Understand who can do what
Three independent checks decide what you can do in a workspace: your Microsoft 365 permissions, Orbit’s admin rule, and your editor seat.
Microsoft 365 decides your reach
Section titled “Microsoft 365 decides your reach”Your own SharePoint or OneDrive permissions on the workspace’s storage decide whether you can read or write its notes. Orbit checks them with your own sign-in — it holds no permissions of its own and never acts in the background; see the Permissions model.
- Write or owner permission on the workspace root → you are an Editor in that workspace.
- Read permission → you are a Reader.
Change access by changing SharePoint site membership (Owners, Members, Visitors) or OneDrive sharing — Orbit follows. The Members section in workspace settings is a read-only mirror of those SharePoint groups; see Workspace settings.
Orbit decides workspace admin
Section titled “Orbit decides workspace admin”Workspace administration — workspace settings and the Members view — is Orbit’s own rule, independent of SharePoint: the workspace creator and your organization’s tenant admins are workspace admins.
Editing needs an editor seat
Section titled “Editing needs an editor seat”Reading is always free. Writing — in every workspace type, personal OneDrive included — additionally requires an editor seat. A person with write reach but no seat opens every note read-only, with no error. Seats are granted and reclaimed by org admins; see How editor seats work.
Know the roles
Section titled “Know the roles”| Role shown | You can |
|---|---|
| Reader | Open and read every note in the workspace, follow live editing, use search and the graph. |
| Editor | Everything a Reader can, plus create, edit, rename, move, and delete notes — with an editor seat. |
| Admin | Everything an Editor can, plus workspace settings and the Members view. |
The full role reference, including how each role maps to Microsoft 365 permissions, is at Roles.
Note shares add access — never subtract
Section titled “Note shares add access — never subtract”A note share grants access to one note on top of whatever workspace access the person already has. Access is the higher of the two: a workspace Editor keeps edit access even if a share on the same note says view-only, and a person with no workspace access at all gets exactly what the share grants. Revoking a share never reduces workspace access.
Why can someone still open a note after I removed their share? They have workspace access through Microsoft 365. Remove them from the SharePoint site (or stop sharing the OneDrive folder) to remove workspace access.
Why is a teammate suddenly read-only? Their editor seat was revoked, or the organization’s seats are frozen over a billing issue — see How editor seats work.
Up next: follow what your team is doing in Track activity and notifications.