Roles
Every seat on a Workstate account has one role: Owner, Admin or Member. The role decides what a person can do. Their namespace access decides where they can do it: a role gives nothing in a namespace the person can't reach.
The console hides the controls a role can't use. Workstate also checks the role on every request, so a hidden control is a convenience, not the protection.
What each role can do
| Action | Owner | Admin | Member |
|---|---|---|---|
| Search, and read the ledger, in the namespaces they can reach | Yes | Yes | Yes |
| Write to the ledger through an agent: create, append, supersede, move and archive topics | Yes | Yes | Yes |
| Create and revoke their own API keys | Yes | Yes | Yes |
| See sources, their sync history and their uploaded files | Yes | Yes | Yes |
Select Sync now on a source, or ask an agent to run reindex_corpus | Yes | Yes | Yes |
| See the Team page and the Namespaces page | Yes | Yes | Yes |
| Add a source, including connecting GitHub and uploading files | Yes | Yes | No |
| Change a source: its sync schedule, pause and resume, cancel a sync, replace its Atlassian token, delete uploaded files | Yes | Yes | No |
| Delete a source | Yes | Yes | No |
| Create a namespace | Yes | Yes | No |
| Delete a namespace | Yes | Yes | No |
| Invite people, at a role no higher than your own | Yes | Yes | No |
| Give a teammate access to one of your namespaces, or take it away | Yes | Yes, except an Owner's | No |
| Revoke all of a teammate's keys | Yes | Yes, except an Owner's | No |
| Get access to each new namespace when it is created | Yes | Yes | No |
Connecting GitHub also needs a role on GitHub's side: you must be an admin of the GitHub organisation, or the owner of the personal account, that the Workstate GitHub App is installed on. See GitHub.
The last row matters for Members. They reach only the namespaces someone gives them: when they are invited, or later on the Team page. See Team & invites.
Owners and Admins
Owners and Admins can do the same things, within these rules:
- Nobody can give a role above their own. An Admin can't invite someone as an Owner.
- Nobody can act on the seat of someone above them. An Admin can't revoke an Owner's keys or change an Owner's namespaces. In the console, those controls are off on the row of anyone above your role.
- You can give only the namespaces you hold.
- Nobody can change their own namespace access. Another Owner or Admin can.
The person who creates a self-serve account is its Owner.
Your role in a namespace
Access to each namespace also carries a role, Admin or Member, shown under Your role on the Namespaces page. By default, Owners and Admins are given namespaces as Admin, and Members as Member.
This role only limits what you can pass on: nobody can give a namespace at a higher role than they hold it. What you can do in a namespace is decided by your role on the account, as in the table above.
Things no role can do yet
- Change a person's role.
- Remove a seat Coming soon.
- Delete an account Coming soon.
- Limit a person to some documents in a namespace. Everyone with access to a namespace sees everything in it Coming soon.
- Sign in with single sign-on (SSO) Coming soon.
- Write to the ledger from the console. The console's Ledger is read-only for every role; people write through their agents.