keys. A key only works inside the workspace it was made in. See API keys, requests and errors.
When a role changes
If an owner changes your role, it applies from your next request. If you are removed from a workspace, you lose access to its forms at once and the API keys you created there stop working. Role changes are recorded in the Activity log, described in Members, invitations and the activity log.
Why not everyone is an owner
The line is drawn where a mistake is hard to undo or affects other people: deleting a form with its responses, changing the public link that others have shared, or changing who else has access. Editors have room to build and run forms every day without those risks.
Updated Sep 30, 2026