Workspaces and access
Work in the correct tenant, organize users and production resources, and activate scoped access without interrupting current operations.
Select and identify a workspace
A workspace is the tenant boundary for projects, templates, agents, printers, jobs, integrations, usage, and billing. If your account belongs to more than one workspace, use the workspace switcher before making changes.
The selected workspace is preserved while you navigate. Managers can update its readable name from Profile > Settings; the tenant ID remains the stable identifier used by integrations.
Understand roles
Roles are cumulative: each level includes the capabilities below it. The interface hides or disables actions the current account cannot perform.
| Role | Typical access |
|---|---|
| Viewer | View resources available to the user. |
| Operator | View resources and submit or operate print work. |
| Editor | Operator access plus creation and editing of production resources. |
| Manager | Editor access plus workspace administration, groups, assignments, access activation, and billing. |
Model access with plants and groups
- 1
Create plants
Use plants to represent production locations or other operational boundaries. Assign agents and printers to the relevant plant.
- 2
Create groups
Group users who need the same plants and projects, then set the appropriate role.
- 3
Assign projects and plants
Attach only the resources that the group needs. A user in multiple groups receives the union of those assignments.
- 4
Add exceptions only when needed
Direct user or group shares are additive. Use them for a specific exception instead of duplicating the main group model.
Activate scoped access
Open Access > Activation after the model is complete. The preflight checks identity claims, active managers, user groups, project assignments, plant assignments for printers and agents, and compatible agent routing. Resolve every blocking item before activation.
After activation, users see the resources allowed by their role and assignments, and legacy unscoped access is disabled. A manager can deactivate scoped access to roll back without deleting the prepared configuration.