What is a workspace?
Sub-organisation containers that scope storage sharing and credentials - and act as a real read boundary.
A workspace is a container inside an organisation. Shared storage configurations attach to exactly one workspace, credentials bind to one workspace at issuance, and what you can see is scoped to the workspace your session is bound to.
The hierarchy is two levels - organisation → workspace. Every organisation has
one built-in default workspace (named Default) that cannot be renamed or
archived and that every member can use at their organisation role; any others are
created and archived by Admins.
A session or API key bound to workspace A cannot list workspace B's shared configurations - including for organisation Admins, who may bind to any workspace but don't see them all at once. To look elsewhere, you switch. An API key reaches only the workspace it was minted in - see API keys.
Access model
| Who | Access |
|---|---|
| Organisation Admin | Admin in every workspace, implicitly |
| Any org member, in the default workspace | Their organisation role, implicitly |
| Explicit member of a non-default workspace | The workspace role they were given (admin, builder, editor, viewer) |
| Everyone else | No access - the workspace 404s as if it didn't exist |
Membership on the default workspace can't be overridden per user - access there is always implicit.
Good to know