Giving people access to a workspace
A matrix of users against workspaces, evaluated before any other permission.
Settings → Team → Workspace access.
Rows are people, columns are workspaces, and each cell is None, Member or Admin.
It is the first gate. Access is decided in this order, everywhere — screens, the API, inquiries, exports, search results and AI answers alike:
- Workspace access
- Company and branch scope
- Role permissions
- Field-level masks
- Record-level rules
Because the workspace check comes first, "a CRM rep cannot see payroll" is one rule rather than a hundred places that each have to remember.
Roles grant workspaces; per-user overrides adjust them. The shipped presets carry sensible scopes — CRM Only (rep), Accounting Only (bookkeeper), Marketing Only (manager), Everything (admin) and others. An administrator can then add or explicitly revoke a workspace for one person, and the change is audited with a before-and-after snapshot.
Two things are refused, on purpose:
- Removing the last administrator from a workspace. Somebody has to be able to give access back.
- Removing a person's only workspace. That leaves them signed in with nowhere to go — deactivate the user instead.
Landing somewhere you cannot reach shows a plain screen naming the workspace and a button to ask an administrator for it, rather than an error.
Roles created before workspaces existed keep working: a role with no workspace grant at all is treated as an Accounting role, which is what it was.