Member roles
Manage organisation membership and assigned roles.
Feature
Control organisation, project, document, and portal access, then choose the organisation authentication method that fits your identity environment.
How it works
Configure the structure once, then use it where the work happens.
Assign organisation roles, groups, titles, and profile details.
Set explicit member permissions for the project.
Map OIDC attributes to organisation identity fields.
Capabilities
These capabilities are implemented in the current TOW product.
Manage organisation membership and assigned roles.
Apply explicit member permissions.
Restrict a document to named members and teams.
Start with Microsoft Entra ID, Okta, Google Workspace, Active Directory, or generic SAML and OIDC.
Control point
Where AI is enabled, accessible context and review-oriented flows apply to the surrounding workspace rather than bypassing its controls.
Deployment and security
Use TOW Cloud, run TOW on controlled infrastructure, or operate an air-gapped Docker Compose deployment. Permissions, identity settings, exports, and AI provider choices stay visible to administrators.
Explore self-hostingFAQ
Current product, deployment, and commercial boundaries.
Yes. Member roles, Project access, Document access, Authentication methods are part of the current product surface and are backed by the linked implementation evidence.
Yes. The capability is available within the TOW application in a configured self-hosted deployment.
See TOW in your environment