Formwork
Menu
Get started free Log in

Roles and permissions

What owners, editors and viewers can do in a workspace, how a collaborator on a single form differs, and who can change plans and API keys.

Workspaces

Forms live in a workspace. When you sign up you get a personal workspace, and you can create more. Each workspace has its own members, forms, saved themes, question bank and plan. The workspace switcher at the top of the sidebar changes which one you are looking at. See Members and invitations for setting one up.

The three roles

Every member of a workspace has one role.

  • Owner: manages people, settings and sharing, and can do everything an editor can.
  • Editor: builds forms and works with responses.
  • Viewer: reads forms and responses.

A workspace can have several owners, and it always has at least one.

What each role can do

ActionViewerEditorOwner
Open forms, read responses, export themYesYesYes
Open a form in the builder, read-onlyYesYesYes
Create, duplicate and edit formsNoYesYes
Preview, publish, restore versionsNoYesYes
Change Settings: open and close, limits, notificationsNoYesYes
Manage webhooksNoYesYes
Star, tag, grade and delete responsesNoYesYes
Comment in the builder, use the question bank and saved themesNoYesYes
Read the Activity logNoYesYes
Custom link, password, results link on a formNoNoYes
Invite collaborators to one formNoNoYes
Move a form to the trash, restore it, delete it foreverNoNoYes
Invite members, change roles, remove membersNoNoYes
Rename or delete the workspaceNoNoYes
Start a trial or change the planNoNoYes

Everyone can leave a workspace, except the last owner.

The Activity log also needs a plan that includes it; see Default plan limits.

A collaborator on one form

You can give someone access to a single form without adding them to the workspace. On the form's Share tab, People with access invites them as an Editor or a Viewer.

  • They see only the forms they were given, not the rest of the workspace.
  • They can never be an owner of that form, so they cannot change its link, password or sharing.
  • If they are also a workspace member, they get whichever of the two roles is higher.

API keys and roles

An API key acts as the person who made it and can never do more than that person. A viewer's key is read-only even if it was created with write access, and viewers can only create read-only keys. A key only works inside the workspace it was made in. See API keys, requests and errors.

When a role changes

If an owner changes your role, it applies from your next request. If you are removed from a workspace, you lose access to its forms at once and the API keys you created there stop working. Role changes are recorded in the Activity log, described in Members, invitations and the activity log.

Why not everyone is an owner

The line is drawn where a mistake is hard to undo or affects other people: deleting a form with its responses, changing the public link that others have shared, or changing who else has access. Editors have room to build and run forms every day without those risks.

Updated Sep 30, 2026