
Canvas permissions
Set Project access or Private, understand owner and assignee roles, and choose view, comment, or edit access.
Use Canvas permissions to decide who can enter a canvas and what each person can do after entry. For a canvas inside a project, choose Project access when the project audience should have access, or Private when access should stay with the canvas's own members.
Choose Project access or Private
Open the visibility control in the canvas header, then choose the scope that fits the work.
| Scope | What it does | Use it for |
|---|---|---|
| Project access | Gives the owning project's members access to the canvas. | Working canvases that should follow the project team. |
| Private | Removes access inherited from the project and keeps explicitly authorized canvas access. | Restricted drafts, sensitive reviews, or a smaller working group. |
Changing a parent canvas also applies the visibility setting to its descendant canvases. Check the whole canvas tree before tightening or widening access.
When a private canvas returns to Project access, existing viewers and commenters keep their permission, and previous project access is restored where ALLO retained it. The change does not forcibly upgrade everyone to edit.
Know who can change the scope
The person changing canvas privacy must be a member of the canvas's workspace. They must also be one of these:
- The canvas owner
- The owner of the project that contains the canvas
- A workspace administrator
The assignee is the person responsible for the work, but assignment alone does not grant the authority to change canvas privacy. Ownership and assignment solve different problems.
Choose what each member can do
Access scope decides who can enter through the project. Member roles decide what a person can do inside the canvas.
| Permission | Choose it when |
|---|---|
| View | Someone needs to read, inspect, or present the canvas. |
| Comment | Someone should leave feedback and replies without changing canvas content. |
| Edit | Someone should create, move, delete, upload, or format canvas content. |
For named collaborators, manage these roles in Canvas members. Give reviewers comment access unless they need to change the work itself.
Handle unassigned canvases
A canvas without an owning project has no project audience to inherit. ALLO therefore does not show the Project access picker for an unassigned canvas. Use direct invitations or a share link to give people access, or move the canvas into a project before using project-based scope.
Remember the independent access paths
Changing a canvas to Private manages project-inherited access. Direct invitations and share-link access are separate paths and can remain active. A private page, object, comment, or chat link only points an already-authorized person to a location; it does not grant access. See Private links and share links for that distinction.
If the goal is to remove someone completely, review the canvas member list, direct invitations, and active share links as well as the project scope.
When to make a canvas private
Use Private when the project audience should not inherit access. Common examples include a draft that is not ready for the project team, confidential preparation before a meeting, and a review limited to a smaller group.
Private keeps explicitly authorized canvas access. Invite the intended people directly, then review active share links. A person with direct membership or an active share link may still enter after project access is removed.
Private or a Canvas PIN?
| Choose | When it fits | What to remember |
|---|---|---|
| Private | The project team should not inherit access. | Direct members and share links remain separate access paths. |
| Canvas PIN | People already have access, but content should open only after they receive a 4-digit PIN. | Knowing the PIN does not grant access or change a person's role. |
| Both | A small invited group needs access and an extra entry check. | Invite the group, review links, and send the PIN separately. |
For a scheduled class or workshop, a Canvas PIN lets you share the link early and reveal the PIN when the session begins. For a confidential draft, start with Private so project members do not inherit access.
When the result looks wrong
The visibility control is missing. Confirm that the canvas belongs to a real project. An unassigned canvas has no project visibility choice, and workspace-managed restrictions can also remove the control.
A project member cannot open a private canvas. Add them directly to the canvas, or switch to Project access if the whole project should enter.
Someone still opens a private canvas. Check direct membership and share-link access. Privacy does not cancel those independent routes.
A viewer or commenter kept the same role after Project access returned. That is expected when ALLO restores the person's preserved permission.
Related guides
- Share a canvas
- Manage Canvas members
- Private links and share links in Canvas
- Public and private projects