Workspaces, projects, and access
Workspaces contain shared administration: members, projects, Notes, Agent Connections, messages, usage, and billing. Projects contain delivery work and can have a narrower team than the workspace.
Workspace membership and project membership are independent. A project-only collaborator sees the workspace name and projects explicitly shared with them, but not the workspace Team, Notes, billing, settings, analytics, Agent Connections, or unrelated projects.
Workspace owners and administrators can discover active projects in their workspace. Other users see projects where they have a project membership. Project roles are:
- Owner: full project control.
- Admin: project administration and shared-content changes.
- Member: normal collaboration and delivery changes.
- Viewer: read-only access, with narrowly scoped personal actions such as recording read state.
The dashboard workspace and project selectors are navigation context. Personal surfaces such as My Work and Messages may span multiple workspaces. Messages labels each conversation with its originating workspace because the same two people can have distinct threads in different workspaces.
Access changes are server-enforced. Hiding a control is useful guidance, but it is never the authorization boundary. When access is removed, stale dashboard selections are cleared and inaccessible routes return the user to an accessible workspace or setup state.
Updated 2026-08-09. Owned by product.

