Why roles matter
Microsoft Teams works on a simple idea. Not everyone in a team should be able to do everything. The person who created the team should not have the same powers as a contractor invited for a two week project. Roles are how Teams draws those lines.
Get roles right and your teams stay secure and easy to manage. Get them wrong, with every member set as an owner or guests given free rein, and you have built exactly the kind of sprawl and risk that is hard to unwind later. There are three core roles in every team: owner, member and guest. Here is what each one can actually do.
The three core roles
The manager
Owners run the team. They control who is in, what settings apply, and when the team retires. Every team needs at least one owner, and ideally two, so the team is never left stranded if one person leaves.
Owners can
- Add and remove members and guests
- Promote a member to owner, or step someone down
- Create, rename and delete channels
- Change team settings, picture and description
- Set channel level permissions, including who can post and who can mention everyone
- Manage apps, tabs and connectors
- Archive or delete the team
The participant
Members are the everyday users, the people doing the actual work in the team. They can collaborate fully but cannot reshape the team itself.
Members can
- Read and post messages in channels
- Create and edit files
- Add standard channels, if owners allow it
- Add apps and tabs, if owners allow it
- Mention the team or channel, if owners allow it
Members cannot add or remove other people, delete channels, or change team wide settings. Notice how much of what a member can do depends on whether owners allow it. That is the owner's settings panel at work.
The outsider
Guests are people from outside your organisation, such as a different company, a client or a partner, who have been invited into a specific team. They get a deliberately limited experience.
Guests can
- Participate in the channel conversations they are added to
- View and edit shared files
- Join meetings and chats within the team
Guests cannot
- See anything outside the teams they are invited to
- Access the global organisation directory
- Create teams
- Add or remove other members
Guest access must be turned on by an admin before anyone can invite one. It stays off limits until governance says otherwise.
Quick comparison
Here is how the three roles stack up side by side.
| Capability | Owner | Member | Guest |
|---|---|---|---|
| Post in channels | Yes | Yes | Yes |
| Create and edit files | Yes | Yes | Yes |
| Add or remove people | Yes | No | No |
| Create channels | Yes | Only if the owner allows it | No |
| Delete channels | Yes | No | No |
| Change team settings | Yes | No | No |
| Add apps and tabs | Yes | Only if the owner allows it | No |
| Archive or delete the team | Yes | No | No |
Rows marked "only if the owner allows it" depend on settings the team owner controls, not on the member role itself.
A layer deeper: channel level permissions
Roles apply to the whole team, but channels add their own nuances.
Standard channels
Open to everyone in the team. Owners can restrict posting, for example limiting an announcements channel to owners only.
Private channels
Open to a subset of the team's members. Private channels have their own owners and members, separate from the parent team. A team member who is not in the private channel cannot see it at all.
Shared channels
Let you collaborate with people outside the team, even outside your organisation, without making them guests of the whole team. They see only that one channel.
A person's real permissions are a combination of their team role and which channels they belong to. Knowing someone's role only tells you half the story.
Not sure your team's roles are set up correctly
Owners with too much reach, guests with more access than they should have, or channels nobody remembers the purpose of are common and easy to fix. We can review your team structure and tighten it up properly.
Book a session with MStack360