In HERAW, access control is managed through roles and permissions.
A role defines what a user can do inside a project: viewing content, uploading files, creating tasks, managing events, sharing casts, adding notes, downloading assets, and more.
From Enterprise plans, workspaces can create custom roles to match their organisation and workflows.
Default roles created automatically
Whenever a new workspace is created, HERAW automatically creates a set of default roles.
These roles provide a ready to use permission structure that covers most common collaboration workflows.
Custom roles (Enterprise)
Enterprise workspaces can create and manage their own roles to fit their internal organisation.
Custom roles can be configured using detailed permissions for:
Downloads
Casts and sharing
Files and folders
Notes and annotations
Tasks and workflow
Events and scheduling
Project management rights (Manage)
This makes it possible to build roles such as:
Legal reviewer
External agency contributor
Client approval only
Production manager
Restricted uploader
The Manage permission: full project and folder administration
Some roles can include a specific permission called Manage.
When Manage is enabled, the user can administrate the project structure and governance, including:
Managing project members (add, edit, remove)
Editing project settings
Updating the project name and status
Managing folder permissions and governance
Manage unlocks administration rights beyond operational collaboration permissions.
Permission levels explained
Each feature can be configured with different access levels:
Level | Meaning |
|---|---|
Disabled | The user cannot access the feature. |
Read | The user can view content, but cannot modify anything. |
Write | The user can create, edit, and update content. |
Manage | The user has full control, including advanced management actions. |
Default roles and permissions
Below are the default roles created in every workspace, with their permission levels.
Permission | Spectator | Reviewer | Contributor | Manager |
|---|---|---|---|---|
License | BASIC | BASIC | BASIC | STANDARD |
Manage | ❌ | ❌ | ❌ | ✅ |
Download | Disabled | All | All | All |
Casts | Disabled | Disabled | Disabled | Manage |
Files | Read | Read | Write | Manage |
Notes | Disabled | Write | Write | Manage |
Tasks | Disabled | Write | Write | Manage |
Events | Read | Read | Write | Manage |
Best practices
✅ Use Spectator for stakeholders who only need visibility
✅ Use Reviewer for validation and feedback workflows
✅ Use Contributor for daily production collaborators
✅ Use Manager for project owners and administrators
For Enterprise organisations, creating custom roles is recommended to reflect internal departments and approval workflows.




