Workspaces and teams
Design organization boundaries, roles, and private access groups.
A Workspace is the organizational boundary for identity, data, credits, and billing. Keep personal experiments in personal space and create organization-owned Playbooks and Cases in workspace context.
Roles are owner, admin, and member. Their main workspace capabilities are:
| Capability | Owner | Admin | Member |
|---|---|---|---|
| Billing | View and manage | View status only | View status only |
| Workspace administration | Manage workspace settings | View administration and usage; manage SSO | No access |
| Workspace members | View and manage | View and manage | No access |
| Teams | View and manage | View and manage | View accessible teams |
| Credits | View balance and usage; purchase credits | View balance and usage | View balance and usage |
Object access still depends on ACLs, not roles alone.
A Team is a private access group inside a Workspace. Create Teams around functions or responsibilities and place their IDs in Playbook or Case ACLs. When changing Workspace membership, also review Team membership, Case assignments, and Playbook ownership.
See Administration and CI in the CLI for operations and Access and identity for ACL behavior.