IntuBuStart free

Giving people access to a workspace

A matrix of users against workspaces, evaluated before any other permission.

Settings → Team → Workspace access.

Rows are people, columns are workspaces, and each cell is None, Member or Admin.

It is the first gate. Access is decided in this order, everywhere — screens, the API, inquiries, exports, search results and AI answers alike:

  1. Workspace access
  2. Company and branch scope
  3. Role permissions
  4. Field-level masks
  5. Record-level rules

Because the workspace check comes first, "a CRM rep cannot see payroll" is one rule rather than a hundred places that each have to remember.

Roles grant workspaces; per-user overrides adjust them. The shipped presets carry sensible scopes — CRM Only (rep), Accounting Only (bookkeeper), Marketing Only (manager), Everything (admin) and others. An administrator can then add or explicitly revoke a workspace for one person, and the change is audited with a before-and-after snapshot.

Two things are refused, on purpose:

  • Removing the last administrator from a workspace. Somebody has to be able to give access back.
  • Removing a person's only workspace. That leaves them signed in with nowhere to go — deactivate the user instead.

Landing somewhere you cannot reach shows a plain screen naming the workspace and a button to ask an administrator for it, rather than an error.

Roles created before workspaces existed keep working: a role with no workspace grant at all is treated as an Accounting role, which is what it was.