Workspace administration
Administer a Zentrik workspace safely
This guide is for workspace Owners and Admins. Use it to assign least-privilege roles, manage invitations, understand Settings visibility, protect integration and API credentials, review billing access, and offboard teammates.
The Settings area is restricted to workspace Owners and Admins. Editors and Viewers can work within their permitted product surfaces but should ask an Owner or Admin to complete administrative changes.
Some settings have narrower visibility: workspace organization is Owner-only, billing depends on billing-management access, and the Ideas Portal appears only when enabled.
1. Choose the least-privilege role
Zentrik workspace roles are:
- Owner: workspace ownership and the most sensitive workspace-level controls
- Admin: settings, integrations, API keys, team administration, and product configuration
- Editor: day-to-day creation and editing in product workflows without access to workspace Settings
- Viewer: read-only workspace participation
Keep at least one active Owner. Do not use Owner as the default collaboration role. Review Admin access whenever responsibilities change.
2. Manage members and invitations
Open Settings → Team.
For new teammates:
- Enter the intended email and role.
- Review the batch before sending.
- Check Invitations for pending, sent, failed, expired, or revoked states.
- Resend only after confirming the original delivery state.
- Verify that an accepted invitation appears under Members with the intended role.
Owners and Admins can change roles and remove members. Confirm the target identity before removal, especially when names are similar.
3. Use the Settings map
The Settings hub groups product configuration and workspace administration:
- Discovery: evaluation, workflow, and property configuration
- Definition: requirements, documentation templates, and user-story standards
- Delivery: sprints and team capacity
- Integrations: connected evidence and delivery providers
- API Keys: credentials for MCP clients and the external API
- Team: members, roles, and invitations
- Billing: plan, usage, and invoices when the role can manage billing
- Portal: Ideas Portal access and configuration when enabled
- Workspaces: Owner-only workspace organization
The options shown in Settings depend on the workspace plan and enabled capabilities.
4. Protect integrations and API keys
Treat provider credentials and Zentrik API keys as secrets:
- create separate credentials for distinct systems or agents when practical
- name keys by purpose and owner
- grant only the scopes the workflow needs
- store secrets in an approved secret manager or environment variable
- never paste a key into documentation, chat, source control, screenshots, or support messages
- revoke credentials that are unused, exposed, or owned by a departing teammate
- confirm the active Zentrik workspace before connecting an MCP client
Use MCP setup or the REST API reference for the relevant authentication flow.
5. Review billing and workspace boundaries
Use Settings → Billing for the workspace plan, current usage, configured limits, and invoices when your role has billing access. Use the pricing page for current published packaging.
Workspace Owners can use Settings → Workspaces to review the workspaces they can organize. Separate workspaces when teams or clients require distinct access and context. Do not move data between workspace boundaries without confirming authorization and downstream integrations.
6. Offboard safely
Before removing a teammate:
- Transfer ownership of important product decisions, documents, integrations, and operating routines.
- Identify credentials, connected providers, or external automations they own.
- Create replacement credentials where needed.
- Revoke the person’s invitations or remove their membership.
- Revoke or rotate affected API keys and provider credentials.
- Verify that required integrations and scheduled imports still run.
Removing a member is not a substitute for rotating a credential they could access.
Quarterly review checklist
- at least one current Owner is active
- Admin access matches current responsibilities
- Editors and Viewers have the least access they need
- pending and expired invitations are reconciled
- API keys have a current purpose and owner
- integration credentials still belong to active administrators
- billing contacts and invoice access are current
- workspace boundaries match team or client access requirements
- teammates understand which capabilities are enabled for the workspace
Support and trust
Use Security and trust for current public assurance information. For a workspace-specific access, billing, or configuration issue, use the Still stuck? path below and include the workspace name, the screen, what you expected, and what happened.
Do not include passwords, API keys, access tokens, private customer content, or full diagnostic exports in the initial support message.
Troubleshooting
Check these steps against what you see in your workspace. If something differs, note your workspace name and the screen, then contact us.
A teammate cannot open Settings
Settings is restricted to Owners and Admins. Confirm the person’s workspace and role; use Editor for product work that does not require administration.
An invitation email failed or expired
Check the Invitations view, confirm the email, and resend or revoke from the recorded invitation state. Avoid creating repeated invitations without reconciling the existing one.
A billing, portal, or workspace control is missing
Visibility depends on role and workspace capabilities. Billing requires billing-management access, Workspaces is Owner-only, and Portal appears only when enabled.
Continue from here
Related guides
Did this guide answer your question?
Your response helps us prioritize missing or unclear documentation.
Still stuck?
Send your question to Zentrik support. This guide will be included automatically.