Organization workspaces
Share automation capacity while preserving explicit workspace authority.
Who can manage access
Organization owners and administrators can create grants for workspaces they currently manage. Ordinary membership does not permit creating or extending an automation grant.
A multi-workspace key contains an explicit allowlist; joining another organization does not extend it automatically. Every request verifies current authority for the selected workspace.
Shared plan and credit pool
The organization workspace shares its plan limits, queue, storage and credits. Usage points are aggregated across its keys and REST/MCP transports. Member count does not multiply the quota.
Use workspace financial ceilings to bound all automation spending and narrower per-key ceilings for individual applications. Admission also checks the actual spendable balance and job concurrency limits.
Changes to membership
If a key's owner loses the required role, it loses authority to perform operations in that organization workspace. Rotating a secret cannot restore removed permissions. Another owner or administrator can manage an authorized replacement integration.
Webhook destinations and media references remain bound to the organization workspace. A domain verified in a personal workspace is not automatically a valid destination for the organization's events.
Audit an integration
Use separate keys for independently managed applications and inspect known Web, API and MCP origins in job and transaction records. Key lifecycle and security notices help workspace managers identify unexpected changes without sending an email for every read request.