Team and access management
Invite people to the workspace, bundle them into groups, and grant website access. Two role systems, and where each one is managed.
Last update:
Managing who works in CentralCSP happens in two places, because there are two role systems.
Team manages workspace membership: who belongs, and who administers the account.
On a website, Settings > Access control manages what someone can do on that site.
What you can do
Five pages cover the two role systems between them:
- Invite and manage members: Add people, set their workspace role, remove them. Members
- Track invitations: Statuses, the 7-day expiry, and why revoking matters. Invitations
- Bundle people into groups: Grant website access once instead of per person. Groups
- Grant website access: Per site, to people or groups. Website access
- Understand the roles: Both systems and how they interact. Roles and permissions
Set up a new team
Work through these four steps in order:
- Invite everyone as Member. Reserve Admin for the small number of people who administer the account, since Admins reach every website automatically and cannot be restricted.
- Create a group per delivery team, plus one for security or compliance.
- Grant each group a role per website. Manager on the sites the team owns, Viewer elsewhere.
- Give script reviewers Analyst on payment-facing sites, so they can justify and reject without being able to change scope.
After that, onboarding is one action: add the person to their group.
Next steps
Usage alerts
Email warnings at 80% and 100% of your report quota. Separate from alert rules, email only, and the one alert you cannot afford to miss.
Roles and permissions
Two separate role systems. Workspace roles decide who administers the account, website roles decide what someone can do on one site.