Get started

Workspaces and teams

Design organization boundaries, roles, and private access groups.


A workspace is the organizational boundary for identity, data, credits, and billing. Keep personal experiments in personal space and create organization-owned cases and playbooks in workspace context.

Roles are owner, admin, and member. Their main workspace capabilities are:

Capability Owner Admin Member
Billing View and manage View status only View status only
Workspace administration Manage workspace settings View administration and usage; manage SSO No access
Workspace members View and manage View and manage No access
Teams View and manage View and manage View accessible teams
Credits View balance and usage; purchase credits View balance and usage View balance and usage

Object access is not roles alone. Cases still use ACLs. Every member can read and edit playbooks owned by the workspace; making them public, changing access, and archiving still require an Owner or Admin.

Owners and Admins can invite unregistered email addresses as Members. Epismo emails each invitee a link; after they create an account with that address, their membership is applied automatically. Existing Epismo users are added immediately instead. Owners and Admins can review and revoke pending invitations; all invitations grant the Member role, and role changes happen after the person joins.

A team is a private access group inside a workspace. Create teams around functions or responsibilities and place their IDs in case or playbook ACLs. When changing workspace membership, also review team membership, case assignments, and playbook ownership.

See Administration and CI in the CLI for operations and Access and identity for ACL behavior.