Workspaces and access

Work in the correct tenant, organize users and production resources, and activate scoped access without interrupting current operations.

About 7 minutes

Select and identify a workspace

A workspace is the tenant boundary for projects, templates, agents, printers, jobs, integrations, usage, and billing. If your account belongs to more than one workspace, use the workspace switcher before making changes.

The selected workspace is preserved while you navigate. Managers can update its readable name from Profile > Settings; the tenant ID remains the stable identifier used by integrations.

Understand roles

Roles are cumulative: each level includes the capabilities below it. The interface hides or disables actions the current account cannot perform.

RoleTypical access
ViewerView resources available to the user.
OperatorView resources and submit or operate print work.
EditorOperator access plus creation and editing of production resources.
ManagerEditor access plus workspace administration, groups, assignments, access activation, and billing.

Model access with plants and groups

  1. 1

    Create plants

    Use plants to represent production locations or other operational boundaries. Assign agents and printers to the relevant plant.

  2. 2

    Create groups

    Group users who need the same plants and projects, then set the appropriate role.

  3. 3

    Assign projects and plants

    Attach only the resources that the group needs. A user in multiple groups receives the union of those assignments.

  4. 4

    Add exceptions only when needed

    Direct user or group shares are additive. Use them for a specific exception instead of duplicating the main group model.

Activate scoped access

Open Access > Activation after the model is complete. The preflight checks identity claims, active managers, user groups, project assignments, plant assignments for printers and agents, and compatible agent routing. Resolve every blocking item before activation.

After activation, users see the resources allowed by their role and assignments, and legacy unscoped access is disabled. A manager can deactivate scoped access to roll back without deleting the prepared configuration.