# Who can work a program

**Updated:** 2026-10-04

## Three levels

- **Workspace admins** create programs and own the published policy, the scope, the custom domain and the team.
- **Program members** work the queue: triage, priority, comments and handing reports to a tracker. They cannot change the published policy.
- **Guests** are outside collaborators. A guest is a member of the programs you add them to and nothing else — they never see the workspace-wide list of programs.

## Why members exist

Security work should be assignable to security people. Without this tier, working a report would require making somebody a workspace admin, which is a much larger grant than reading a bug report.

The published policy stays with admins because it is a legal commitment — safe harbor, response times and what is in scope are promises to the outside world.
## Adding an outside contractor

Add them on **Team**. If they are a guest, they are granted access to the app at the same time, because otherwise they would have a queue they cannot open.


---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)