Workspaces
Understand the team, subscription, roles, and shared resources contained by a workspace.
A workspace is the top-level boundary for a team. It owns projects, membership, subscription state, plan limits, and security resources that may be shared between projects.
What belongs to a workspace
- workspace members and roles;
- projects;
- the current subscription and resource limits;
- workspace-shared credentials;
- workspace-shared Client CAs.
Project data remains organized inside individual projects even though the subscription is measured at workspace level.
Workspace roles
Owners and administrators can perform sensitive workspace operations such as inviting members and managing shared resources. Other roles receive narrower access according to the active authorization policy.
The console hides or disables actions that the signed-in user cannot perform, but the backend remains the final authorization authority.
Shared security resources
Credentials and Client CAs can be project-local or workspace-shared. Sharing is useful when several projects connect to the same warehouse or trust the same certificate authority.
Creating or deleting a workspace-shared security resource requires workspace administrator or owner authorization. Share only when the broader scope is intentional.
Subscription and limits
Open Settings → Workspace to inspect workspace information and current subscription context. Resource creation can be disabled when a plan count limit is full. Runtime traffic can also be governed by hourly, daily, or monthly quotas.