Skip to content

Team & invites ​

The Team page lists everyone with a seat on your account and the namespaces each person reaches. Owners and Admins use it to invite people, to give or take away access to namespaces, and to revoke a person's API keys. Everyone on the account can see the page, including each person's email address and role.

What the Team page shows ​

The Seats panel shows a count such as "4 active · 5 billed". The first number counts people who have signed in. The second counts every seat, including invitations that nobody has accepted yet. Billing is not built into Workstate yet.

Each row shows:

ColumnWhat it shows
MemberThe email address the seat was created for
RoleOwner, Admin or Member. See Roles
NamespacesThe namespaces the person reaches, out of the ones you hold. None means they reach none of yours. See Change who reaches a namespace
KeyThe start of the person's newest live API key. Invited means they haven't signed in yet. No key means they have signed in but hold no live key
Searches, 30 days and Ledger writesUsage is not recorded yet, so these columns show 0 Coming soon
Last usedWhen the person's newest key was last used

Invite someone ​

What you need ​

  • The Owner or Admin role.
  • An email address that is verified on the person's GitHub account. Workstate matches invitations only against verified addresses. Any verified address on their GitHub account works, not only the primary one, and letter case doesn't matter.
  • Access to the namespaces the person needs. You can give only namespaces you hold yourself.

Steps ​

  1. Open Team.
  2. In the Seats panel, select Invite.
  3. In Invite a teammate, enter the person's Email.
  4. Choose a Role. You can choose your own role or one below it, so an Admin can't invite an Owner. See Roles.
  5. Under Namespaces, tick each namespace the person should reach. The list shows only the namespaces you hold.
  6. Select Invite. A new row appears with the Invited badge, and a notice confirms the role and the number of namespaces.
  7. Tell the person yourself. Workstate does not send an invitation email. Send them the console's address, https://console-uat.workstate.io, and ask them to select Continue with GitHub and sign in with the GitHub account that has that address verified.

When they sign in, the invitation is accepted and the seat becomes active. From their first request, they reach the namespaces you ticked. In the Key column, Invited changes to No key until they create an API key.

Signing in with GitHub gives Workstate no access to anyone's repositories. See Security & privacy.

Which namespaces are ticked at first ​

The dialog starts with a suggestion, which you can change:

  • For a Member, the namespace you are working in.
  • For an Admin or Owner, every namespace you hold.

Changing the role resets the ticks to that role's suggestion. So choose the role first, then adjust the namespaces.

An invitation with no namespace reaches nothing

If you tick no namespace, the dialog warns you, but you can still send the invitation. The person can then sign in, but search, sources, the ledger and their API key reach nothing until someone gives them a namespace. Give them one later in the Namespaces column.

Invitation details ​

  • An email address can hold only one seat on an account. Inviting an address that already has one, in any letter case, fails with "… already has a seat on this account".
  • You can give an invited person namespaces before they accept. The access applies when they sign in.

Change who reaches a namespace ​

You need the Owner or Admin role.

  1. Open Team.
  2. In the person's row, open the picker in the Namespaces column.
  3. Tick a namespace to give it, or untick it to take it away.
  4. Select Done.

Each change applies at once, from the person's next request. Taking a namespace away doesn't revoke their keys: requests that name that namespace are refused with "no grant for namespace …", and their other namespaces keep working.

The rules:

  • You can give only what you hold. The picker lists only your own namespaces, and the column shows only those. The person may also reach namespaces you don't hold.
  • Nobody changes their own access. Another Owner or Admin can.
  • Nobody changes the access of someone above them. Only an Owner can change an Owner's namespaces.
  • Owners and Admins get every new namespace. When a namespace is created, every Owner and Admin on the account is given it. See Managing namespaces.

Where you can't make a change, the column shows the person's namespaces without a picker.

Revoke a person's keys ​

Use this when someone leaves, or when their keys may have been exposed.

  1. Open Team.
  2. In the person's row, select the trash icon, Revoke this person's keys.

Every live key the person holds is revoked at once. There is no confirmation step. Their agents get HTTP 401 (Unauthorized) on their next request. The seat stays on the account and still counts in the Seats total.

The button is off on the row of anyone above your role, so an Admin can't revoke an Owner's keys. It is also off when the person holds no live key.

Revoking keys doesn't remove the person

Revoking keys does not remove the seat, and it does not sign the person out of the console. They can still sign in with GitHub and create a new key. To make sure a new key reaches nothing, also untick every namespace in their row. The column shows only the namespaces you hold. Owners are given every namespace when it is created, so an Owner usually sees them all. Removing a seat is not built yet Coming soon. Until it is, follow the steps in Governance & offboarding.

To revoke one of your own keys, use the API keys page instead. See API keys.

What is not possible yet ​

  • Removing a seat Coming soon
  • Switching between accounts in the console, for someone with seats on more than one account Coming soon
  • Seeing how much each person searches and writes to the ledger Coming soon
  • Changing a person's role
  • Sending invitation emails

Troubleshooting ​

The person sees "Workstate is invite-only for now". No invitation matched a verified address on the GitHub account they used. Check the address on the Team page for typos. Then ask them to verify that address in their GitHub email settings, or to sign in with the GitHub account that has it verified. The refused sign-in created nothing.

The person signs in and sees "No namespace yet". They hold no namespace. Give them one in the Namespaces column of their row. This happens when an invitation had no namespace ticked, or was sent before namespaces could be chosen.

The row still shows Invited after the person signed in. An invitation is accepted only when a GitHub account signs in to Workstate for the first time. If the person had already signed in with that GitHub account before you invited them, for example to another Workstate account, the invitation is not picked up. This is a known limitation.

Their agent gets 401. See When a key stops working.

Workstate is built by Nerdstorm Pty Ltd, Sydney.