Workspaces & membership
Confine members to the environments they own.
Membership
Assign a member to specific workspaces and they can see and act only there — confinement extends down to direct by-id access, so it cannot be bypassed by guessing an id.
Per-workspace roles
A member can hold a different role in different workspaces — for example DBA in staging but Operator in production. Assign these at invite time or later from Manage workspace roles, and change or remove a member’s role in any workspace independently. Effective permissions resolve per active workspace on every request.
Try it yourself
Open the console and put this into practice.