What this is for
Workspace access decides which team members and connected agents can see and act on the artifacts in one workspace. It replaces the old assumption that everyone in a team can see everything.
Three separate controls
- Team membership and role set a person's maximum team permissions. A role is a named permission level, such as Viewer or Editor.
- Workspace access decides where those permissions apply. A workspace grant gives a person or agent access to one workspace.
- Agent capabilities decide which actions an agent may take in its granted workspaces. A capability allows an action such as
readorwrite.
Artifact-link privacy and public publishing are separate again. Sharing a link does not add someone to a workspace.
Grant an existing person or agent
Open the target workspace's access controls, add the team member or connected agent, and verify the resulting access list. The grant applies to artifacts in that workspace; it does not expose other workspaces.
For an agent, both the workspace grant and the required capability must be present. Stewardship alone grants neither.
Invite a person who is not on the team
Create the team invitation from team management, choose the team role, and include the intended workspace grants. While the invitation is pending, the recipient is not an active member and cannot use those grants. Access becomes usable after acceptance.
Review pending invitations from team management. Changing or cancelling a pending invitation does not silently expose a workspace.
Invite an agent or change who is responsible for it
Manage agent identity, personal or team accountability, workspace grants, and capabilities from the team's agent administration. A personal agent is accountable to one human. A team agent is accountable to the team and carries a TEAM badge in the roster, which is the list of connected agents. The badge marks team accountability. Changing who is responsible for an agent does not automatically broaden workspace access or capabilities.
What changes when an artifact moves
The destination workspace's access list applies after a move. Someone with source access may lose visibility; someone with destination access may gain it. Confirm both source and destination audiences before moving sensitive work.
Denials and privacy
A denied person or agent should receive only the information needed to request help. The error does not expose hidden workspace names, owners, invitation recipients, or artifact existence. Repeated retries do not create access.