Product · Workspaces
One body of work, shared as a whole.
A workspace holds a deal, a portfolio or a client — the documents and every table built over them, together. Access is granted to the workspace rather than to anything inside it, so there is one place to decide who can see the work, and one place to change your mind.
Free credits on sign-up. No card, no subscription.
| Document | Priya · owner | Sam · member | Lena · member | Jo · guest |
|---|---|---|---|---|
| Atlas data room | Manage | Manage | Read & Write | Read |
| Portfolio monitoring | Manage | Read | Manage | Read |
| HR matters | Manage | — | Manage | — |
Three levels, granted three ways.
A rule gives one level to everyone in the organisation, to a role, or to one person. Rules only add: where two apply, the higher level wins, and taking access away means deleting the rule that gave it.
| Level | Lets you |
|---|---|
| Read | Open the workspace, read its documents and tables, follow citations, and export what you can read. |
| Read & Write | Everything Read allows, plus uploading documents and building, editing and running tables. |
| Manage | Everything above, plus the workspace’s settings and sharing, its API keys, and table settings such as auto mode. |
The permission matrix lists every action against every level.
Decided when you create it.
A new workspace starts one of two ways, and you choose which: readable by everyone in the organisation, or reachable only by you and your organisation’s owners and admins. Anything more — write access for a role, Manage for one person — is a rule you add afterwards.
Owners and admins can reach every workspace, whichever you choose. That is by design, and worth knowing before you put something sensitive in one. An organisation-wide rule reaches guests too.
Share the workspace, not the file.
There is no sharing a single table or a single document. Someone who can read a workspace can read everything in it, and can export what they read.
So the workspace is the line you draw. If two groups should see different documents, they belong in two workspaces — which is also what keeps a table from quietly mixing work that was never meant to meet.
The same rules, whatever the door.
The app, the API and the MCP server decide access in exactly the same way. A personal API key reaches what its owner can reach, and can be narrowed but never widened. An AI client connected over MCP reads only what the person who connected it could open, and the organisation can take tools away from it but never add access.
What it will not do.
- It does not hide a workspace from your admins. Owners and admins reach every workspace in the organisation.
- It keeps no record of who read what. Access is decided on every request; reading is not logged for you to review.
- Manage does not include delete. A workspace can be deleted only by its creator or by an owner or admin, and deleting it is final.
How documents are protected, and where they are held, is on the security page. A workspace is where tables and bundles live, and where auto mode answers new rows as they arrive.
Start with the pile you already have.
Signing up comes with free credits. No card, no subscription.
