Skip to content

Set up your team

Bring your team in with roles that match what each person does, and give each team a workspace, so the right people see the right work without anyone sharing it item by item.

  • Permissions: an organization Admin. People, Workspaces and Access Policies are admin-only pages in Settings. To share a single project or dashboard, you need to own it.
  • Data you need: a list of who’s joining, whether each person builds things or only reads them, and which teams need a space of their own.
  • Credits this uses: none. Creators and Admins each use a seat on your plan, and Guests don’t.

Say you’re setting up Curio. The finance team builds the monthly reports, the operations team builds its own, and the store managers only read what they’re given.

Roles come at two levels, and the names don’t quite match, so sort them out on paper first.

LevelRolesSet on
OrganizationAdmin, Creator, GuestPeople
WorkspaceAdmin, Creator, ViewerA workspace’s Members tab

In the organization, Creators build and edit, Guests can only view, and Admins also run the organization’s settings. For Curio, both teams are Creators, the store managers are Guests, and one or two people are Admins.

Is a workspace Admin an organization Admin? No. They manage that one workspace and its members, but the admin pages in Settings stay closed to them.

  1. Open Settings, then People under Organization, and click Invite Users.
  2. For each person, fill in Email, First name, Last name and Role. To invite several at once, paste a list of addresses into Email, and it splits into one row per person.
  3. Check every Role before you send. It starts at Guest, and so does every row from a pasted list.
  4. Click Send Invites.

Not Verified beside a name means that person hasn’t verified their email address yet. A role you change in the members table saves straight away.

If your company’s email domain was claimed when the organization was set up, the Team email domain card on People offers your organization to anyone who signs up with a verified address at that domain. They choose whether to join.

The card’s switch turns that offer on or off, and They join as sets Creator or Guest. The card says “workspace”, but it means your whole organization. If most people who’d sign up only read, pick Guest.

  1. Under Organization, open Workspaces, type a Name under New workspace, and click Create workspace.
  2. Choose Stay here and configure it.
  3. Click Manage on the new workspace, then open Members.
  4. Under Add a member, pick someone from Choose a person…, pick a role, and click Add. The role starts at Creator.

Only people already in your organization can be added, so invite them first. Until you add anyone, only you can see the workspace.

For Curio, that’s a Finance workspace with the finance team as Creators and the store managers as Viewers, and an Operations workspace set up the same way. Work that everyone should see belongs in your organization’s default workspace, which everyone can reach without being added.

None of this helps unless work gets saved in the workspace. New projects, dashboards and chats go to your private workspace unless you’re working in a workspace you belong to. So pick the team’s workspace in the switcher at the top of the app rail before you start. Anything the chat makes while the switcher shows Everything goes to Private.

Files are the trap. A file added outside the Library, say on Home, goes to the organization’s default workspace, where everyone can see it. Upload anything sensitive from inside the team’s workspace in the Library.

Tell your team this part, because it’s easy to miss.

Some work needs to reach someone outside its workspace, like a dashboard for one manager. Share that item instead of adding them to the whole workspace.

Open Share: the share icon in a project’s chat header, or Share in a dashboard’s header. Search for the person, pick a role, and click Invite. The role starts at Editor, so switch it to Viewer for anyone who only reads. Only an owner can add people, and on a dashboard an admin can too.

Create Link makes a public link anyone can open. Visitors see your data, filtered by your access policies, not theirs. So share directly with anyone who should see only their own slice. On any link you do send, set an expiry and a password, and send the password separately.

Sharing decides who can open something, and access policies decide which rows they see. If each store manager should see only their own store, add a policy.

  1. In Settings, open Security, then Access Policies, and click Create Policy.
  2. Enter a Name. Under Row Filter, enter a Column Name and the Allowed Values. In Curio’s point-of-sale data, location_id holds the store.
  3. Leave Applies To on Auto to cover every source with that column, and click Create.
  4. Click the number in the policy’s Users column and pick the people it’s for.

Until someone has a policy, they see every row. Check what a person will get with Preview Access. Access Policies covers the rest.

  • People shows everyone with the role you meant.
  • Each workspace’s Members tab lists its team, with the right roles.
  • A teammate sees their team’s workspace in the switcher.
  • Preview Access shows a store manager the filter you expect.

A new teammate can’t build anything. Invites start as Guest. Change their Role on People to Creator.

You can’t find someone to add to a workspace. Only people already in your organization can be added to a workspace. Invite them on People first.

A workspace admin can’t open People or Workspaces. Those pages need the organization Admin role. A workspace role doesn’t open them.

A teammate can’t see a project they need. It was probably saved to its owner’s Private workspace. Ask the owner to share it.

You can’t change your own role. Your row on People has no menu, so another admin has to change it.

A store manager still sees every store. They may have no policy, or the policy may not cover that source. An Auto policy covers only sources that have a column with that name, whatever its capitalization. Check with Preview Access.