Invite additional users only after the first app, AI client, provider read, and
audit record have been verified.
Plan access before inviting
Define groups around job responsibilities, not individual providers. Examples
include:
Service desk readers
Security reviewers
Account and reporting users
Documentation users
Workspace administrators
Start each group with the smallest useful set of apps and read tools. Add write
access only for a documented workflow with an accountable owner.
Create a group
Open Users & Groups, select Groups, and create a group with a clear
purpose and description.
Assign permissions
Add the required app or individual tool grants. Use explicit denies when a
group must not reach a sensitive tool that might otherwise be granted.
Invite the user
Open Users, add the person's company email, choose the appropriate role,
and assign the planned groups.
Have the user sign in
The user should follow the invitation and authenticate with the matching
verified company account.
Connect personal apps
If an enabled app uses personal credentials, each user must authorize their
own provider account before using it.
Verify effective access
Use the Permissions view to inspect the user's effective access. Test
one expected allowed read and, where appropriate, one expected denial.
Roles and tool access are different
A portal role controls administrative actions and page visibility. App and
tool grants control what the user's AI client can discover and execute. Giving
someone an administrator role should not be used as a substitute for designing
their tool access.
MSP customer workspaces
MSPs can create a separate workspace for each managed customer. Do not invite a
customer user into the MSP's internal company workspace as a shortcut. Create
or select the customer's isolated workspace, connect the appropriate customer
apps there, and grant only that workspace's tools.
Always verify the workspace selector before inviting users or changing group
permissions. Workspace membership and tool policy are boundary-sensitive.
Ongoing review
Review group membership, app connections, tool grants, explicit denies, MCP
clients, and audit activity whenever someone changes roles or leaves the
company.