# Giving people access to a workspace

> A matrix of users against workspaces, evaluated before any other permission.

Section: Workspaces and access · Canonical: https://intubu.intuitivecapital-dai.com/docs/workspace-access

Settings → Team → **Workspace access**.

Rows are people, columns are workspaces, and each cell is **None**, **Member** or **Admin**.

**It is the first gate.** Access is decided in this order, everywhere — screens, the API, inquiries, exports, search results and AI answers alike:

1. Workspace access
2. Company and branch scope
3. Role permissions
4. Field-level masks
5. Record-level rules

Because the workspace check comes first, "a CRM rep cannot see payroll" is one rule rather than a hundred places that each have to remember.

**Roles grant workspaces; per-user overrides adjust them.** The shipped presets carry sensible scopes — *CRM Only (rep)*, *Accounting Only (bookkeeper)*, *Marketing Only (manager)*, *Everything (admin)* and others. An administrator can then add or explicitly revoke a workspace for one person, and the change is audited with a before-and-after snapshot.

**Two things are refused, on purpose:**
- Removing the last administrator from a workspace. Somebody has to be able to give access back.
- Removing a person's only workspace. That leaves them signed in with nowhere to go — deactivate the user instead.

**Landing somewhere you cannot reach** shows a plain screen naming the workspace and a button to ask an administrator for it, rather than an error.

**Roles created before workspaces existed** keep working: a role with no workspace grant at all is treated as an Accounting role, which is what it was.
