> For the complete documentation index, see [llms.txt](https://docs.terrakube.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.terrakube.io/user-guide/projects/team-access.md).

# Team Access

Project-level team access lets you grant a team a specific role that applies to all workspaces within the project. This avoids having to configure permissions on each workspace individually.

### Permission Hierarchy

Permissions follow a three-tier hierarchy. The most permissive level takes precedence:

1. **Organization** — organization-level team permissions (Manage Workspaces, etc.)
2. **Project** — project-level role assigned on the Teams tab
3. **Workspace** — future workspace-level overrides

{% hint style="info" %}
Workspaces that are not assigned to any project remain visible to all members of the organization (backward-compatible behavior).
{% endhint %}

### Project Roles

| Role  | Manage Project | Manage Workspace | Create Workspace | Plan Job | Approve Job |
| ----- | :------------: | :--------------: | :--------------: | :------: | :---------: |
| Admin |        ✅       |         ✅        |         ✅        |     ✅    |      ✅      |
| Write |        ❌       |         ✅        |         ✅        |     ✅    |      ✅      |
| Plan  |        ❌       |         ❌        |         ❌        |     ✅    |      ❌      |
| Read  |        ❌       |         ❌        |         ❌        |     ❌    |      ❌      |

### Adding a Team

Open the project and click the **Teams** tab.

<figure><img src="/files/IL3D8NURR1NUBVQ3uXth" alt=""><figcaption></figcaption></figure>

Select a team from the dropdown, choose a role, and click **Add Team**.

<figure><img src="/files/DWnL4vunm7iDbCmVgCZW" alt=""><figcaption></figcaption></figure>

The team will appear in the access table and the selected role will be applied to all workspaces in the project.

### Changing a Team's Role

In the Team Access table, click the **Change** button on the row of the team you want to update. Select the new role from the dropdown.

<figure><img src="/files/oCWhYRO5AWIOHW9Cso8N" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Hover over a role tag in the table to see a description of what the role allows.
{% endhint %}

### Removing a Team

Click the **Remove** button on the team's row in the Team Access table to revoke the team's access to the project.

<figure><img src="/files/f3FV5tQuU8cgRpspbMI7" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.terrakube.io/user-guide/projects/team-access.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
