Skip to main content
Workspace Owners manage who can read and contribute, the workspace’s security level, and its standing agent instructions. Check each change against the people and data that the workspace reaches.

Before you start

You need permission to manage the workspace’s members. For a security-level change, your clearance must cover both the current level and the proposed level. Product access, workspace access, and clearance are separate. Vantage access does not make someone a member of every workspace, and Owner access does not bypass clearance or content permissions.

Choose the access group for each person or team

A workspace has no generic permission to execute everything it contains. Running a workflow or using a source also checks the relevant resource, definition, data, credential, and execution requirements. Dataset authority is separate. Workspace attachment grants Reader access to an attached dataset; it does not grant ingestion, dataset updates, or credential access. See Organise data through collections.

Add or change members

  1. Inspect the current named-user and team grants. Decide what the recipient needs to do in this workspace.
  2. Check that the recipient’s clearance covers the workspace level. For a team, check every person who would gain access through that team.
  3. Grant or change the appropriate Reader, Contributor, or Owner access through the supported membership controls.
  4. Check the resulting access, including any direct and team grants that still apply.
Direct and team grants combine. A person who is a direct Reader and a Contributor through a team has effective Contributor access. Removing one grant does not remove access supplied by another. Teams do not nest. A workspace grant names the exact team; membership in another team does not inherit it.
Illustrative workspace member list showing a Demo owner, Demo reader, and Demo analyst with Owner, Reader, and Contributor access respectively.

Illustrative member list: each named user has an explicit workspace access group. The example does not establish dataset write authority or security clearance.

When reducing or removing access, check every applicable grant. Membership changes affect the next protected operation, including resumed work. They cannot recall bytes already delivered or external requests already sent.

Check the workspace security level

The security level sets a boundary for the workspace’s members and attached data:
  • Every member must hold clearance at or above the workspace level.
  • Every dataset reached by the workspace must hold data at or below that level.
  • Current permissions and per-record clearance checks still apply.
The audience includes direct members, members of assigned teams, and people admitted to a workspace agent chat. Apply the same clearance checks when sharing a chat or adding collaborators. A new workspace starts at the lowest classification level unless its creator chooses another permitted level. Workspaces that predate the level setting also begin at that lowest level until an Owner changes it. The workspace security level is a data-classification boundary. A model’s provider-security indicator describes a separate boundary and does not set workspace membership or clearance.

Change the level only when the workspace conforms

Before applying a change, inspect the conformance report available to people who can manage members. It lists the same blockers that would refuse the change. Review the named blockers with the responsible workspace, data, or security administrator. The refusal does not recommend a remedy. Recheck conformance after any separately authorised changes, then apply the level change only if it is permitted. The same boundary applies when adding people, changing a team, sharing a workspace agent chat, attaching data, uploading files, running ingestion, or changing file labels. Lowering a person’s clearance is refused while it would leave them in a workspace above that clearance.
Changing a workspace level, membership, or clearance does not move or relabel data. A level change is not declassification. Owner access alone does not grant authority to lower a content label.
A system custodian is a separate platform role with ownership across workspaces and datasets. The custodian is not a workspace member for the membership-level gate; current content checks still apply. Ordinary platform administration is not a universal grant to workspace content.

Set standing agent instructions

Use the workspace’s agent-instruction editor for rules that should apply across its agent chats. Examples include spelling, evidence handling, or the shape of an answer. Only someone who can manage workspace members can edit these instructions. A Contributor can update ordinary workspace fields but cannot write standing rules that other users’ agent chats will obey. Workspace readers can read the instructions. For the Bristol exercise, an illustrative instruction is:
Keep the text within the 16,000-character limit. Empty or whitespace-only input clears the instructions. Prompt-template tokens are not expanded in this text. An edit applies from the next dispatched turn, including in an existing workspace agent chat. A follow-up sent while a run is still working keeps the instructions that run started with; do not treat it as a fresh dispatch. These rules apply to workspace agent chats, including Explorer. A workflow Agent step uses its own configured instructions and attachments. It does not receive this workspace instruction file. Instructions do not expand a user’s authority, an agent’s authorised scope, or access to data. Keep permission decisions in the resource grants and security checks.

Check the result

Confirm the effective access for each recipient, the workspace’s level, and any remaining people or data blockers. If instructions changed, verify the intended rule in a newly dispatched agent turn rather than assuming an in-progress run picked it up. Next, attach permitted data through Organise data through collections, or follow the Vantage investigation path in Your first task in Arc or Vantage.