Invite additional users only after the first app, AI client, provider read, and
audit record have been verified. Manage normal access through groups, not
per-user grants.
Plan access before inviting
Define groups around job responsibilities, not individual providers. Examples
include:
Service desk readers
Security reviewers
Account and reporting users
Documentation users
Workspace administrators
Start each group with the smallest useful set of apps and read tools. Add write
access only for a documented workflow with an accountable owner. Check the
workspace selector
before inviting users or changing group permissions.
Create a group
Open Users & Groups, select Groups, and create a group with a clear
purpose and description.
Assign permissions
Add the required app or individual tool grants. Use restrictions when a
group must not reach a sensitive tool that might otherwise be granted.
Invite the user
Open Users, add the person's company email, choose the appropriate role,
and assign the planned groups.
Have the user sign in
The user should follow the invitation and authenticate with the matching
verified company account.
Connect personal apps
If an enabled app uses personal credentials, each user must authorize their
own provider account before using it.
Verify effective access
Use the Permissions view to inspect the user's effective access. Test
one expected allowed read and, where appropriate, one expected denial.
Roles and tool access are different
Every user has one workspace role: owner, admin, or member. Owners
and admins can manage the workspace — apps, users, groups, and settings —
while members use the access they have been granted.
A portal role controls administrative actions and page visibility. App and
tool grants control what the user's AI client can discover and execute. Giving
someone an admin role should not be used as a substitute for designing
their tool access.
MSP customer workspaces
Do not invite a customer user into the MSP's internal company workspace as a
shortcut. Create or select the customer's isolated workspace instead — see
Managed customers.
Ongoing review
Review group membership, tool grants, and audit activity whenever someone
changes roles or leaves the company.