Canvas permissions

Set Project access or Private, understand owner and assignee roles, and choose view, comment, or edit access.

Use Canvas permissions to decide who can enter a canvas and what each person can do after entry. For a canvas inside a project, choose Project access when the project audience should have access, or Private when access should stay with the canvas's own members.

Choose Project access or Private

Open the visibility control in the canvas header, then choose the scope that fits the work.

ScopeWhat it doesUse it for
Project accessGives the owning project's members access to the canvas.Working canvases that should follow the project team.
PrivateRemoves access inherited from the project and keeps explicitly authorized canvas access.Restricted drafts, sensitive reviews, or a smaller working group.

Changing a parent canvas also applies the visibility setting to its descendant canvases. Check the whole canvas tree before tightening or widening access.

When a private canvas returns to Project access, existing viewers and commenters keep their permission, and previous project access is restored where ALLO retained it. The change does not forcibly upgrade everyone to edit.

Know who can change the scope

The person changing canvas privacy must be a member of the canvas's workspace. They must also be one of these:

  • The canvas owner
  • The owner of the project that contains the canvas
  • A workspace administrator

The assignee is the person responsible for the work, but assignment alone does not grant the authority to change canvas privacy. Ownership and assignment solve different problems.

Choose what each member can do

Access scope decides who can enter through the project. Member roles decide what a person can do inside the canvas.

PermissionChoose it when
ViewSomeone needs to read, inspect, or present the canvas.
CommentSomeone should leave feedback and replies without changing canvas content.
EditSomeone should create, move, delete, upload, or format canvas content.

For named collaborators, manage these roles in Canvas members. Give reviewers comment access unless they need to change the work itself.

Handle unassigned canvases

A canvas without an owning project has no project audience to inherit. ALLO therefore does not show the Project access picker for an unassigned canvas. Use direct invitations or a share link to give people access, or move the canvas into a project before using project-based scope.

Remember the independent access paths

Changing a canvas to Private manages project-inherited access. Direct invitations and share-link access are separate paths and can remain active. A private page, object, comment, or chat link only points an already-authorized person to a location; it does not grant access. See Private links and share links for that distinction.

If the goal is to remove someone completely, review the canvas member list, direct invitations, and active share links as well as the project scope.

When to make a canvas private

Use Private when the project audience should not inherit access. Common examples include a draft that is not ready for the project team, confidential preparation before a meeting, and a review limited to a smaller group.

Private keeps explicitly authorized canvas access. Invite the intended people directly, then review active share links. A person with direct membership or an active share link may still enter after project access is removed.

Private or a Canvas PIN?

ChooseWhen it fitsWhat to remember
PrivateThe project team should not inherit access.Direct members and share links remain separate access paths.
Canvas PINPeople already have access, but content should open only after they receive a 4-digit PIN.Knowing the PIN does not grant access or change a person's role.
BothA small invited group needs access and an extra entry check.Invite the group, review links, and send the PIN separately.

For a scheduled class or workshop, a Canvas PIN lets you share the link early and reveal the PIN when the session begins. For a confidential draft, start with Private so project members do not inherit access.

When the result looks wrong

The visibility control is missing. Confirm that the canvas belongs to a real project. An unassigned canvas has no project visibility choice, and workspace-managed restrictions can also remove the control.

A project member cannot open a private canvas. Add them directly to the canvas, or switch to Project access if the whole project should enter.

Someone still opens a private canvas. Check direct membership and share-link access. Privacy does not cancel those independent routes.

A viewer or commenter kept the same role after Project access returned. That is expected when ALLO restores the person's preserved permission.

Give feedback

Was this article helpful?