Workspace · Access and governance
Manage workspace access and security
Control members, API keys, workspace identity, sign-in methods, and security-sensitive settings.
Source reviewed 2026-09-16. Availability depends on your installation, permissions, and compatible runtimes. A supported path is not a guarantee of model quality or production readiness.
Outcome
Give people and systems the access they need while keeping credentials, ownership, and billing boundaries clear.
Start here
What you need to know first
Check the inputs below before starting. If you are new, begin with the first-project guide. A dataset holds media and labels; a model produces results; a deployment makes a selected model version callable. Creating one does not create the others.
Bring these inputs
- — Members, roles, API keys, provider credentials, and devices
- — Workspace ownership and authentication policy
Expected output and limits
- — Scoped human and machine access
- — Revocation, rotation, and membership state
Core workflow
Review workspace identity
Open your name at the top of the sidebar → Settings. Use Profile for personal details and Workspace for the active organization and workspace-level configuration. Owners and admins can edit the workspace display name; the stable workspace ID remains visible for integrations and URLs. Product tour on this page lets you replay or continue onboarding.
Manage the team
Invite or remove members and align roles with operational responsibility.
Control machine access
Smart and Pro can create production API keys and connect agents. Pro can also create, rotate, and revoke customer-owned provider credentials.
Audit critical settings
Review security, billing, providers, and device access as the workspace changes.
What this surface supports
Member management
Workspace API keys
Provider and device access
Security settings
Expert section
Contracts, signals, and failure modes
Use this section when you are defining acceptance criteria, automating the surface, or reviewing whether its output is safe to promote downstream.
Quality and operating signals
- — Active privileged principals
- — Credential age
- — Failed authentication
- — Orphaned devices or integrations
Common failure modes
- — Shared long-lived keys
- — Former members retaining access
- — Secrets committed to source control
- — Unclear workspace ownership
Expert release checklist
□ Inputs and dependencies are pinned to immutable versions.
□ Acceptance metrics include critical classes and operating slices.
□ Failure, retry, cost, and rollback behavior are understood.
□ The resulting artifact has an owner and a downstream review path.
Engineering safeguards
- — New keys may be shown once; stored provider secrets are masked
- — Revocation is explicit
- — Critical ownership stays workspace-scoped