Skip to documentation

Workspace administration

Administer a Zentrik workspace safely

This guide is for workspace Owners and Admins. Use it to assign least-privilege roles, manage invitations, understand Settings visibility, protect integration and API credentials, review billing access, and offboard teammates.

The Settings area is restricted to workspace Owners and Admins. Editors and Viewers can work within their permitted product surfaces but should ask an Owner or Admin to complete administrative changes.

Some settings have narrower visibility: workspace organization is Owner-only, billing depends on billing-management access, and the Ideas Portal appears only when enabled.

1. Choose the least-privilege role

Zentrik workspace roles are:

  • Owner: workspace ownership and the most sensitive workspace-level controls
  • Admin: settings, integrations, API keys, team administration, and product configuration
  • Editor: day-to-day creation and editing in product workflows without access to workspace Settings
  • Viewer: read-only workspace participation

Keep at least one active Owner. Do not use Owner as the default collaboration role. Review Admin access whenever responsibilities change.

2. Manage members and invitations

Open Settings → Team.

For new teammates:

  1. Enter the intended email and role.
  2. Review the batch before sending.
  3. Check Invitations for pending, sent, failed, expired, or revoked states.
  4. Resend only after confirming the original delivery state.
  5. Verify that an accepted invitation appears under Members with the intended role.

Owners and Admins can change roles and remove members. Confirm the target identity before removal, especially when names are similar.

3. Use the Settings map

The Settings hub groups product configuration and workspace administration:

  • Discovery: evaluation, workflow, and property configuration
  • Definition: requirements, documentation templates, and user-story standards
  • Delivery: sprints and team capacity
  • Integrations: connected evidence and delivery providers
  • API Keys: credentials for MCP clients and the external API
  • Team: members, roles, and invitations
  • Billing: plan, usage, and invoices when the role can manage billing
  • Portal: Ideas Portal access and configuration when enabled
  • Workspaces: Owner-only workspace organization

The options shown in Settings depend on the workspace plan and enabled capabilities.

4. Protect integrations and API keys

Treat provider credentials and Zentrik API keys as secrets:

  • create separate credentials for distinct systems or agents when practical
  • name keys by purpose and owner
  • grant only the scopes the workflow needs
  • store secrets in an approved secret manager or environment variable
  • never paste a key into documentation, chat, source control, screenshots, or support messages
  • revoke credentials that are unused, exposed, or owned by a departing teammate
  • confirm the active Zentrik workspace before connecting an MCP client

Use MCP setup or the REST API reference for the relevant authentication flow.

5. Review billing and workspace boundaries

Use Settings → Billing for the workspace plan, current usage, configured limits, and invoices when your role has billing access. Use the pricing page for current published packaging.

Workspace Owners can use Settings → Workspaces to review the workspaces they can organize. Separate workspaces when teams or clients require distinct access and context. Do not move data between workspace boundaries without confirming authorization and downstream integrations.

6. Offboard safely

Before removing a teammate:

  1. Transfer ownership of important product decisions, documents, integrations, and operating routines.
  2. Identify credentials, connected providers, or external automations they own.
  3. Create replacement credentials where needed.
  4. Revoke the person’s invitations or remove their membership.
  5. Revoke or rotate affected API keys and provider credentials.
  6. Verify that required integrations and scheduled imports still run.

Removing a member is not a substitute for rotating a credential they could access.

Quarterly review checklist

  • at least one current Owner is active
  • Admin access matches current responsibilities
  • Editors and Viewers have the least access they need
  • pending and expired invitations are reconciled
  • API keys have a current purpose and owner
  • integration credentials still belong to active administrators
  • billing contacts and invoice access are current
  • workspace boundaries match team or client access requirements
  • teammates understand which capabilities are enabled for the workspace

Support and trust

Use Security and trust for current public assurance information. For a workspace-specific access, billing, or configuration issue, use the Still stuck? path below and include the workspace name, the screen, what you expected, and what happened.

Do not include passwords, API keys, access tokens, private customer content, or full diagnostic exports in the initial support message.

Troubleshooting

Check these steps against what you see in your workspace. If something differs, note your workspace name and the screen, then contact us.

A teammate cannot open Settings

Settings is restricted to Owners and Admins. Confirm the person’s workspace and role; use Editor for product work that does not require administration.

An invitation email failed or expired

Check the Invitations view, confirm the email, and resend or revoke from the recorded invitation state. Avoid creating repeated invitations without reconciling the existing one.

A billing, portal, or workspace control is missing

Visibility depends on role and workspace capabilities. Billing requires billing-management access, Workspaces is Owner-only, and Portal appears only when enabled.

Continue from here

Did this guide answer your question?

Your response helps us prioritize missing or unclear documentation.

Still stuck?

Send your question to Zentrik support. This guide will be included automatically.

Ask Zentrik support