Workspaces & users
Workspaces and users are how you structure your organization and decide who can see what. Workspaces keep your data tidy and separated, while user management controls who's on your team and what each person is allowed to do. Getting these right early makes everything else — reporting, billing and security — far simpler. Admin only
Set up your structure
Create your workspaces
A workspace is an isolated data container — typically one per store, branch or department. Create a workspace for each unit you want to keep separate, giving it a clear title.
Invite your team
Invite team members by email — one address or a whole list at once. They join your organization, and you then give each of them access to the workspaces they need.
Give each person a role, then their workspaces
The role you give someone in the organization decides what they can do. The workspaces you add them to decide which data they see. Administrators reach every workspace already, so they need only the role.
Workspaces
Workspaces let you separate feedback, data and access by unit. Because each workspace is isolated, a regional manager can be limited to their own branch while head office sees everything.
You can create new workspaces, search and sort the list by title or creation date, and open any workspace to view its details. Long lists are paginated so they stay easy to scan. Most settings elsewhere in the Admin Panel — like retention or the CX Badge — can be applied per workspace, which is why a clean workspace structure pays off everywhere.
Users
The Users area is where you manage everyone on your team. You can view all users across the organization, or switch to a workspace tab to see who has access to a specific workspace.
Roles and access
Two separate questions decide what somebody gets, and it helps to keep them apart:
- What can they do? Their role in the organization — see Roles below.
- Which data do they see? The workspaces they're on.
Administrators reach every workspace in the organization without being added to each one. Everyone else sees the workspaces you give them, and nothing else.
Adding somebody to a workspace is a yes-or-no decision — there's no role to pick there. What a person can do is the same in every workspace they can see.
Ownership
Every organization has one owner with full control, including billing and the ability to delete the organization. Other people are members. When responsibilities change, the owner can transfer organization ownership to another user.
Transfer ownership carefully
Transferring ownership hands over full control of the organization, including billing and deletion rights. Make sure you're handing it to the right person before you confirm. Admin only
Seeing where one person can go
Each row on the organization tab has a Workspaces (n) button showing how many workspaces that person can open. It opens a panel listing them, where you can add a workspace or take one away and save the lot in one go. It is the quickest way to answer "what can this person actually reach?" without visiting each workspace in turn.
When somebody asks for access
A person who belongs to the organization but hasn't been added to any workspace can't open anything, and the products offer them a Request access button. That emails every administrator of the organization — you'll get one message naming who is asking and which product they were in.
The link in it opens that person's workspace access panel directly, so you can tick the workspaces they need and save without searching the user list. Nothing is granted automatically; the decision stays with you. Requests are limited to one per person per day, so a frustrated click doesn't fill your inbox.
Spotting people from outside your company
Once you've listed your organization's email domains, anyone whose email address is on none of them carries an External badge in the user list — typically contractors, agencies, or people who signed up with a personal address. The badge is for information only: it doesn't change what they can do or see. If you haven't listed any domains, nobody is marked.
While no domains are listed, the Users page shows a prompt, Define your organization's email domains. Add a domain takes you to User Security to add them, and Why? explains what domains are for. If now isn't the right time, dismiss the prompt and it stays hidden for 30 days.
When somebody asks to join
If your organization is set to Discoverable, but open only after approval (see Email domains & team sign-up), colleagues who find it can ask to join. When requests are waiting, the Users page shows a banner such as 3 people are asking to join this organization.
Open the requests
Choose Review requests on the banner. The Requests to join panel lists each person asking.
Check your seats
The panel shows how many user seats are in use, and your plan's allowance when it's known. If approving would take you past that allowance, it warns you — but doesn't stop you.
Approve or decline
Choose Approve to add the person to your organization as a Member; they get an email letting them know. Choose Decline to turn the request down.
Declining is silent — the person isn't emailed, and your organization simply stops being offered to them. You can still invite them yourself later. Somebody you approve starts as a Member, so add them to the workspaces they need.
You don't have to keep checking the page: every administrator gets an email when someone asks to join, and its link opens the Requests to join panel directly. Administrators are also emailed when someone joins an organization that's open to join.
Removing someone removes them everywhere
Removing a person from the organization also removes them from every workspace in it. There is no leftover access to clean up afterwards — and no way to leave someone on a single workspace by removing them from the organization. To narrow access instead, take away the workspaces you do not want them on and leave them in the organization.
Roles
Roles are set at the organization level, and a single person can hold more than one at a time. A role applies everywhere that person can see — what somebody may do doesn't change from one workspace to the next.
How somebody gets access
Joining happens in two steps, and they are deliberately separate.
First, invite the person to the organization. You invite by email and assign one or more roles. You can paste a whole list of addresses at once — separated by commas, one per line, or straight out of a spreadsheet column — and everyone in it gets the same roles. Ticking Send an email lets them know they have been added, and you can add a short message; leave it unticked to add people quietly, which is useful when you are setting up an account before anyone starts.
Then add them to their workspaces. Adding somebody to a workspace picks from the people already in your organization rather than asking for an email again — so a workspace can never contain somebody the organization does not know. If the person you want is not in the list, invite them to the organization first.
Administrators can skip the second step: they reach every workspace in the organization already.
Or let colleagues find you. Instead of inviting everyone, you can let people with an address on your company's email domains find your organization and join — straight away, or once an administrator approves. They always join as a Member. See Email domains & team sign-up.
After somebody has joined you can change their role, add or remove workspaces, or remove them entirely at any time. Because roles are additive, granting an extra role widens what they can do and removing one narrows it.
The roles
| Role | What they can do |
|---|---|
| Owner | The top authority — a single person per organization, and a single person per workspace. The Owner can edit and delete the organization (or workspace), move a workspace to another organization, and transfer ownership. |
| Admin Admin only | Manage the organization's users, settings and configuration, and reach every workspace in it. Broad access to all features and settings except the Owner-only actions. Admins are the people who can open this Admin Panel. |
| Member | Work in the products your plan includes, in the workspaces they've been added to. No administrative rights over the organization itself, and no access to the Admin Panel. |
About the Owner
There is exactly one Owner per organization and one per workspace — it's the top authority, not a role you hand out freely. Owners always retain access, so you can't simply be removed as Owner; instead, to hand control to someone else you transfer ownership, which is password-protected for safety. See the warning above on transferring carefully.
Permissions evolve
Roles are assigned per organization, and the exact permissions attached to each one can change over time as we add features. Treat the table above as a practical guide rather than a fixed contract. When access doesn't look right, check two things: the person's role, and the workspaces they're on.
For a primer on how accounts and organizations fit together, see Accounts & organizations. To control sign-in policy, sessions and API keys for the people you've invited, head to Security & API keys.
Related
Accounts & organizations
Security & API keys
Email domains & team sign-up
Identity & Account
For your own login, password and personal profile, head to Identity & Account.