Skip to main content
Skip table of contents

Rights and Roles Overview

📄 Summary: What You’ll Learn in This Article

This article provides an overview of rights and roles in MARMIND, explains how permissions inherit within the object tree, and shows how to view and adjust a user’s permissions in the Teams module.

  • Roles and permissions overview

  • Permission inheritance explained

  • Adjust rights in Teams module


🧑‍🤝‍🧑 Who Should Read This?

This article is most useful for:

  • Marmind administrators who manage user permissions.


✔️ Prerequisites: What Should You Know Before Getting Started?

Level: Easy

Access required: Admin rights

  • Basic knowledge about the object tree and the teams module is required.


Rights and Roles by default

In Marmind, you can customize rights and roles for each object to fit your company’s needs.

Main roles

The following rights and roles are provided by Marmind by default:

Role / Category

Rights

Description

Comment

Super Admin

admin + see description

  • Administration of users

  • Management of workflow definitions

  • Management of workflow groups

  • Management of jobs

  • Import actual costs

  • Management of news

Role can only be set manually via database and is not visible in the User Interface.

Administrator

Full control

✅ read, create, edit, delete

Management of master data / settings

  • Everything under settings/administration

  • right only applicable to root folder

  • Implicitly requires Moderator / Contributor role

Moderator

Most actions

✅ read, create, edit

⚠️ limited delete

  • Granting permissions within the MARMIND structure

  • All rights in the MARMIND tree structure

  • Implicitly requires Contributor role

Contributor

Work access

✅ read, create, edit

❌ no delete

  • Role that fits for regular users

Guest

View only

✅ read

❌ no changes

  • Read rights of all objects except to-dos.

  • Collaboration rights can be activated for guest users.

Collaboration rights

Type

Description

Comment

Assets

  • See assets

  • Upload/edit assets

  • Download assets

  • Delete assets

Starting from Guest role

To-dos

  • See to-dos

  • Create to-dos

  • Edit to-dos (without responsibility)

  • Delete to-dos

Starting from Guest role

Budget & Expenses Rights

Action

Description

Comment

see

  • read budgets

  • read estimated costs

  • read costs

  • read imported costs

Implicitly requires Contributor role + “see” rights.

edit

  • Plan budget

  • allocate estimated costs

  • enter costs

  • edit imported costs

Implicitly requires Contributor role + “see” rights.

  • Allocate Estimated Costs:
    Editing is only possible if the attribute “Forecast transfer to estimated costs” has not been activated under “Budget & Costs” when managing the planning areas.
    This allows the transfer of forecast data to estimated costs (estimated costs can no longer be changed directly).

  • Edit actuals:
    Editing is only possible if actuals are marked as “editable” in the finance area. Tags and Special Projects can also be edited without being able to edit the actual value itself.

approve

Give approval

Required for budget approval; implicitly requires the participant / moderator role.

Marketing Objects Rights

Action

Description

Comment

delete

Delete workspaces, campaigns, projects, actions, and work packages

Starting from Contributor role.

edit

Edit workspace

Starting from Contributor role.

Core Concept

Marmind security works like a folder tree with permissions that flow downward and can expand at deeper levels.

CODE
Marketing Folder (You: ReadOnly)
  ├── Active Campaigns (You: Contributor) ← EXPANDED
  │   └── Q1 Launch (You: Moderator) ← EXPANDED AGAIN
  └── Archive (You: ReadOnly) ← INHERITED

Key Rule: Permissions can increase as you go deeper, but never decrease.

What You CAN Do

Start permissions at any level (no need to grant from root)

CODE
Company Root (no access)
  └── Sales Dept (Team: "Sales" → Contributor) ← START HERE
      └── Q1 Campaigns (auto-inherit Contributor)

Expand permissions deeper

CODE
Marketing (Team: "Junior" → ReadOnly)
  └── Active Projects (Team: "Junior" → Contributor) ← EXPANDED

Different teams, different permissions

CODE
Campaign Folder
  ├── Team: "Designers" → Contributor
  ├── Team: "Managers" → Administrator
  └── Team: "Vendors" → ReadOnly

Separate read from write/delete

  • Budget readers can view financials without editing

  • Contributors can edit but not delete

  • Specific "Deleter" roles required for deletion


What You CANNOT Do

Restrict at lower levels

CODE
Marketing (Team: "Sarah" → Contributor)
  └── Archive (try to make ReadOnly) ← IMPOSSIBLE

Once Sarah has Contributor, she has it everywhere below.

Hide items from team members (in new features)

CODE
Folder (Team: "Everyone" → Contributor)
  └── My Private Item ← Everyone can still see it

Privacy requires separate folders, not item flags.

Filter by "show only mine" (security level)

  • "My items" views are UI filtering, not security

  • If you can read the folder, you can read all items


Teams Module

You can find the authorizations by clicking on the object and the “Team” module:

User authorization in module.jpg

Seeing user authorizations in your object

A user’s permissions are visible in the overview under their name.

When you click on the user, you get a more detailed view on their permissions and you are able to change them by checking the box next to the permission. Scroll down to see all possible permissions:

User Roles and Rights (1).jpg

Detailed view of user permissions


❓ FAQs

What is the difference between the main roles (Super Admin, Administrator, Moderator, Contributor, Guest) in Marmind?

Each role has specific permissions:

  • Super Admin: Full access to all settings and data.

  • Administrator: Can manage users, settings, and most content.

  • Moderator: Can manage content but not system settings or users.

  • Contributor: Can create and edit content within assigned areas.

  • Guest: Has limited, mostly read-only access.

How do permissions flow and inherit through the folder structure in Marmind?

Permissions are inherited from parent folders to subfolders and items. If you set permissions at a higher level, all nested items will automatically receive those permissions unless specifically overridden.

How can I view and change a user's permissions using the Teams module?

Go to the Teams module, select the relevant team or user, and review their assigned roles and permissions. You can adjust permissions directly from this interface to grant or restrict access as needed.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.