---
title: "Administer a Zentrik workspace safely"
canonical_url: https://zentrik.ai/docs/product/workspace-administration
markdown_url: https://zentrik.ai/docs/product/workspace-administration.md
category: "Product guides"
learning_track: "administration"
last_reviewed: 2026-07-28
---

# Administer a Zentrik workspace safely

This guide is for workspace Owners and Admins. Use it to assign least-privilege roles, manage invitations, understand Settings visibility, protect integration and API credentials, review billing access, and offboard teammates.

## Overview

The **Settings** area is restricted to workspace Owners and Admins. Editors and Viewers can work within their permitted product surfaces but should ask an Owner or Admin to complete administrative changes.

Some settings have narrower visibility: workspace organization is Owner-only, billing depends on billing-management access, and the Ideas Portal appears only when enabled.

## 1. Choose the least-privilege role

Zentrik workspace roles are:

- **Owner**: workspace ownership and the most sensitive workspace-level controls
- **Admin**: settings, integrations, API keys, team administration, and product configuration
- **Editor**: day-to-day creation and editing in product workflows without access to workspace Settings
- **Viewer**: read-only workspace participation

Keep at least one active Owner. Do not use Owner as the default collaboration role. Review Admin access whenever responsibilities change.

## 2. Manage members and invitations

Open **Settings → Team**.

For new teammates:

1. Enter the intended email and role.
2. Review the batch before sending.
3. Check **Invitations** for pending, sent, failed, expired, or revoked states.
4. Resend only after confirming the original delivery state.
5. Verify that an accepted invitation appears under **Members** with the intended role.

Owners and Admins can change roles and remove members. Confirm the target identity before removal, especially when names are similar.

## 3. Use the Settings map

The Settings hub groups product configuration and workspace administration:

- **Discovery**: evaluation, workflow, and property configuration
- **Definition**: requirements, documentation templates, and user-story standards
- **Delivery**: sprints and team capacity
- **Integrations**: connected evidence and delivery providers
- **API Keys**: credentials for MCP clients and the external API
- **Team**: members, roles, and invitations
- **Billing**: plan, usage, and invoices when the role can manage billing
- **Portal**: Ideas Portal access and configuration when enabled
- **Workspaces**: Owner-only workspace organization

The options shown in Settings depend on the workspace plan and enabled capabilities.

## 4. Protect integrations and API keys

Treat provider credentials and Zentrik API keys as secrets:

- create separate credentials for distinct systems or agents when practical
- name keys by purpose and owner
- grant only the scopes the workflow needs
- store secrets in an approved secret manager or environment variable
- never paste a key into documentation, chat, source control, screenshots, or support messages
- revoke credentials that are unused, exposed, or owned by a departing teammate
- confirm the active Zentrik workspace before connecting an MCP client

Use [MCP setup](https://zentrik.ai/docs/integrations/mcp) or the [REST API reference](https://zentrik.ai/docs/api) for the relevant authentication flow.

## 5. Review billing and workspace boundaries

Use **Settings → Billing** for the workspace plan, current usage, configured limits, and invoices when your role has billing access. Use the [pricing page](https://zentrik.ai/pricing) for current published packaging.

Workspace Owners can use **Settings → Workspaces** to review the workspaces they can organize. Separate workspaces when teams or clients require distinct access and context. Do not move data between workspace boundaries without confirming authorization and downstream integrations.

## 6. Offboard safely

Before removing a teammate:

1. Transfer ownership of important product decisions, documents, integrations, and operating routines.
2. Identify credentials, connected providers, or external automations they own.
3. Create replacement credentials where needed.
4. Revoke the person’s invitations or remove their membership.
5. Revoke or rotate affected API keys and provider credentials.
6. Verify that required integrations and scheduled imports still run.

Removing a member is not a substitute for rotating a credential they could access.

## Quarterly review checklist

- at least one current Owner is active
- Admin access matches current responsibilities
- Editors and Viewers have the least access they need
- pending and expired invitations are reconciled
- API keys have a current purpose and owner
- integration credentials still belong to active administrators
- billing contacts and invoice access are current
- workspace boundaries match team or client access requirements
- teammates understand which capabilities are enabled for the workspace

## Support and trust

Use [Security and trust](https://zentrik.ai/security) for current public assurance information. For a workspace-specific access, billing, or configuration issue, use the **Still stuck?** path below and include the workspace name, the screen, what you expected, and what happened.

Do not include passwords, API keys, access tokens, private customer content, or full diagnostic exports in the initial support message.

## Troubleshooting

### A teammate cannot open Settings

Settings is restricted to Owners and Admins. Confirm the person’s workspace and role; use Editor for product work that does not require administration.

### An invitation email failed or expired

Check the Invitations view, confirm the email, and resend or revoke from the recorded invitation state. Avoid creating repeated invitations without reconciling the existing one.

### A billing, portal, or workspace control is missing

Visibility depends on role and workspace capabilities. Billing requires billing-management access, Workspaces is Owner-only, and Portal appears only when enabled.

## Related guides

- [Use the Ideas Portal to turn customer demand into product evidence](https://zentrik.ai/docs/product/ideas-portal)
- [Create delivery artifacts without losing the product decision](https://zentrik.ai/docs/product/documents-and-delivery)
- [Move from evidence-backed priorities to a usable roadmap](https://zentrik.ai/docs/product/planning-and-roadmaps)
